How Can I Protect Myself From Identity Theft in the UAE?

how can i protect myself from identity theft​ in the uae
AUTHOR VERIFICATION
Written & reviewed by

Faris Raian

Founder Partner Leaders Advocates, Dubai
Cyber crime law Updated September 1, 2026

Identity theft risks in the UAE can affect Emirates ID, passports, UAE PASS, banking, mobile accounts, property, employment, and delivery services. A criminal may need only one compromised email account, one remote-access session, or a convincing copy of an identity document to attempt a SIM change, payment, loan application, fake account, or impersonation scam.

The first sign may be a one-time password you did not request, a new beneficiary, a missing mobile signal, an unfamiliar credit facility, or a caller who already knows personal details. Waiting to prove the entire scheme before acting can make recovery harder. The immediate goal is to close access, stop money movement, preserve evidence, and notify the correct institutions and authority.

QUICK ANSWER

Limit and watermark ID copies, secure your email, UAE PASS, banking, and mobile account with unique passwords and multi-factor authentication, and verify every request through an independently found official channel.

If misuse is suspected, contact the bank and telecom provider immediately, preserve evidence, report the incident to police, and replace compromised identification or credentials.

Treat identity security as a connected system. Protect the documents that establish who you are, the email and phone that receive recovery codes, the accounts that move money, and the devices that approve transactions. If one layer is compromised, secure the others at once.

What Identity Theft Looks Like in the UAE

Identity theft is a practical description, not always the name of one standalone criminal charge. The conduct may fall across several provisions of Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, depending on whether the offender accessed personal data, obtained passwords, created a fake account, misused payment-instrument data, forged an electronic document, or used impersonation to obtain money or a signature.

Article 6 addresses specified unauthorized conduct involving electronic personal data and information. Article 9 addresses unlawful acquisition of passwords, codes, or similar credentials. Article 11 covers fake websites, accounts, or emails attributed to another person or entity. Article 15 deals with electronic payment instruments and their data, while Article 40 addresses internet fraud using fraudulent methods, aliases, or false impersonation.

Concerned About Identity Theft in the UAE?

If your Emirates ID, UAE PASS, mobile number, email, or banking details may have been exposed, our legal team can help you assess the risk and the appropriate next steps.

Discuss Your Situation

Protect Emirates ID and Passport Copies

Ask why a copy is required, who will receive it, how it will be stored, and whether the organization needs the full document. Use official upload portals rather than personal messaging accounts where possible. Do not send identification merely because a caller knows your name, employer, address, or part of your card number; breached data is often used to make a false request look credible.

Where the recipient accepts it, watermark the copy with the purpose, recipient, and date without obscuring mandatory security features. A watermark is not complete protection, but it can limit reuse and show the intended transaction. Keep a simple disclosure log so you can identify likely exposure points if misuse later appears.

If an Emirates ID is lost, stolen, or damaged, use the Federal Authority for Identity, Citizenship, Customs and Port Security’s official replacement process promptly. UAE government guidance directs lost-card reporting to ICP within seven days. A police report or other proof may be required depending on the circumstances and service instructions.

  • Remove identity scans from shared downloads folders, old devices, and unprotected cloud links.
  • Give brokers, employers, landlords, banks, and providers only the information their lawful process requires.
  • Shred unwanted paper copies and confirm secure deletion when a service relationship ends.

Secure the Accounts That Control Your Identity

Your primary email account is often the master key because it can reset banking, shopping, cloud, and social accounts. Use a long unique password, strong multi-factor authentication, current recovery information, and alerts for new logins. Review forwarding rules, connected applications, recent sessions, recovery addresses, and app passwords after any suspicious activity.

Protect UAE PASS with the same care. Approve only a request you initiated and understand. A caller should not instruct you to approve a UAE PASS notification, share a one-time password, reveal a PIN, or install a remote-support application to receive a refund, parcel, prize, or government service. Close the call and use the organization’s independently verified number or application.

A sudden loss of mobile service can indicate a SIM problem or account takeover. Contact the telecom provider immediately from another channel, ask whether a replacement SIM or account change was requested, and secure email and bank accounts at the same time. Do not rely on SMS alone for sensitive accounts if stronger authentication is available.

  • Use a password manager and never reuse the email or banking password.
  • Enable login, beneficiary, transfer, card, and profile-change notifications.
  • Update phones and computers and remove unneeded remote-access or sideloaded applications.
  • Lock screens, encrypt devices, back up important data, and record device serial numbers.

Phishing, Calls, Links, and Remote-Access Scams

Scammers imitate banks, police, courts, utilities, delivery companies, toll systems, property platforms, recruiters, and government services. The message may create urgency by threatening a fine, frozen account, failed parcel, immigration problem, or expiring benefit. The display name and caller ID can be forged, and a website can closely copy the original.

Do not use the link, number, QR code, or application provided in the unexpected contact. Open the official application or type the known domain yourself. A legitimate institution may verify identity through its secure process, but it should not ask for a banking PIN, full password, card security code, or one-time password in an unsolicited call or message.

Remote-access software is especially dangerous because it can expose the screen, messages, files, and banking session while the victim believes technical support is helping. If installed, disconnect the device from networks, use another trusted device to contact the bank and change critical credentials, preserve installation and communication evidence, and obtain technical assistance before returning the device to normal use.

What to Do in the First Hour After Suspected Misuse

Contact the bank or payment provider through its official emergency channel. Ask it to block affected cards or digital access, stop or recall transfers where possible, record the fraud reference, preserve account logs, and explain the written dispute process. Speed does not guarantee recovery, but delay can reduce the chance of tracing or freezing funds.

Secure the email, phone, UAE PASS, banking, and cloud accounts from a trusted device. Change compromised passwords, end sessions, remove unknown recovery methods, and notify the telecom provider of any SIM issue. If an identity document is missing or used, begin the official replacement or status-check process and notify the relevant issuer.

Preserve the original messages, headers, links, usernames, phone numbers, recordings lawfully held, account statements, beneficiary details, transaction references, website addresses, wallet addresses, receipts, application names, and device information. Screenshots help, but native emails, statements, and exported conversations may contain more useful metadata.

    • Do not continue negotiating with the scammer or send a verification payment.
    • Do not delete the account or reset the device before preserving evidence and securing access.
    • Write a timeline while events are fresh and separate what you observed from what you infer.

Has Your Identity or Bank Account Already Been Misused?

Acting quickly can matter. Preserve the evidence, secure affected accounts, and get advice on police reporting, financial-loss recovery, and any connected civil or cybercrime issues.

Speak With a Cybercrime Lawyer

How to Report Identity Theft or Cyber Fraud

Report an emergency or active crime through the official police emergency route. Cyber-enabled financial crime in Dubai can be reported through Dubai Police’s eCrime service, a Smart Police Station, or another official Dubai Police channel. Other emirates provide their own police platforms, and the UAE government portal lists cybercrime reporting options. Use the channel for the place and incident, and keep the complaint reference.

A police report does not replace the bank’s urgent fraud process, and a bank complaint does not replace a criminal report. Contact both where money or payment data is involved. If a regulated financial institution does not resolve a service complaint through its internal process, Sanadak may be relevant for an eligible complaint, but it is not a substitute for reporting the criminal conduct.

If the incident affects a business database, the organization may also need to assess duties under Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data and any sector or free-zone rules. Preserve confidentiality, limit circulation of breached data, and coordinate technical containment, legal assessment, regulatory duties, customer communications, and police cooperation.

Has your identity, UAE PASS, phone, or bank account already been misused?
Leaders Advocates can assess the digital evidence, reporting route, criminal complaint, financial-loss strategy, and connected civil or data issues while urgent preservation and notification steps are taken.

Common Mistakes

  • Sending an unmarked identity copy through an unverified personal account without checking why it is required.
  • Approving a UAE PASS request or sharing an OTP because a caller creates urgency or knows personal details.
  • Securing only the bank account while leaving the compromised email or mobile number under the attacker’s control.
  • Paying a recovery agent or scammer who promises to release, verify, or trace funds for an advance fee.
  • Deleting messages, resetting devices, or closing accounts before preserving useful evidence.
  • Reporting only to the bank or only to police when both financial containment and criminal reporting are needed.

Relevant Legal Services

A Cybercrime Lawyer in Dubai can classify the digital conduct, preserve evidence, and assist with a cybercrime complaint. A Criminal Defense Lawyer in Dubai can advise on police and Public Prosecution procedure where identity misuse forms part of a criminal case. A Civil Lawyer in Dubai can assess compensation, recovery, contractual, and other private-law remedies arising from the loss.

People Also Ask

Should I Watermark My Emirates ID Before Sharing It?
Where the recipient and process allow, add the recipient, purpose, and date without hiding required details. It reduces reuse risk but does not replace verification and secure transmission.
Will a UAE Bank Ask for My OTP or PIN by Phone?
Treat an unsolicited request for a PIN, password, card security code, or one-time password as suspicious. End the call and contact the bank through its official application or independently verified number.
What Should I Do If My Emirates ID Is Lost?
Report the loss and begin ICP’s official replacement process promptly. Current UAE government guidance directs lost-card reporting within seven days, subject to the service’s required documents and steps.
Where Can I Report Identity Theft in Dubai?
Use an official Dubai Police channel such as eCrime or a Smart Police Station, and call emergency services for an active emergency. Also notify the affected bank, telecom provider, or document issuer immediately.
What Evidence Should I Keep After a Phishing Scam?
Keep original messages and emails, headers, links, phone numbers, usernames, statements, beneficiary and transaction details, website addresses, application records, device information, and a dated timeline.
Is Identity Theft One Specific Offence Under UAE Law?
Not necessarily. The facts may engage cybercrime provisions on personal data, credentials, fake accounts, payment instruments, electronic documents, privacy, or internet fraud, together with other laws. 

Identity protection in the UAE depends on controlling documents and securing the email, phone, UAE PASS, banking, and devices that prove and use identity. Verify every unexpected request independently. If misuse occurs, speed matters: contain access and money movement, preserve the evidence, and notify the relevant provider and police through official channels.

Need Legal Help After Identity Theft or Cyber Fraud?

Leaders Advocates can review the digital evidence, reporting options, criminal complaint, financial-loss strategy, and possible recovery routes arising from identity misuse in the UAE.

Message Us on WhatsApp

    Leave a comment