2025 cemented the UAE’s position as one of the most targeted markets in the region. By mid-year, the country ranked among the most-affected in the Middle East and Africa for cyber activity, and across the region more than half of all attacks with a known motive were driven by extortion or ransomware. Here are the incidents and trends that defined the year — and the lessons that matter most.
1. The Dubai PCFC data leak
- Who: unattributed threat actor; data surfaced on leak channels.
- Technique: large-scale data exfiltration.
- Impact: A reported leak of roughly 1.94 TB of data tied to Dubai’s Ports, Customs and Free Zone Corporation — including highly sensitive identity documents such as passports and Emirates IDs.
Lessons for businesses
– Identity documents are gold to attackers — classify and encrypt sensitive data, and minimise what you store.
– Know where your most sensitive data lives; you can’t protect what you haven’t mapped.
– Government and critical-infrastructure suppliers are prime targets — hold your vendors to the same standard you hold yourself.
2. Ransomware against Dubai-based operations
- Who: the Crypto24 ransomware group.
- Technique: ransomware with large-scale data exfiltration.
- Impact: In July 2025, TransCore — a US company operating in Dubai — was reportedly hit, with more than 200 GB of internal data exfiltrated, including in-development source code and customer data.
Lessons for businesses
– Protect intellectual property and source code as carefully as customer data.
– Limit lateral movement so one foothold can’t become a full breach.
– Have a legal and regulatory playbook ready — under the UAE PDPL, breaches involving personal data carry notification obligations.
3. The ransomware and extortion economy
- Who: Everest was among the most active groups in 2025, alongside Medusa and Embargo.
- Technique: ransomware-as-a-service and pure extortion (steal-and-leak without encryption).
- Impact: Global ransomware rose sharply, and the Middle East saw notable increases in spyware and password-stealing malware.
Lessons for businesses
– Extortion-only attacks make data theft the main event — focus on detection and data protection, not just recovery.
– Watch for infostealers; stolen credentials are the fuel for the next breach.
– Run continuous monitoring (managed detection / XDR) — speed of detection decides the size of the loss.
4. The new way in: MFA bypass and AI-driven social engineering
- Who: a broad mix of criminal and state-linked actors.
- Technique: “MFA fatigue”, token theft, and AI-generated phishing and social engineering.
- Impact: In the UAE, attackers increasingly bypassed multi-factor authentication rather than passwords — aided by convincing, AI-driven social engineering.
Lessons for businesses
– Move to phishing-resistant MFA (passkeys / FIDO2); push-approval MFA is now routinely defeated.
– Train staff on MFA-fatigue and token-theft tactics — the attack has moved past the password.
– Assume AI makes phishing better and faster; test your people with realistic simulations.
Goodbye 2025
The pattern of 2025 was clear: extortion-led, identity-focused, and increasingly AI-assisted. The defining lesson isn’t any single breach — it’s that cybersecurity is now a boardroom issue and a matter of business continuity. The organisations that fared best treated security as an ongoing discipline: continuously tested, layered across endpoints, identity and network, and aligned with NESA/SIA, Dubai’s DESC (ISR) and the UAE PDPL. That’s the foundation to build on in 2026.
Don’t let your organisation become a 2026 headline. A Rootsec security assessment or red team operation shows you exactly where you stand. Book a free consultation.