Skip to content
Monday, 24 August 2026 Dubai · GST
UAE, UNFILTERED
AI News

A Single Virus Could Hit UAE Critical Services

About 600,000 cyberattacks a day. That is the current average the UAE is absorbing, according to the country’s cybersecurity chief.

Share this story

About 600,000 cyberattacks a day. That is the current average the UAE is absorbing, according to the country’s cybersecurity chief.

But the number is not the most important part of the warning. Dr Mohamed Al Kuwaiti says cyberwarfare has moved far beyond stolen passwords and noisy website attacks. In the wrong place, one malicious program could interfere with an airport, a power system or a water network. Recent attacks on UAE aviation, energy and education also show how attackers are trying to get closer to the systems behind daily life.

The Robius Action Brief
Important
Why it matters

The cyber risk is shifting from stolen data toward disruption of services UAE residents and businesses depend on every day.

Who should care

UAE companies, infrastructure operators, IT teams, SMEs, employees and anyone whose account can become an entry point into a larger network.

Opportunities

The threat is creating demand for stronger incident response, identity security, segmentation, cyber resilience and AI-assisted defense across UAE organizations.

Risks or limitations

Attack-volume figures show pressure, not successful compromise, and public reporting does not identify every target, attacker or technical method.

What happens next

UAE authorities are expected to keep expanding national monitoring, response and information-sharing capabilities as attacks remain elevated.

What you can do

Use phishing-resistant MFA where possible, patch exposed systems, review vendor access, separate admin accounts and test offline recovery rather than assuming a cloud backup is enough.

Who benefits

Organizations that separate business IT from operational systems and treat identity, vendor access and backups as infrastructure controls gain the clearest resilience advantage

What readers should monitor

Watch for confirmed service disruption, new sector-specific advisories and official details on how recent campaigns moved from corporate accounts toward operational environments.

The Attack Count Is the Headline. The Boundary Is the Story

Al Kuwaiti told Khaleej Times that the UAE is currently facing around 600,000 cyberattacks each day, rising to around 800,000 a day at the peak of the recent regional conflict. Gulf News reported the same current average on August 11, equivalent to roughly 25,000 attempts an hour.

Those figures are dramatic, but they can also mislead if they are read as 600,000 successful hacks. They are not. Cybersecurity platforms block huge numbers of scans, probes, phishing attempts, automated requests and malicious traffic. The useful question is how far a serious attacker gets after the first barrier fails.

That is where the recent UAE cases become more important. On August 10, the Cyber Security Council said organized attacks had targeted aviation, energy and education. The National reported that the campaigns included attempts to breach digital infrastructure, operational accounts and data, alongside targeted phishing.

WIRED Middle East later reported, after interviewing Al Kuwaiti, that a limited number of corporate accounts and devices were compromised in a campaign the council assessed as state-aligned espionage. The attackers were stopped before reaching systems that control essential services.

That difference matters. A compromised mailbox is serious. A compromised operational control environment is a different class of event. The national warning is really about keeping those two worlds separated when attackers are actively looking for a bridge.

The Human Account Is Still Part of the Infrastructure

One of the most uncomfortable details in the August 10 disclosure is that the attackers tried to exploit users as entry points. That means the person receiving a convincing message can sit on the same attack path as a firewall, a VPN gateway or a vulnerable server.

AI makes that social layer harder. Al Kuwaiti has repeatedly warned that AI is increasing the sophistication and speed of attacks. The same technology that helps defenders analyze anomalies can also help attackers write more convincing phishing, automate reconnaissance and generate fake media at scale.

Robius has already covered the practical side of that problem in our UAE deepfake warning.

Why Aviation, Energy and Water Change the Risk Calculation

Critical infrastructure is not just another collection of laptops. Airports, utilities and large industrial systems combine normal corporate IT with operational technology, specialist devices, control systems, contractors and old equipment that may stay in service for years.

That creates an asymmetry. An office computer can often be replaced or reimaged. A control system may have to stay available while engineers contain the problem. The cost of getting the response wrong can be downtime, safety risk or interruption to a service used by thousands of people.

Al Kuwaiti’s warning about airports, power and water should therefore be read as a resilience warning, not a prediction that one of those services is currently compromised. The public evidence says recent attacks were contained before continuity of vital services was affected.

This is the Robius layer: the best cyber defense is no longer only about preventing entry. It is about designing the environment so that one stolen account, one infected laptop or one compromised supplier cannot travel far enough to become a national-service problem.

AI Is Now on Both Sides of the Fight

The UAE is not responding with awareness campaigns alone. In May, the Cyber Security Council and CPX launched the UAE Cyber Factory, intended to develop next-generation cybersecurity capabilities using advanced technology and AI-powered systems.

The country has also formalized cybersecurity information sharing. The UAE Government’s Cyber Security Information Sharing Framework, updated in July, is designed to support near real-time sharing of cyber information among national stakeholders.

That matters because a campaign hitting an airline, a utility and an education network may reuse infrastructure, phishing methods or indicators. A defense that learns across sectors can move faster than teams working in isolation.

But AI does not remove the old disciplines. It can prioritize alerts and find patterns. It cannot compensate for an administrator using the same privileged account everywhere, an exposed remote-access tool, or a backup that has never been tested.

What UAE Businesses Should Do Before the Next Alert

For a large operator, the work is technical and continuous. For an SME, the priorities can be simpler. Separate administrator accounts from everyday accounts. Require strong MFA. Remove old remote-access credentials. Patch internet-facing systems quickly. Know which third parties can enter your network.

Then test recovery. A backup that exists but cannot be restored under pressure is not resilience. Keep at least one recovery path that is isolated from normal production credentials and document who can activate it.

Staff awareness also needs to move beyond generic warnings. Employees should know what an unusual payment request looks like, how to report a suspicious login and who to call when a message appears to come from a senior manager.

We have seen the same identity problem in consumer fraud. Our WhatsApp job scam guide shows how quickly a convincing message can turn one employee into an entry point.

The Warning Is Serious. The Evidence Also Shows the Defenses Worked

There is a danger in covering cybersecurity with permanent panic. The August attacks are not evidence that UAE critical infrastructure has failed. The available reporting says the opposite: the campaigns were detected and contained before vital services were disrupted.

That is an important fairness point. Attack pressure is high, and attackers are probing sectors where disruption would matter. At the same time, the UAE’s national systems have repeatedly reported stopping those attempts before operational impact.

The next threshold to watch is not whether the daily attack counter rises from 600,000 to 700,000. It is whether a future campaign crosses the boundary the latest one did not.

That boundary sits between ordinary compromise and operational consequence. Right now, that is where the real cyber story in the UAE is.

For the wider policy layer, see our coverage of the UAE AI and Data Authority and our Arabic AI test.

Sources

Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.

About the author

Roland Guirdonan

Roland Guirdonan is the founder of Robius.news and Optimisus.com, UAE-based digital media properties covering consumer technology, AI, fintech, and crypto. Based in Dubai, Roland covers the intersection of technology and everyday life for UAE residents.

View all articles →