Is Computer Hacking a Crime in the UAE? What the Law Says

Is Computer Hacking a Crime in the UAE
AUTHOR VERIFICATION
Written & reviewed by

Faris Raian

Founder Partner Leaders Advocates, Dubai
Criminal Law Updated July 25, 2026

Many people assume hacking only becomes illegal when money is stolen or a system is damaged. UAE law takes a much stricter approach. In many cases, unauthorized access alone is enough to trigger criminal penalties.

Quick Answer

Yes. Computer hacking is a crime in the UAE. Under Federal Decree-Law No. 34 of 2021, accessing a system, website, or account without authorization is a criminal offense, even if no damage is caused. Depending on the target and the impact of the offense, penalties may include imprisonment and fines starting from around AED 100,000 and reaching up to AED 3,000,000 for the most serious cybercrime offenses.

From there the penalties climb steeply with the target and the harm: leaked data, government systems, and disabled networks push the offense toward AED 3,000,000 and years of imprisonment. 

This guide explains what counts as hacking, the punishments under UAE law, and the legal exceptions you should know. If you are under investigation or facing cybercrime allegations, a cybercrime lawyer in Dubai can help you understand your rights and legal options.

What Counts as Hacking Under UAE Law?

The law defines the offense as accessing a website, electronic information system, network, or information technology means without authorization or exceeding the authorization you have. No sophistication is required. Guessing a password, using someone’s logged-in session, or opening an account you were once allowed into all qualify.

Two features make the offense wider than people assume. Intent to access is enough: the prosecution does not need to prove you meant to cause damage, only that you meant to get in. And attempts are punishable, so a failed intrusion is still a case.

The related offenses travel in a pack: intercepting communications, obstructing access to a network, spreading malware, and using a fraudulent IP address to commit a crime each carry their own penalties on top of the access offense.

The Penalty Tiers

The law grades the punishment by the target and the harm:

ConductPenalty
Unauthorized access to a private system or accountImprisonment and/or a fine of roughly AED 100,000 to AED 300,000.
Access resulting in data being altered, copied, deleted, disclosed, or publishedAggravated offence with longer imprisonment and higher fines, with even harsher penalties where personal data is involved.
Hacking a government website or systemTemporary imprisonment and a fine ranging from AED 200,000 to AED 500,000.
Obtaining government data or confidential data of financial and economic establishmentsTemporary imprisonment and a fine of AED 250,000 to AED 1,500,000.
Attacks causing damage, destruction, or disruption of government systemsImprisonment for no less than 5 years and fines ranging from AED 250,000 to AED 1,500,000.
Interception of communications; leaking what was interceptedImprisonment and a fine of AED 150,000 to AED 500,000. Leaking intercepted communications increases the penalty to at least 1 year of imprisonment and fines of up to AED 1,000,000.

The law’s overall fine ceilings extend to AED 3,000,000 for the gravest attacks, devices and proceeds are confiscated, and for expatriate offenders deportation is commonly ordered alongside the sentence.

The Ex-Employee Trap

Ask any cybercrime unit who the typical hacking defendant is, and the answer is not a hooded stranger. It is a former employee logging into the company email, CRM, or cloud drive with credentials nobody revoked.

Legally, the moment employment ends, the authorization ends. Downloading “your own” files, checking what colleagues are saying, or taking the client list on the way out is unauthorized access, and copying the data aggravates it. The employee’s sense of entitlement to the work they created is not a defense; ownership of the work product sits with the employer, as our guide on non-compete clauses and its companion on IP explain.

For employers, the same fact pattern is a compliance instruction: revoke access on the exit day, log it, and audit unusual activity around resignations. The logs you keep in that window are the evidence that wins the case if the exit goes wrong.

Is Ethical Hacking Legal in the UAE?

Yes, with authorization, and only with authorization. Penetration testing, vulnerability research, and security auditing are lawful when the system owner has consented in writing, with a defined scope.

The law contains no general good-faith researcher defense. Finding a vulnerability in a system you were not asked to test, even to report it helpfully, is still unauthorized access on the statute’s terms. Security professionals working in the UAE run on three documents: a signed engagement letter, a scope definition, and rules of engagement, and they stay inside all three.

What to Do If Your Systems Were Hacked

1. Contain without destroying: isolate affected machines and accounts, but do not wipe or rebuild them yet; the logs and images are your evidence.

 

2. Preserve: access logs, IP records, altered files, ransom notes, and the timeline of what was touched and when.

 

3. Report: through the Dubai Police E-Crime platform, the MoI UAE app, or the other official channels. Our step-by-step guide covers each one. 

 

4. Notify where required: banks for financial compromise and affected parties and regulators where personal data protection obligations apply.

 

5. Pursue both tracks: the criminal case punishes the offender; a civil claim recovers the loss and can follow or accompany the prosecution.

Accused of Hacking or Facing a Cybercrime Investigation?

Early legal advice can make a significant difference in cybercrime cases. Our criminal defence lawyers can review the allegations, explain your legal position, and help you protect your rights before responding to investigators.

Speak with a Cybercrime Lawyer!

What to Do If You Are Accused

Take it seriously from the first call. These cases are built on technical evidence, and the early stage is where authorization, scope, and intent are established or lost. Do not delete anything; destroying data after an accusation creates a second problem larger than the first.

The realistic defenses track the statute: you were authorized, you did not exceed the authorization you had, or the technical attribution is wrong. All three are argued from documents and logs, which is why preserving your own records matters as much for the accused as for the victim.

Practical next step: Preserve device images, access logs, messages, and scope documents before responding to a complaint or accusation.

The Legal Provisions That Apply

Official texts are on the UAE Legislation portal (uaelegislation.gov.ae).

Federal Decree-Law No. 34 of 2021 on Combatting Rumors and Cybercrimes: in force since 2 January 2022. Its opening articles criminalize unauthorized access and its aggravated forms, attacks on government systems and data, interception and obstruction of networks, malware, and the use of fraudulent network addresses, with the tiered penalties set out above.

 

Federal Decree-Law No. 31 of 2021 (Penal Code): applies alongside it where the intrusion serves another crime, such as theft, extortion, or breach of trust.

 

Federal Decree-Law No. 45 of 2021 on Personal Data Protection: adds the civil and regulatory layer where personal data was compromised, including obligations on the breached organization itself.

How These Cases Run in Practice

Hacking prosecutions are not published with searchable citations, but the operating patterns are consistent across the cybercrime units and courts.

Attribution is built from the provider records. Investigators trace IP logs, device identifiers, and platform data, and courts convict on that technical chain. The defense that anyone could have used the connection meets detailed forensic rebuttal.

Insider cases turn on the exit date. Where access logs show entry after the employment ended, the authorization question usually answers itself. Companies that revoked and logged access on the exit day win these cases; companies that left accounts open fight uphill.

Intent to enter suffices for the base offense. Defendants who accessed but claim they meant no harm are still convicted of the access; the absence of damage mitigates the penalty rather than erasing the offense.

Criminal Law Firm of the Year UAE

Criminal Law Firm of the Year | UAE

Leaders Advocates has been recognized by Lawyer International – Legal 100 (2026) for excellence in criminal law services, strategic legal representation, and outstanding client advocacy across the UAE.

Speak With Our Criminal Lawyers

Frequently Asked Questions

Is hacking illegal in the UAE even if no damage is done?
Yes. Unauthorized access itself is the offence. It can lead to imprisonment and fines generally ranging from AED 100,000 to AED 300,000. If damage is caused or data is leaked, the penalties can increase, but damage is not required for an offence to exist.

Is it a crime to log into someone’s account with their password?
Yes, if you do not have authorization. Knowing or offensesomeone’s password does not give you legal permission to access their account. Using a partner’s, colleague’s, or former employer’s credentials without permission can be treated as unauthorized access.

Can I be prosecuted for accessing my old work email after resigning?
Yes. Access rights usually end when employment ends. Logging into a former employer’s email after leaving can lead to hacking-related prosecution, especially if information was copied, forwarded, or misused.

What is the maximum fine for hacking in the UAE?
The highest penalties can reach AED 3,000,000 for the most serious cyber offenses. Government-related attacks can involve fines between AED 250,000 and AED 1,500,000, along with imprisonment of five years or more where systems are damaged.

Is ethical hacking or penetration testing legal?
Yes, when it is performed with the system owner’s written authorization and within an agreed scope. Testing systems without permission can still be considered unauthorized access, even if the intention is to find security weaknesses.

Is attempting to hack a crime even if it fails?
Yes. Attempts can be punishable even when access is unsuccessful. The prosecution may focus on proving the intention to gain unauthorized access rather than proving that damage occurred.

Can hackers outside the UAE be prosecuted?
Yes. UAE cybercrime laws can apply to conduct targeting UAE systems or interests. Cross-border cases may involve international cooperation, although practical enforcement depends on the offender’s location.

How do I report hacking in the UAE?
Preserve your evidence and logs first, then report through the Dubai Police E-Crime platform, the UAE Ministry of Interior app, or your nearest police station. For urgent ongoing attacks, contact emergency services at 999.

Authorization Is the Whole Game

Every hacking case, prosecution, or defense comes down to one question: was access authorized, and can the documents prove it? Whether you are securing systems, testing them, or dealing with a breach, get the paperwork and the logs right and the law is on your side. If you need legal advice or representation, the best advocates in Dubai can assess your case and help protect your rights from the outset.

Before You Respond to a Cybercrime Allegation

Whether you have been accused of unauthorized access, your business has suffered a cyber attack, or you need advice on UAE cybercrime laws, obtaining legal guidance early can help you avoid costly mistakes and protect your legal position.

Speak with Our Cybercrime Lawyers!

 

    Leave a comment