Common Cyber Security Threats in the UAE

Common Cyber Security Threats in the UAE
AUTHOR VERIFICATION
Written & reviewed by

Faris Raian

Founder Partner Leaders Advocates, Dubai
Cyber crime law Updated September 2, 2026

Cyber incidents in the UAE can move from a deceptive email to a financial transfer, data loss, service shutdown, privacy issue, police report, and contractual dispute in a few hours. Businesses often respond as if the event is only an IT problem, while the ability to recover money and prove what happened depends on early banking, legal, evidence, and communication decisions.

Phishing, business email compromise, ransomware, unauthorised access, and crypto-connected fraud do not create identical risks. The organisation needs to identify the attack, stop continuing harm, preserve evidence, protect accounts and people, and assess the applicable UAE Cybercrime Law, data protection, contractual, insurance, and reporting issues without delaying urgent containment.

Quick Answer

Common cyber security threats in the UAE include phishing, business email compromise, ransomware, unauthorised access, account takeover, malicious insiders, supplier compromise, and crypto-related fraud. Phishing steals credentials or payment information; business email compromise impersonates an executive or supplier to redirect a real payment; ransomware encrypts data and may threaten publication; account takeover uses stolen access to control email, banking, or business systems. Federal Decree-Law No. 34 of 2021 provides the main federal cybercrime framework, while financial loss, personal data, contracts, employment, and sector rules can create additional legal issues. The first response should contain access, notify the bank where money moved, preserve logs and original messages, create a chronology, and report through the competent channel instead of deleting evidence or negotiating impulsively.

Prepare for cyber incidents as a combined technical, financial, legal, and operational process. Give named people authority to contain systems, contact banks, preserve evidence, assess notifications, communicate safely, and obtain legal advice without waiting for a perfect technical diagnosis.

About Faris Raian

Faris Raian is the founder, managing partner, and senior legal consultant at Leaders Advocates. He brings more than 15 years of experience across corporate, commercial, criminal, cybercrime, family, and real estate matters in UAE courts. That breadth is relevant to a cyber incident because the response may need to connect digital evidence, banking and payment issues, police and public prosecution procedure, contractual responsibility, data protection, and recovery strategy.

Phishing and Credential Theft

Phishing uses a deceptive email, message, website, attachment, or call to make a person reveal credentials, approve access, open malicious content, or send money. The message may imitate a bank, courier, government service, manager, supplier, cloud platform, or colleague. Urgency and secrecy are common manipulation tools.

A stolen password can expose more than one system if it is reused. The attacker may read old conversations, reset other accounts, create mailbox rules, download customer data, and wait for a valuable payment. Multi-factor authentication reduces risk, but weak recovery methods, stolen sessions, push fatigue, or social engineering can still be exploited.

The response should reset access from a trusted device, revoke sessions, preserve the original message and headers, inspect mailbox rules and forwarding, identify connected accounts, and record the timeline. Do not simply delete the phishing email; it may contain evidence needed by the technical team, bank, insurer, police, or court.

Business Email Compromise and Payment Diversion

Business email compromise goes beyond a generic phishing attempt. The attacker impersonates or controls a real executive, employee, customer, or supplier and uses a genuine transaction to redirect payment. The false bank details may arrive inside an existing email thread, making the request look credible.

Faris Raian, cybercrime lawyer in Dubai , said that business email compromise cases often expose a gap between how quickly the loss happens and how quickly a business notices it. He explained that acting within the first hours after discovering a fraudulent transfer, freezing accounts and notifying the bank and police immediately, meaningfully affects whether funds can actually be traced or recovered.

Responding to a Cyber Incident in the UAE?

Phishing, ransomware, account takeover, and unauthorised access can quickly create legal, financial, and operational risks. Leaders Advocates can assess the incident, evidence, reporting requirements, and UAE Cybercrime Law implications while technical containment continues.

Review My Cyber Incident

Contact the sending and receiving banks through verified channels as soon as the loss is discovered. Ask for the fraud or recall procedure and preserve the reference. Notify police through the competent channel and keep the account details, transfer confirmation, invoice, emails, headers, telephone records, and internal approval evidence. Do not alert the attacker through the compromised account.

• Verify every new or changed bank instruction through a separate trusted telephone or in-person channel.

• Use approval separation so one compromised person cannot change a beneficiary and release payment alone.

• Protect email with multi-factor authentication, session monitoring, domain controls, and restricted forwarding rules.

• Train finance staff to recognise unusual urgency, secrecy, payment timing, and writing-pattern changes.

Ransomware and Data Extortion

Ransomware encrypts or disrupts data and systems and demands payment for restoration. Many attacks also copy information and threaten to publish it. The incident can therefore create operational interruption, data confidentiality issues, contractual failures, and legal obligations even if backups restore the affected systems.

Isolate affected systems using the incident plan, preserve logs and forensic evidence, protect unaffected backups, and identify critical services. Avoid wiping machines or rebuilding everything before evidence is captured. The organisation should assess what data was accessed, whether it was copied, which people or clients are affected, and what legal, regulator, contractual, or insurance notices may apply.

A ransom decision carries legal, sanctions, operational, insurance, and recovery risks and should not be made by an employee under pressure. Payment does not guarantee restoration, deletion, or silence. The decision needs senior authority, specialist technical input, legal advice, and documented reasoning.

Unauthorised Access and Account Takeover

Unauthorised access can involve email, banking, social media, cloud storage, customer portals, business applications, or an internal network. It may result from stolen credentials, an exposed service, excessive access, a compromised device, weak supplier controls, or an insider. Federal Decree-Law No. 34 of 2021 is central to the UAE cybercrime analysis.

Containment should be controlled. Disable or restrict the compromised account, revoke tokens and sessions, preserve logs, image affected devices where appropriate, and check privilege escalation and lateral movement. A rapid password change alone may not remove persistent access or malicious rules.

Record which systems, data, transactions, and communications the account could reach. That scope supports the legal assessment and prevents an organisation from making a notification based on speculation. It also helps identify clients, employees, suppliers, insurers, or authorities who may require accurate information.

Crypto-Connected Fraud

Crypto fraud can involve fake investment platforms, impersonated exchanges, wallet-draining links, romance or relationship manipulation, fraudulent recovery agents, token promotions, and payment demands. The speed and cross-border nature of transfers can make recovery difficult, but the victim should not assume that reporting is pointless.

Preserve wallet addresses, transaction hashes, platform URLs, account profiles, chats, advertisements, transfer instructions, bank funding records, and identity material provided by the suspect. Do not pay a second person who claims they can recover funds for an advance fee without independent verification. Recovery scams frequently target people who have already suffered a loss.

Notify the relevant bank or payment provider where fiat funds were used and report through the competent police or cybercrime channel. A regulated platform may also have a freeze, fraud, or law-enforcement contact process. The legal team should map the payment trail and distinguish evidence, tracing possibilities, and jurisdiction from promises of guaranteed recovery.

Supplier and Insider Threats

A supplier with remote access, sensitive data, or payment influence can create a pathway into the organisation. The contract should define security controls, approved access, incident notice, cooperation, evidence preservation, subcontractors, data return, audit rights, and liability. Due diligence should continue after onboarding.

Insider incidents may be malicious or accidental. Excessive permissions, shared accounts, weak supervision, rushed offboarding, personal cloud storage, and uncontrolled exports increase exposure. Monitor appropriately, apply least privilege, record approvals, and remove access promptly while respecting employment, privacy, and evidence requirements.

Avoid accusing an employee publicly or searching personal accounts without lawful authority. Preserve business evidence, limit access based on risk, and coordinate HR, legal, technical, and management steps. An unfair or poorly documented response can create a separate employment or privacy dispute.

The First Hours of Incident Response

The first objective is to stop continuing loss without destroying evidence. Activate the incident team, identify a decision-maker, use a trusted communication channel, and record every material action. Where money moved, notify banks immediately. Where safety or active crime is involved, contact the competent authority.

Preserve original emails, message exports, logs, devices, screenshots with context, transfer records, call details, access changes, and the incident timeline. Separate confirmed facts from assumptions. Legal privilege, confidentiality, employee rights, data protection, insurer conditions, and contractual notices should be considered before distributing an internal report widely.

Dealing with a cyber incident, or want to understand your legal exposure before one happens? Faris Raian and the team at Leaders Advocates can assess the Cybercrime Law, evidence, reporting, payment recovery, data, contracts, and dispute strategy for the specific situation.

• Contain compromised access and preserve logs and original evidence.

• Contact the bank or payment provider immediately where funds were sent or credentials exposed.

• Create one verified chronology and keep decisions, references, and evidence custodians recorded.

• Assess police, regulator, data protection, insurer, contract, client, and employee communications.

• Restore from clean, tested backups only after persistence and scope are understood.

Lost Money Through Phishing or Business Email Compromise?

The first hours after a fraudulent transfer can be critical. Preserve emails, payment records, account details, and transaction evidence while taking prompt steps with banks and the competent authorities. Our team can assess tracing and recovery options.

Assess My Recovery Options

Common Mistakes

• Deleting the phishing email or rebuilding affected systems before preserving evidence.

• Using the compromised email account to warn colleagues, customers, or the attacker.

• Delaying bank and police notification after discovering a diverted payment.

• Treating ransomware restoration as proof that no personal data was accessed or copied.

• Paying a crypto recovery agent or ransom demand without verification and legal assessment.

• Treating the incident as an IT-only event and missing contractual, reporting, insurance, and liability issues.

Relevant Legal Services

A Cybercrime Lawyer in Dubai can advise on unlawful access, digital evidence, reporting, fraud, and Cybercrime Law exposure. A Criminal Defense Lawyer in Dubai can support complainants or accused persons through police and Public Prosecution procedures. A Corporate Lawyer in Dubai can address governance, incident plans, supplier contracts, data obligations, and management decisions.

People Also Ask

▼ What are the most common cyber security threats in the UAE?
Common threats include phishing, business email compromise, ransomware, unauthorised access, account takeover, supplier compromise, insider incidents, and crypto-related fraud.
▼ What should a business do after a fraudulent transfer?
Contact the sending and receiving banks immediately through verified channels, preserve the transfer and email evidence, notify police through the competent route, and record every reference.
▼ Does ransomware create legal issues beyond restoring systems?
Yes. Data access or exfiltration, contractual disruption, regulatory duties, insurance conditions, evidence, communications, and ransom legality can all require assessment.
▼ Why preserve the original phishing email?
The original and its headers may show sender infrastructure, routing, links, timing, account compromise, and evidence needed by investigators, banks, insurers, and courts.
▼ Can stolen cryptocurrency be reported?
Yes. Preserve wallet addresses, transaction hashes, platform records, communications, bank funding records, and suspect details, then use the competent reporting and platform channels.
▼ Who is Faris Raian?
Faris Raian is the Founder and Managing Partner at Leaders Advocates, with more than 15 years across UAE corporate, commercial, criminal, and cyber-related matters.

Conclusion

Common UAE cyber threats use different techniques but demand the same disciplined foundations: fast containment, immediate financial action where money moved, lawful reporting, complete evidence preservation, and a coordinated legal and technical assessment. The first hours can determine whether funds, data, systems, and legal rights remain recoverable.

Is Your Business Legally Prepared for a Cyber Attack?

A cyber incident can trigger data, contractual, insurance, employee, supplier, reporting, and liability issues. Leaders Advocates can review your incident-response framework and help your business prepare for the legal decisions that follow a breach.

Assess Our Cyber Legal Risk

    Leave a comment