UAE Blocks 600,000 Cyberattacks a Day as AI-Enabled Threats Target Vital Sectors

The UAE Cyber Security Council says the country blocks around 600,000 cyberattacks daily, with AI-enabled threats increasingly targeting aviation, energy and education.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
Cybersecurity analysts viewed from behind, monitoring threat dashboards in a modern SOC.

Cybersecurity analysts viewed from behind, monitoring threat dashboards in a modern SOC.

The scale of cyber threats facing the UAE has come into unusually sharp focus this week, with the country's top cybersecurity official disclosing figures that put a hard number on what has long been described only in general terms as a rapidly evolving threat landscape. According to Dr. Mohamed Al Kuwaiti, head of the UAE Cyber Security Council, the country blocks approximately 600,000 cyberattacks every day, a figure that breaks down to roughly 25,000 attacks per hour, or about 416 attacks every minute, close to seven every second.

That number deserves context rather than a flat read. As MCW has previously reported, the Council confirmed earlier in 2026 that daily attack volumes had already reached 600,000 to 800,000, a three to four times increase from the baseline recorded at the start of the year. This week's disclosure presents 600,000 without that framing, but for enterprise risk teams the distinction matters: this is an elevated, sustained volume that built up over the year, not a stable daily constant.

The disclosure came alongside confirmation from the Council that national cybersecurity teams had thwarted a series of advanced, organised cyberattacks specifically targeting the aviation, energy and education sectors. The Council said the attacks used multiple routes, including attempts to breach systems and digital infrastructure, targeting of accounts and operational data, and phishing campaigns that tried to use individual users as an entry point into the wider environment. Intrusion attempts were contained before attackers could achieve their objectives or affect the continuity of vital systems and services.

This is not an isolated event. It is the third time in 2026 the Council has disclosed a major sector-targeting campaign: in February, foiled attacks on vital sectors used ransomware; in July, an attack on the financial sector relied on phishing, vulnerability exploitation and AI-supported malware; and now, in August, aviation, energy and education were targeted through account compromise and phishing. The recurrence across different sectors and methods within a single year is itself a signal worth reading alongside the volume figures.

Al Kuwaiti was direct about what is driving the growing sophistication behind these attacks: artificial intelligence. He said the attacks vary widely in type and increasingly involve the use of AI to make them more complex and considerably harder to detect using conventional monitoring approaches, a dynamic MCW's coverage of AI-powered financial cyber risk has also flagged as reshaping the entry points attackers rely on, phishing chief among them.

The specific threat categories Al Kuwaiti outlined will be familiar to any enterprise security team, though the framing from a national authority carries particular weight. Phishing remains among the most common attack types the UAE contends with, alongside distributed denial-of-service attacks, ransomware, malware, and direct attempts to steal or destroy sensitive data. He also flagged two categories that deserve particular attention from enterprise risk teams specifically: zero-day attacks exploiting previously unknown software vulnerabilities before patches become available, and attacks specifically targeting digital supply chains rather than an organisation's own perimeter directly.

That supply chain emphasis is worth sitting with. A growing share of successful intrusions against well-defended organisations now originates through a trusted third-party vendor, contractor, or software dependency rather than a direct assault on the primary target's own systems, a pattern MCW examined in detail in the context of vendor-side breaches affecting GCC financial and government entities.

The sector targeting disclosed this week, aviation, energy and education, is itself instructive. These sectors share a common characteristic that makes them attractive targets regardless of the attacker's specific motive: each sits at the intersection of high public visibility and genuine operational fragility, where even a contained, unsuccessful intrusion attempt carries reputational and confidence costs beyond its technical impact.

Al Kuwaiti framed the UAE's defensive posture as resting on several pillars working together: proactive threat detection, continuously updated digital infrastructure, sustained investment in cutting-edge security technologies, and parallel investment in national cybersecurity talent and public awareness of security best practices, an approach set out in the UAE's compliance regime under the NESA framework.

For enterprises operating in the UAE, the practical takeaway is not the 600,000 figure itself but its trajectory and recurrence. Three separate sector-targeting campaigns in eight months, sustained by an elevated attack baseline and increasingly AI-assisted methods, is a different risk signal than a single disclosure would suggest. Organisations whose security investment still weights heavily toward perimeter and endpoint protection, without comparable attention to third-party and supply chain exposure, should treat this pattern as a signal to revisit that balance specifically.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

UAE national cyber defenceCritical infrastructure protectionAI-enabled threat landscape