2025 cemented the UAE’s position as one of the most targeted markets in the region. By mid-year, the country ranked among the most-affected in the Middle East and Africa for cyber activity, and across the region more than half of all attacks with a known motive were driven by extortion or ransomware. Here are the incidents and trends that defined the year — and the lessons that matter most.

1. The Dubai PCFC data leak

  • Who: unattributed threat actor; data surfaced on leak channels.
  • Technique: large-scale data exfiltration.
  • Impact: A reported leak of roughly 1.94 TB of data tied to Dubai’s Ports, Customs and Free Zone Corporation — including highly sensitive identity documents such as passports and Emirates IDs.

Lessons for businesses
– Identity documents are gold to attackers — classify and encrypt sensitive data, and minimise what you store.
– Know where your most sensitive data lives; you can’t protect what you haven’t mapped.
– Government and critical-infrastructure suppliers are prime targets — hold your vendors to the same standard you hold yourself.

2. Ransomware against Dubai-based operations

  • Who: the Crypto24 ransomware group.
  • Technique: ransomware with large-scale data exfiltration.
  • Impact: In July 2025, TransCore — a US company operating in Dubai — was reportedly hit, with more than 200 GB of internal data exfiltrated, including in-development source code and customer data.

Lessons for businesses
– Protect intellectual property and source code as carefully as customer data.
– Limit lateral movement so one foothold can’t become a full breach.
– Have a legal and regulatory playbook ready — under the UAE PDPL, breaches involving personal data carry notification obligations.

3. The ransomware and extortion economy

  • Who: Everest was among the most active groups in 2025, alongside Medusa and Embargo.
  • Technique: ransomware-as-a-service and pure extortion (steal-and-leak without encryption).
  • Impact: Global ransomware rose sharply, and the Middle East saw notable increases in spyware and password-stealing malware.

Lessons for businesses
– Extortion-only attacks make data theft the main event — focus on detection and data protection, not just recovery.
– Watch for infostealers; stolen credentials are the fuel for the next breach.
– Run continuous monitoring (managed detection / XDR) — speed of detection decides the size of the loss.

4. The new way in: MFA bypass and AI-driven social engineering

  • Who: a broad mix of criminal and state-linked actors.
  • Technique: “MFA fatigue”, token theft, and AI-generated phishing and social engineering.
  • Impact: In the UAE, attackers increasingly bypassed multi-factor authentication rather than passwords — aided by convincing, AI-driven social engineering.

Lessons for businesses
– Move to phishing-resistant MFA (passkeys / FIDO2); push-approval MFA is now routinely defeated.
– Train staff on MFA-fatigue and token-theft tactics — the attack has moved past the password.
– Assume AI makes phishing better and faster; test your people with realistic simulations.

Goodbye 2025

The pattern of 2025 was clear: extortion-led, identity-focused, and increasingly AI-assisted. The defining lesson isn’t any single breach — it’s that cybersecurity is now a boardroom issue and a matter of business continuity. The organisations that fared best treated security as an ongoing discipline: continuously tested, layered across endpoints, identity and network, and aligned with NESA/SIA, Dubai’s DESC (ISR) and the UAE PDPL. That’s the foundation to build on in 2026.

Don’t let your organisation become a 2026 headline. A Rootsec security assessment or red team operation shows you exactly where you stand. Book a free consultation.