AI phishing UAE cyber breaches statistics 2026
AI Now Writes 90% of the Phishing Messages Breaching UAE Systems. Here Is Why That Number Matters.
The UAE Cyber Security Council released a striking figure this month. AI-driven phishing now accounts for more than 90% of digital breaches in the country.
More than 75% of all cyber breaches start with phishing emails and fraudulent messages generally. Attackers send an estimated 3.4 billion phishing messages globally every day.
Robius covers individual phishing scams as they happen. Fake Salik texts. Fake consumer protection sites. Fake vehicle insurance accounts. This piece is about the trend underneath all of them.
| T H E R O B I U S V E R D I C T: A real, sourced statistic from the UAE’s own Cyber Security Council. Not an estimate from a private security vendor with a product to sell.The claim worth understanding is specific. AI did not just increase phishing volume. It eliminated the errors that used to give phishing away. The Cyber Security Council attributes the 90% figure specifically to AI-generated messages crafted well enough to remove the traditional warning signs. Poor grammar. Awkward phrasing. Generic greetings. All the things people were taught to look for. Generative AI now lets attackers produce grammatically flawless, contextually specific messages at massive scale, in any language, personalized to a named target. None of that requires the manual effort that used to cap how many convincing fakes one attacker could make. |
Why the Old Warning Signs Stopped Working
For years, the advice was simple. Look for spelling errors. Look for awkward grammar. Look for Dear Customer instead of your actual name. Look for formatting that seems slightly off.
That advice worked for a structural reason. Producing a convincing fake at scale required either real language fluency or careful manual effort. Both capped output.
Generative AI removes the cap entirely. One attacker can now generate thousands of grammatically perfect, tailored messages in minutes. Each personalized with a target’s real name, employer, or recent activity, pulled from public data.
So the 90% figure is not just about volume. The quality bar for a convincing fake collapsed to almost zero effort. You can see it in the individual cases, like the AED 4 Salik fine scam quietly draining UAE accounts.
The Scale Number Worth Sitting With
3.4 billion phishing messages a day is hard to hold onto intuitively. Here is what it means practically. At any given moment, phishing attempts are landing in inboxes and messaging apps across the UAE continuously. Not as occasional incidents. As a constant background rate. Individual scam warnings can only ever address one tactic at a time.
What Still Works as a Defense
Message quality is no longer a reliable signal. So the defenses that still hold up are structural, not linguistic. Verify the sender’s actual domain or phone number independently. Do not judge by how professional the message reads. Never act on urgency alone. Urgency is a psychological lever. It works the same whether a human or a model wrote the message.
And treat any request for a password, OTP, or remote device access as an automatic red flag. That is the moment the damage actually happens. It is also why your bank stopped sending SMS codes, so anyone asking you for one is a scammer.
The Signal Shifted, So Shift With It
| What Used to Flag a Fake | What Flags One Now |
|---|---|
| Spelling and grammar errors | Nothing about the writing itself |
| Generic greeting instead of your name | A greeting using your real name and employer |
| Odd formatting | A request for an OTP, password, or remote access |
| An obviously wrong sender address | A sender domain you have not verified independently |
| A far-fetched story | Any deadline that pressures you to act now |
The Other Number in the Same Release
The 90% figure gets the headline. The 75% figure is arguably more useful. More than 75% of all cyber breaches in the country begin with a phishing email or a fraudulent message. Not a sophisticated technical intrusion. A message someone read and acted on.
That reframes where the risk actually sits. The weak point is rarely the bank’s systems. It is the thirty seconds between a message arriving and someone tapping a link. Which is also the good news. That is the one part of the chain you personally control.
Why This Matters Beyond Any Single Scam
Every individual scam documented here this month sits inside the larger trend. The fake version of the website you use to report scams. The fake car and health insurance ads on social media. Each one is a tactic, not the cause.
Understanding the 90% figure explains why these scams keep multiplying instead of being solved once. The tool generating them got dramatically better and cheaper. That is the whole story. The same shift produced the first $35 million voice clone heist, which happened here in the UAE. Five years later, the same trick is free.
Sources
- Khaleej Times: fraud rises in UAE during summer, holidaymakers lured with fake offers and AI scams — https://www.khaleejtimes.com/uae/fraud-rises-uae-holidaymakers-targeted-fake-offers-ai-scams
Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.





