UAE Discloses $5 Million Ransomware Demand Against Private-Sector Company
The UAE's cyber security chief has disclosed that a hacker demanded more than $5 million after breaching a private-sector company, with stolen data circulated on Telegram and the dark web.

A dimly lit office workstation with a laptop showing an abstract locked-file interface, representing a ransomware attack on a private company
A hacker demanded more than $5 million in ransom after breaching a private-sector organisation supporting a UAE government function, Dr Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government, revealed during a session titled "Media and Fifth-Generation Warfare" at the Arab Media Summit in Dubai. Al Kuwaiti described an attack that combined data destruction with an attempt to leak stolen information more broadly, and said the attacker contacted him directly by phone to make the demand.
"I got a phone call from the hacker, and he asked me to pay a ransom of more than $5 million," Al Kuwaiti said. He described the attacker as claiming detailed knowledge of the organisation's systems, having reportedly mapped its infrastructure and identified how to navigate it, and confirmed that stolen data was subsequently circulated across Telegram and the dark web, two distribution channels that have become standard practice for ransomware operators pressuring victims into payment through public exposure. Al Kuwaiti did not identify the company involved or specify when the incident occurred, though he separately disclosed the UAE had faced 640,000 cyberattacks in a single day, part of the same broader attack surge this site has tracked through the current regional conflict.
According to Al Kuwaiti, national authorities worked directly with the affected private-sector organisation to deter the attack and prevent further circulation of the leaked data. That detail is worth noting for what it signals about incident response coordination in the UAE specifically: a private company facing a live ransomware negotiation had direct access to government-level cybersecurity involvement, rather than managing the incident, and the decision on whether to pay, in isolation. That model of direct, hands-on coordination between national authorities and private victims is consistent with the containment approach that has already characterised the UAE Cyber Security Council's public disclosures this year, and it stands in contrast to the more common regional pattern of enterprises relying primarily on contracted managed detection and response providers for containment, with government involvement typically limited to critical infrastructure operators.
This disclosure adds a specific, named data point to a broader pattern of ransomware and cyber extortion activity the UAE has been documenting publicly across multiple sectors this year. It follows an August disclosure from the UAE Cyber Security Council describing detected and contained attacks against aviation, energy and education sector organisations, and a separate July disclosure covering attacks targeting financial institutions. Taken together with this latest private-sector ransomware case, the pattern spans critical infrastructure, financial services and now general private enterprise, indicating ransomware and extortion-focused threat actors are not concentrating on a single sector but testing across the UAE's economy broadly, a pattern this site has separately quantified in comparable BFSI-sector data showing financial institutions in rapidly digitalising economies face cyberattacks at 1.6 times the global average.
Al Kuwaiti separately addressed how artificial intelligence is being governed inside UAE government operations, offering figures worth registering alongside the ransomware disclosure. More than 50 percent of UAE government entities are currently automating various processes using AI, he said, with that automation built around ethical frameworks, compliance measures and oversight policies rather than deployed without governance structure. He characterised the overwhelming majority of AI interactions inside government operations as positive, citing a 95 percent figure, while acknowledging directly that the technology carries genuine potential for misuse alongside its benefits.
For enterprises operating in the UAE, particularly those outside the critical infrastructure and financial sectors already accustomed to heightened regulatory attention, this disclosure is a useful signal that ransomware targeting is not confined to sectors with obvious strategic value. A private company facing a seven-figure ransom demand, data destruction, and public leak threats represents exactly the kind of incident many mid-sized organisations assume applies primarily to banks, utilities or government bodies. Al Kuwaiti's willingness to disclose a specific dollar figure and describe the direct hacker communication in public remarks suggests the UAE's cybersecurity leadership is treating broad public awareness of ransomware's real financial stakes as a deliberate part of its national response strategy, not simply a technical matter handled quietly between affected companies and authorities.
The practical takeaway for organisations assessing their own ransomware readiness is straightforward. Incident response plans should assume direct contact from an attacker is a realistic scenario, not a hypothetical one, and should include a clear protocol for engaging national cybersecurity authorities early rather than attempting to manage a live extortion negotiation internally. Given that stolen data reaching Telegram and dark web forums is now a standard escalation tactic once initial ransom demands go unmet, organisations should also treat data exfiltration monitoring and rapid public-relations response planning as core components of ransomware preparedness, alongside the more commonly discussed technical recovery and backup restoration capabilities.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.