Can Your Identity Stack Withstand the New Wave of AI Social Engineering?

As global threat actors pivot from traditional malware to sophisticated identity-based attacks, GCC enterprises face a critical juncture in securing their digital borders.

Layla Haddad
Cyber Policy & Digital Risk Correspondent2 min read
Can Your Identity Stack Withstand the New Wave of AI Social Engineering?

Can Your Identity Stack Withstand the New Wave of AI Social Engineering?

The paradigm of cybersecurity in the Middle East is shifting. While regional enterprises historically focused on perimeter defense and malware signatures, a more insidious threat is emerging: the weaponization of identity. Recent global breaches demonstrate that attackers no longer break in; they log in using stolen, phished, or spoofed credentials. For organizations in Dubai and Riyadh, where digital transformation is moving at a breakneck pace, this shift demands an immediate architectural response.

The GCC Growing Target Profile

Wealthy GCC economies are increasingly attractive targets for state-sponsored actors and cybercriminal syndicates alike. The sophistication of these attacks has escalated through the use of generative AI, which allows non-native speakers to craft perfect, culturally nuanced phishing lures in Arabic and English. This localizing of threats makes traditional awareness training less effective.

45%The average increase in credential-harvesting attempts targeting Middle Eastern financial institutions over the last 12 months.
  • Deepfake audio used to impersonate C-suite executives during high-value wire transfers.
  • Session cookie theft bypassing standard Multi-Factor Authentication (MFA).
  • Targeted LinkedIn campaigns aimed at regional energy sector engineers.
"The era of trusting a password and a simple SMS code is over. In the current threat environment, identity is the only true perimeter we have left to defend."
Cybersecurity Lead, Dubai International Financial Centre

Lessons for Regional CISOs

Global incidents involving companies like Okta serve as a blueprint for what MENA enterprises should expect. The focus must move toward 'Identity Threat Detection and Response' (ITDR). It is not enough to manage access; security teams must actively hunt for anomalies in user behavior that suggest a hijacked session.

Regional Regulatory Context

The UAE Cybersecurity Council and Saudi Arabia's National Cybersecurity Authority (NCA) have consistently updated their frameworks to emphasize Zero Trust Architecture. Local entities should align their identity governance with the [NCA Essential Cybersecurity Controls](https://nca.gov.sa/en/pages/ecc.html) to ensure compliance and resilience.

Actionable Steps for Identity Resilience

  1. Implement Phishing-Resistant MFA: Transition from SMS and TOTP apps to FIDO2-compliant hardware keys or biometrics.
  2. Adopt Continuous Adaptive Access: Assess the risk of every login attempt in real-time based on location, device health, and time of day.
  3. Automate Account Lifecycle Management: Ensure that 'ghost accounts'—those belonging to former employees or contractors—are purged immediately upon contract termination.

As we look toward 2025, the winners in the regional cyber landscape will be those who treat identity not as an administrative task, but as a core security discipline. The objective is to make the cost of attack higher than the potential reward for the adversary.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.