Record attack volumes, ransomware as the dominant financially motivated threat, wiper campaigns tied to regional tension and AI on both sides. A summary of the public data.
Check Point's data for the first half of 2026 put the average UAE organisation at roughly 2,200 attempted cyber attacks per week. The UAE Cybersecurity Council reported intercepting between 90,000 and 200,000 attacks per day early in the year, rising to around 600,000 daily during periods of heightened regional tension, with the majority linked to state-aligned actors. By mid-February the Council had confirmed 128 targeted incidents against UAE entities since the start of the year, including attempts to deploy ransomware and coordinated phishing campaigns against finance, aviation and energy.
Microsoft's regional data attributes about 52 percent of attacks on UAE organisations to financially motivated ransomware and extortion. The families seen in UAE incidents mirror the global picture: Qilin, Akira and LockBit-derived builds in enterprise cases, and Phobos, Dharma, Makop and Mallox in the small and medium business segment, where exposed remote desktop and SQL Server services remain the most common entry points.
A survey of UAE organisations that paid a ransom found that roughly nine in ten were attacked again, most within a month and most with a higher demand. Reported ransom payments by UAE firms have run into the millions of dirhams per year, without corresponding guarantees of recovery.
Unlike ransomware, wiper malware seeks destruction rather than payment. UAE authorities described the incidents intercepted in 2026 as including distributed denial-of-service attacks, ransomware, data breaches, wiper malware and defacement, several of them aimed at critical infrastructure. For operators of essential services the practical difference is that a wiper leaves nothing to negotiate and everything to reconstruct.
In a 2026 survey, 83 percent of UAE organisations affected by ransomware said AI had increased the effectiveness of the attack: more convincing phishing in Arabic and English, faster vulnerability discovery and automated lateral movement. The UAE has responded with AI-driven national defence programmes. For an individual organisation the relevant change is speed: dwell times are shorter and the window for detection before encryption is narrowing.
The probability of an incident is high enough that recovery capability should be planned, not improvised. Immutable off-site backups, segmented hypervisor management, multi-factor authentication on every remote access path and a tested incident checklist reduce both likelihood and impact. When an incident does happen, preserving evidence and obtaining a recovery assessment before engaging with the attackers is the position regulators, insurers and boards will expect to see.