UAE Experts Warn Deepfake Fraud Is Fuelling Unlicensed Trading Platform Scams

UAE cybersecurity and legal experts warn that deepfake technology is fuelling a surge in unlicensed trading platform fraud, with victims losing up to AED 200,000.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
A smartphone showing a video call interface beside a laptop on an office desk, representing deepfake-enabled investment fraud

A smartphone showing a video call interface beside a laptop on an office desk, representing deepfake-enabled investment fraud

Investment fraud is not a new category of cybercrime, but the specific technical sophistication now being deployed against victims in the UAE marks a genuine shift, one with implications reaching well beyond the individual consumers currently bearing the financial losses. UAE cybersecurity, legal and psychological experts have jointly warned that organised criminal networks are increasingly using deepfake technology to lend false credibility to unlicensed trading platforms, and the losses being reported are substantial enough to warrant enterprise attention, not just consumer caution.

The pattern documented by authorities follows a consistent structure. Victims are approached through WhatsApp, Telegram, Instagram or similar messaging and social platforms, often by individuals claiming affiliation with legitimate investment brokers. They are drawn into groups promising returns on trading activity across gold, oil, commodities, currencies, cryptocurrencies and indices, frequently receiving small initial payouts designed specifically to establish trust before being persuaded to commit significantly larger sums. Documented individual losses range from AED 85,711 up to AED 200,000, concrete figures that move this well past anecdotal concern into a measurable financial threat.

Cybersecurity expert Abdul Noor Sami detailed the specific technical infrastructure fraudsters are now deploying at scale: professionally produced promotional videos, deepfake technology used to convincingly imitate trusted public figures, polished websites and applications, and always-available chatbots handling victim interaction around the clock. Many of these platforms construct entirely fabricated trading interfaces and data streams with no connection to actual financial markets or assets whatsoever, meaning the "trading activity" a victim observes is theatre built specifically to sustain the fraud long enough to extract maximum funds.

The deepfake element deserves particular attention from enterprise security and communications teams specifically, not just individual investors. Deepfake-enabled impersonation of trusted figures has already emerged globally as a vector for a related but distinct threat: executive impersonation fraud, where finance or operations staff are deceived by convincing audio or video impersonating a senior leader authorising an urgent wire transfer or sensitive disclosure. Enterprises that have already begun tightening identity and access management practices across their organisation should treat this as a reminder to extend that same verification discipline to how staff authenticate video and voice requests from senior leadership, not just system logins. The same underlying technology and criminal infrastructure documented in this consumer-fraud context, professional-grade deepfake production, organised operational teams with specialised roles, cross-jurisdictional fund movement designed to frustrate recovery, is directly transferable to corporate-targeted fraud, and UAE enterprises should treat this warning as a signal about capability that exists in the wild right now, not solely a retail investor problem.

Psychological consultant Dr Medhat Al-Sabahi identified eight specific factors fraudsters exploit systematically: the desire to improve financial circumstances, fear of missing out, excessive self-confidence, reliance on perceived credibility, social proof through peer influence, gradual commitment and escalation, excessive optimism, and underlying economic or psychological pressure. Framing fraud vulnerability around these specific, named psychological levers rather than generic "awareness" is instructive for enterprise training programmes too. Employee-facing anti-fraud and social engineering training that names the specific manipulation techniques being used, rather than issuing generic warnings, tends to build considerably more durable resistance than broad caution advisories.

The legal exposure attached to this activity is concrete and specific. Lawyer Salem Obaid Al-Naqbi confirmed that individuals or entities knowingly promoting unlicensed trading platforms face both civil and criminal liability, including prosecution as accomplices to cyber fraud, compensation liability to victims, and penalties for misleading advertising. Article 48 of Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes specifically criminalises promoting goods or services through misleading online advertising, as well as advertising or encouraging dealings in unlicensed virtual or digital currencies, carrying penalties ranging from imprisonment to fines between AED 20,000 and AED 500,000, or both. Critically, this liability applies to anyone who promotes such platforms across digital channels, regardless of whether they operated the platform themselves. Lawyer Salem Saeed Al-Haiqi added that liability can extend to anyone promoting unlicensed investment platforms without adequately verifying their legal status, a detail worth flagging for any UAE business involved in marketing, affiliate partnerships, or influencer collaborations, since promotional relationships with unverified financial platforms carry genuine legal exposure under this framework, not merely reputational risk. Businesses collecting or processing customer data through these promotional channels should also weigh this against their obligations under the UAE PDPL compliance framework, since personal data harvested through a fraudulent platform's onboarding flow can itself become a separate liability chain entirely.

The Abu Dhabi Judicial Department separately warned against fake investment groups on social media using the same escalation pattern: initial rewards to build trust, followed by encouragement toward progressively larger transactions before the operators disappear with victim funds.

For UAE enterprises, this warning carries two distinct and equally relevant implications. First, employees are themselves potential targets, and the deepfake and social engineering techniques documented here are directly applicable to workplace-targeted fraud, including impersonation of executives for wire transfer authorisation or sensitive data requests. Second, the specific legal liability outlined for anyone promoting unlicensed platforms without adequate verification, whether or not they operated the platform themselves, is directly relevant to marketing, partnerships, and affiliate relationships, an area where due diligence processes may not currently account for this level of regulatory exposure. As deepfake technology continues to lower the barrier to convincing impersonation fraud, both employee awareness training and marketing compliance review deserve treatment as active, current priorities rather than theoretical future concerns.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Deepfake-enabled fraudUAE cybercrime legislationExecutive impersonation risk