UAE Cyber Security Council: 75% of Cyber Attacks Start With Phishing Emails

The UAE Cyber Security Council has warned that more than 75% of cyber breaches begin with phishing emails, as 3.4 billion fraudulent messages are sent daily targeting individuals and institutions worldwide.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
 Cybersecurity network illustration representing phishing email threats targeting UAE individuals and institutions

Cybersecurity network illustration representing phishing email threats targeting UAE individuals and institutions

The UAE Cyber Security Council has issued a warning about the growing risk of email fraud, urging individuals and institutions across the country to exercise caution regarding deceptive and fraudulent emails used by cybercriminals to breach accounts and steal financial data.

The Council confirmed to Emirates News Agency that more than 75% of cyber breaches begin with phishing emails or fraudulent messages containing malware, designed to steal login credentials or facilitate identity theft. The warning highlights the widespread nature of this threat, which exploits gaps in digital awareness and behaviour among users.

More than 3.4 billion phishing messages are sent daily, targeting individuals worldwide to steal personal and financial data, as well as sensitive information that may later be used to carry out cyberattacks, extortion, or ransomware operations.

The Council identified several indicators that can help identify phishing messages. These include requests for advance payments, pressure to take immediate action without time to think, requests for personal data without clear justification, suspiciously attractive offers, and invitations to log in via links from unknown sources. Messages containing spelling and grammatical errors are also among the most common signs of a phishing attempt.

For GCC enterprise security teams, the Council's warning carries direct operational relevance. Phishing remains the primary initial access vector across the region's banking, government, energy, and telecommunications sectors — a pattern consistently confirmed by threat intelligence reporting throughout early 2026. The elevated geopolitical threat environment has further intensified phishing activity, with Iran-aligned threat actors deploying AI-enhanced phishing lures against Gulf institutions since February 2026.

The Council advised citizens and residents to avoid clicking on suspicious or unknown links, refrain from scanning QR codes in public or untrusted locations, and maintain the confidentiality of personal information and login credentials. Organisations are urged to enable multi-factor authentication across all accounts, regularly update systems and applications, and immediately report any fraudulent or suspicious messages to security teams.

The Council emphasised that the human element remains the most critical link in any cybersecurity system. Rapid reporting of phishing attempts enables response teams to analyse threats and take preventive measures before serious security incidents occur. Suspicious messages in the UAE can be reported directly through the UAE official cybercrime reporting portal.

The statement reinforces a broader pattern of UAE government-led cybersecurity awareness initiatives in 2026, as the country's National Cyber Security Strategy 2025–2031 shifts focus from capacity building to active defence — with user behaviour and organisational resilience identified as priority areas alongside technical controls.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

GCC Threat Landscape 2026Cyber Awareness & Human RiskCompliance & Regulatory Strategy