UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day

UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day

UAE records 640K cyberattacks in a single day as deepfakes raise new threats. Image: David Pupăză/Unsplash

The UAE faced 640,000 cyberattacks in one day, its cyber chief says, highlighting risks from unpatched software, ransomware, and deepfakes.

Verfasst von
Aminu Abdullahi
Aminu Abdullahi
Sep 18, 2026

The UAE faced 640,000 cyberattacks in a single day, according to the country’s cybersecurity chief, underscoring the scale of threats aimed at governments, businesses, and critical infrastructure.

Mohamed Al Kuwaiti, chairman of the UAE Cybersecurity Council, disclosed the figure during the Arab Media Summit in Dubai. He said threats increasingly extend across electricity, water, operational technology, and other economically important systems, while attackers are also using ransomware, artificial intelligence, and manipulated content.

The attacks have targeted critical areas including electricity, water, operational technology and the wider economy, according to Al Kuwaiti. He said the potential damage is no longer limited to temporarily taking services offline.

“Awareness is the first line of defence,” Al Kuwaiti said during the session, per Khaleej Times, stressing the need for people to check the source of information before sharing it.

The warning comes as the UAE faces attacks using ransomware, data breaches and artificial intelligence. The UAE Cyber Security Council also said in August that national teams had detected and contained organized attacks aimed at aviation, energy and education sectors.

$5 million ransom after software flaw

Al Kuwaiti also described an attack on an unnamed private-sector organization that supports a UAE government sector.

The hacker reportedly exploited an unpatched software vulnerability to gain access to the organization’s systems and data before demanding more than $5 million. The attacker threatened to release stolen information online, with some material later appearing on Telegram and the dark web.

Cooperation between government agencies, the private sector and international organizations helped contain the incident and limit the exposure of sensitive information, officials said. The episode points to a familiar but costly security problem: an overlooked software vulnerability can become an entry point into systems connected to critical government operations.

Must-read security coverage

Advertisement

Deepfakes turn cybersecurity into a human problem

Al Kuwaiti also warned that attackers increasingly have another target: public perception. He described misinformation, rumors and deepfakes as elements of what he called fifth-generation warfare, where decentralized actors can use digital tools to influence communities without directly attacking infrastructure.

“A single person can, through fabricated or fake information, influence society and change the course of events,” Al Kuwaiti said.

He cited a case involving a schoolgirl who was bullied and blackmailed using digitally manipulated images. The incident forced her to leave school for about a year while undergoing rehabilitation, according to Khaleej Times.

Why technical defenses are not enough

The UAE’s experience suggests cybersecurity now extends well beyond defending a traditional network perimeter, with organizations also facing social engineering, manipulated media, and rapidly spreading misinformation.se or malicious information can move.

That creates a difficult problem for businesses. Security teams can patch software, monitor networks and block suspicious activity, but they cannot fully prevent employees, customers or the public from encountering convincing fake content.

Artificial intelligence could help authorities identify and respond to false information faster, Al Kuwaiti said, but he stressed that human judgment remains necessary. He also urged media organizations, influencers and ordinary users to verify information through official and trusted sources.

For businesses, keeping software updated remains essential, but cybersecurity programs increasingly need to account for social engineering, manipulated media, and the possibility that a single compromised account or careless action can amplify a much larger attack.

Advertisement

More news: Google patched a high-severity Pixel modem zero-day after detecting limited, targeted exploitation, while CISA gave affected federal agencies just three days to remediate the vulnerability. 

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.