82% of GCC Enterprises Report Surge in AI-Enhanced Social Engineering Campaigns
New intelligence indicates that threat actors are leveraging localized large language models to bypass traditional security filters across UAE and Saudi financial sectors.

82% of GCC Enterprises Report Surge in AI-Enhanced Social Engineering Campaigns
Recent forensic telemetry across the Arabian Peninsula reveals a sophisticated shift in how threat actors target the region's digital infrastructure. As the UAE and Saudi Arabia accelerate their digital transformation agendas, cyber-syndicates are increasingly weaponizing artificial intelligence to craft hyper-localized phishing campaigns that resonate with regional cultural nuances.
The Linguistic Evolution of Social Engineering
Historically, regional security teams relied on identifying broken syntax or poor translations as markers for phishing. That era has ended. Threat actors now use advanced LLMs to generate flawless Arabic content in various dialects, including Khaleeji and Najdi, making it nearly impossible for employees to distinguish between legitimate corporate communications and malicious probes.
"The digital perimeter has dissolved into the identity layer. In the GCC, where high-value targets are frequent, identity is the only remaining firewall that matters."
Impact on Saudi Vision 2030 Infrastructure
The massive scale of Saudi Arabia’s giga-projects creates a unique risk profile. With thousands of third-party vendors integrated into a unified digital ecosystem, a single compromised identity can provide lateral access to critical national infrastructure. Security leaders must pivot from traditional signature-based detection to behavioral analytics that monitor for anomalous user activity.
Regional Regulatory Context
The Dubai Electronic Security Center (DESC) and Saudi Arabia’s National Cybersecurity Authority (NCA) have both updated their frameworks to emphasize continuous authentication and zero-trust architecture as the primary defense against AI-driven identity theft.
Strategic Mitigations for MENA Enterprises
- Deployment of FIDO2-compliant hardware security keys to eliminate the risk of credential harvesting.
- Implementation of AI-native email security layers that analyze the intent and sentiment of messages rather than just metadata.
- Adopting the [NIST Zero Trust Architecture](https://www.nist.gov/publications/zero-trust-architecture) to ensure that every access request is fully authenticated, authorized, and encrypted.
As we move toward 2025, the focus for regional security operations centers (SOCs) must shift toward proactive threat hunting. Organizations that continue to rely on legacy [MFA methods](https://www.cisa.gov/resources-tools/resources/multi-factor-authentication-mfa) like SMS-based codes will find themselves increasingly vulnerable to the next wave of automated session hijacking.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.