Iran Conflict Fuels Sharp Surge in Cyberattacks on UAE

The United Arab Emirates has recorded a dramatic escalation in cyberattacks since the outbreak of the Iran-related conflict in late February 2026, with daily attack volumes roughly tripling from pre-war levels of around 200,000 to peaks of 600,000–800,000, according to the country’s top cybersecurity officials.
Dr Mohamed Al Kuwaiti, head of cybersecurity for the UAE government and chairman of the UAE Cyber Security Council, has repeatedly confirmed the surge. In statements earlier this year he noted the jump from approximately 200,000 daily incidents to about 600,000, later citing figures as high as 800,000 during peak periods and 640,000 on a single recent day.
Iran’s Islamic Revolutionary Guard Corps (IRGC) and affiliated groups are described as a primary driver. Al Kuwaiti has stated that Iran remains “one of the main players,” with the IRGC specifically linked to many of the operations. Attacks have originated from networks involving more than 40 organisations across roughly 20 countries, often operating through proxies.
The nature of the threats has evolved. State-linked actors are increasingly using artificial intelligence tools, including systems such as ChatGPT, to craft sophisticated phishing emails, identify software vulnerabilities faster, and develop malicious code. Traditional methods have given way to multi-stage campaigns that blend fraud, disinformation, ransomware, data wipers, and attempts to gain persistent access for espionage.
Critical sectors have been primary targets, including government administration, energy and oil facilities, aviation, finance, education, ports, and utilities. In several documented cases, national teams detected and contained coordinated intrusions into aviation, energy, and education networks before they could disrupt operational systems. Iranian-linked groups have also claimed cyber operations timed with physical strikes, such as attempts linked to drone attacks on Fujairah Port.
UAE officials emphasise that defences have held: digital borders remain secure, and no major disruptions to essential services have been reported in the contained campaigns. The country has responded by accelerating its own AI-powered detection and defence systems, strengthening cyber hygiene guidance for businesses and residents, and maintaining high alert levels even amid any pauses in kinetic fighting.
The parallel digital offensive underscores how the regional conflict has expanded beyond missiles and drones into a sustained cyber dimension, with officials warning that the elevated threat level is likely to persist.
Further Reads





