Missiles crossed the Gulf in February, and hackers armed with artificial intelligence followed.
The United Arab Emirates has detected and contained coordinated cyberattacks on the aviation, energy, and education sectors since February, when fighting began between Iran, Israel, and the U.S., the country’s Cyber Security Council said on August 10. Hackers have made about 800,000 attempts a day since February, four times the prewar level.
AI is writing the hackers’ phishing emails, hunting for flaws in software, and building malicious programs faster than the teams guarding those systems can close the gaps, said the council. Speed is what has changed most, because a weakness that once took days to turn into a working attack can now be exploited within hours, according to security firms working across the Gulf.
Iranian hackers have used AI at every step during the war, from choosing targets to writing malicious code and fake messages that get people to click, according to the Center for Strategic and International Studies, a Washington-based research group. On August 18, the U.S. Justice Department charged 17 Iranians over a campaign running since 2013 that prosecutors say stole research and designs from 144 U.S. universities and 42 companies.
“AI is now influencing almost every stage of a cyberattack,” Ram Narayanan, Middle East country manager at Israeli cybersecurity firm Check Point Software Technologies, told Rest of World. “The biggest change is speed. In some cases, the time between a vulnerability being disclosed and attackers trying to exploit it has fallen from days to just hours.”
The attacks on the UAE have come from about 20 countries and more than 40 organizations, including groups with links to Iran, Mohamed Al Kuwaiti, head of the Cyber Security Council, said in April.
U.S. cybersecurity company Palo Alto Networks has also tracked a rise in AI-assisted scams, password theft, and fake company websites across the Gulf since February. Telecoms, energy, and government services make the most tempting targets, because knocking them out causes damage that spreads well beyond the first victim, Haider Pasha, the company’s chief security officer for Europe, the Middle East, and Africa, told Rest of World.
The UAE has put government services and banking online, and runs its power grid on computer networks, as the U.S. and Europe are now doing.
Different attacks, different targets #
The Cyber Security Council has announced each incident and set out the methods used against it, such as ransomware aimed at government platforms, phishing runs at banks, and break-in attempts on street cameras. Check Point identified the camera campaign separately and traced it to Iranian hackers.
Here is a timeline of the attacks reported in the UAE and its neighbors this year:
February 2026: The UAE’s cybersecurity systems repelled attacks described as terrorism-related, involving attempts to break into government platforms and plant ransomware. The attackers used AI to build their tools, the council said.
Check Point traced break-in attempts on internet-connected cameras in the UAE, Qatar, Kuwait, and Bahrain to Iranian hackers, starting February 28, the day the war began. The researchers assessed that the operators wanted footage to correct missile targeting and estimate damage after strikes.
April 2026: Al Kuwaiti said there were about 800,000 hacking attempts on the UAE per day, up from as many as 200,000 before the war.
July 2026: National teams detected and contained attacks on financial firms involving phishing, software flaws, and malicious code, with no disruption to services. The attackers used AI to make the methods more complex, the council said.
August 2026: National teams tracked the attack paths behind coordinated attacks on aviation, energy, and education, stopping the intrusions before they spread, the council said.
Iranian-linked groups have been trying out AI to write the programs they use to break into systems, according to Trellix, a U.S. security firm working in the Middle East. Humans still pick the targets and set the timing, and the technology scans for weaknesses and writes the code, Trellix researchers said.
“State-sponsored actors treat artificial intelligence as a practical force multiplier rather than a fully autonomous weapon,” Vibin Shaju, Trellix’s vice president of solutions engineering for the region, told Rest of World.
The UAE fights back #
Analysts working in shifts have held the line so far, reading alerts as they arrive and deciding which ones to act on, the council said in July. Those teams share what they see with government bodies, banks, and outside security firms.
The analysts work out of a national operations center set up under the country’s cybersecurity strategy, which collects alerts from across the government in one place. The AI systems designed to work alongside them are part of a program the country started in May.
The UAE launched the “Cyber Factory” initiative on May 12, run by the council and CPX Holding, its national strategic cybersecurity partner, to design and build AI security systems. The aim is to anticipate, detect, and respond to attacks with greater speed and precision, and to give the UAE end-to-end ownership of its defenses, the council said.
The initiative is part of a wider push for what the council calls national cyber sovereignty — making the tools at home instead of buying them abroad.
“The UAE Cyber Factory brings together local talent, advanced engineering, and innovation built in the UAE,” Hadi Anwar, chief executive officer of CPX, said at the launch.
Cyber Factory is working on closing the gap in speed that opened this year. Attackers have automated their work and scaled it up, and defenders need technology that moves just as fast, Narayanan said.
“In many areas, we are already moving toward machine-to-machine cyber conflict,” he said.