The UAE’s rapid shift from technology consumer to regional innovation hub has come with a corresponding rise in the sophistication of attacks targeting it. Phishing remains the most common way those attacks begin, and UAE regulators have responded by moving cybersecurity from a voluntary best practice to a mandatory compliance requirement with real financial and legal consequences for businesses that fall short.
This guide covers how common phishing has become in the UAE, what current regulation expects from businesses, and what to know before running a phishing simulation program of your own.
In Short: Phishing attacks in the UAE rose more than 21 percent in a single quarter of 2025, and the UAE Cyber Security Council attributes more than 75 percent of cyber breaches to phishing emails. Businesses operating in the UAE now face mandatory cybersecurity frameworks, including PDPL and NESA, that increasingly expect documented evidence of security awareness efforts.
How Common Is Phishing in the UAE
Phishing remains the dominant entry point for cyberattacks against UAE organizations, and the trend is accelerating. According to Eventus Security, citing the UAE Cyber Security Council directly, more than 75 percent of cyber breaches in the UAE start with phishing emails, and the Council confirmed 128 distinct cyber threat incidents targeting UAE entities within just the first six weeks of 2026 alone.
Separately, according to Chambers and Partners’ 2026 Global Practice Guide on UAE cybersecurity, citing Kaspersky research, phishing attacks in the UAE surged 21.2 percent in the second quarter of 2025 alone. The same analysis notes these are no longer generic mass emails: attacks are increasingly AI-enhanced, tailored to the specific victim or environment, and in more sophisticated cases, attackers breach an environment first, exfiltrate real emails, and use them to train AI models that generate a more convincing, personalized attack plan.
Emerging Techniques Specific to the UAE’s Cloud-Heavy Sectors
A specific, growing technique in the UAE deserves particular attention: adversary-in-the-middle, or AiTM, phishing. Unlike traditional credential phishing, AiTM attacks intercept login sessions and authentication tokens in real time, allowing attackers to bypass multi-factor authentication entirely rather than trying to defeat it directly. This technique specifically targets cloud-heavy sectors such as energy, finance, and enterprise IT, relying on legitimate-looking cloud login flows that are especially effective against UAE organizations built heavily around Microsoft 365 and similar platforms.
Business email compromise has grown alongside this trend, targeting finance teams, executives, suppliers, and invoice workflows directly. These attacks typically involve no malware at all, relying entirely on social engineering, urgency, and a believable email exchange, often through a hijacked real account rather than an obviously fake one. Multi-channel attacks combining email with deepfake voice cloning to impersonate trusted executives have also been documented, a pattern covered in more depth in our roundup of the top 10 deepfake video call scams.
What UAE Regulation Expects From Businesses
The UAE’s regulatory environment has shifted decisively from voluntary guidance to mandatory, enforced compliance. The Personal Data Protection Law, Federal Law No. 45 of 2021, establishes data localization, transfer restriction, and security requirements, with fines reaching up to 20 million UAE dirhams for serious violations. Healthcare data specifically must generally remain within UAE borders unless special arrangements are made.
For government entities and Critical Information Infrastructure operators, the National Electronic Security Authority’s Information Assurance Standards set a binding baseline, comprising 188 individual controls, with 39 designated as mandatory Priority 1 controls covering identity and access management, patch management, data classification, and incident response readiness. Businesses operating within Dubai’s DIFC or Abu Dhabi’s ADGM financial free zones face their own additional data protection regimes, closely aligned with GDPR standards and subject to active regulatory enforcement.
Regulators increasingly look for evidence of a functioning security management system during audits, not just the presence of technical tools. Organizations that cannot document how security decisions were made, risks were assessed, and past incidents were handled struggle to demonstrate compliance even when their actual technical security posture is reasonable. Regular, documented security awareness training, rather than an annual compliance checkbox exercise, is specifically highlighted as an expectation across multiple current UAE regulatory guidance sources.
A Note on Language and Templates
Businesses in the UAE often operate with a mix of Arabic-speaking and English-speaking staff across different roles and functions. It is worth noting directly: PhishCare’s phishing simulation templates are currently available in English only, without native Arabic-language template support. Organizations with a significant Arabic-speaking workforce should factor this into planning a testing program, and may want to consider supplementing English-language simulation with separately developed Arabic awareness materials for the parts of their workforce where this matters most.
What This Means for Testing Your Team
A few practical considerations follow specifically from the UAE’s current landscape:
Test for AiTM-style scenarios, not just static credential phishing. Since these attacks bypass MFA by intercepting live sessions rather than stealing a password directly, awareness needs to cover login flows that look completely legitimate, not just obviously suspicious pages.
Finance and executive-adjacent roles warrant dedicated testing, given how consistently business email compromise targets these functions specifically in current UAE threat data.
Document testing evidence with NESA and PDPL expectations in mind. Regulated entities and CII operators in particular benefit from treating simulation results as part of an ongoing, documented security management system rather than a one-off internal exercise.
Understand what phishing actually is before building a program, since regulatory guidance increasingly distinguishes genuine security awareness efforts from checkbox compliance. Our guide on what phishing is and how it works covers this foundation.
Cover voice-based social engineering explicitly, given the documented use of deepfake voice cloning in UAE-targeted attacks. Our guide on vishing simulation platforms covers this pattern in more depth.

Building a Testing Program
Given how quickly UAE-specific threats are evolving toward AI-enhanced and multi-channel techniques, generic phishing templates built for a different market are unlikely to reflect the real risk UAE businesses actually face. Running a phishing test for employees that includes realistic, current scenarios gives a far more accurate picture of organizational readiness than generic corporate templates alone.
Tracking results over successive campaigns through an employee phishing risk score also produces exactly the kind of ongoing, documented evidence UAE regulators increasingly expect to see during compliance audits, rather than a single point-in-time assessment.
FAQ
How common are phishing attacks in the UAE?
More than 75 percent of cyber breaches in the UAE start with phishing emails according to the UAE Cyber Security Council, and phishing attacks surged 21.2 percent in a single quarter of 2025 according to Kaspersky research.
What regulations should UAE businesses consider when running phishing simulation?
The Personal Data Protection Law (Federal Law No. 45 of 2021) governs data handling with fines up to 20 million dirhams for serious violations, while NESA’s Information Assurance Standards set mandatory security controls for government entities and Critical Information Infrastructure operators specifically.
What is adversary-in-the-middle (AiTM) phishing?
AiTM phishing intercepts live login sessions and authentication tokens in real time, allowing attackers to bypass multi-factor authentication without directly defeating it. It specifically targets cloud-heavy sectors like finance, energy, and enterprise IT in the UAE.
Does PhishCare offer Arabic-language phishing templates for UAE businesses?
Not currently. PhishCare’s templates are available in English only. Organizations with a significant Arabic-speaking workforce should factor this into their testing plans and may want to supplement with separately developed Arabic-language awareness materials where needed.
What should UAE businesses prioritize when building a phishing awareness program?
Testing should cover AiTM-style session hijacking, business email compromise targeting finance and executive roles, and voice-based social engineering, alongside documenting results in a way that supports NESA and PDPL compliance expectations.
Content Reviewed By

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.
He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.
View LinkedIn Profile







