In 2024, cyber threats against the UAE and the wider Gulf reached a new level. Ransomware incidents targeting UAE organisations surged sharply year-on-year, the country faced an estimated hundreds of thousands of attacks a day, and hacktivist and state-linked groups turned the region into a front line. Below are the incidents and trends that defined the year — and the lessons every UAE business should take from them.

1. Hacktivist DDoS hits UAE banking

  • Who: Anonymous Sudan (a hacktivist group widely assessed as state-aligned)
  • Technique: large-scale distributed denial-of-service (DDoS)
  • Impact: In March 2024, a wave of DDoS attacks temporarily disrupted online and mobile banking at several major UAE banks, including First Abu Dhabi Bank, RAKBANK and Mashreq.

Lessons for businesses
– DDoS is about availability — even without a data breach, downtime damages trust and revenue.
– Put DDoS protection and traffic scrubbing in front of customer-facing services.
– Rehearse a communications plan for outages; silence erodes confidence faster than the outage itself.

2. The ransomware surge

  • Who: LockBit and Stormous were among the most active groups targeting UAE government and private-sector entities.
  • Technique: ransomware with double extortion (encrypt + steal-and-leak).
  • Impact: Industry reports describe a steep rise in UAE ransomware incidents through 2024 across multiple sectors.

Lessons for businesses
– Assume when, not if. Maintain tested, offline backups and a written incident-response plan.
– Double extortion means backups alone aren’t enough — data theft still hurts; reduce what attackers can reach.
– Patch internet-facing systems fast; ransomware crews favour known, unpatched vulnerabilities.

3. Destructive and state-linked threats

  • Who: Iran-linked groups such as Handala operated across the Gulf.
  • Technique: wiper malware designed to destroy data, not just ransom it.
  • Impact: Geopolitical tension translated directly into destructive cyber activity against regional targets.

Lessons for businesses
– Some attackers want destruction, not payment — recovery capability is your last line of defence.
– Segment networks so a single compromise can’t reach everything.
– Treat critical infrastructure and OT environments as high-priority, separately hardened zones.

4. The regional picture

Across the GCC, DDoS dominated the incident mix, phishing volumes against regional organisations stayed high, and credential theft fed many of the year’s intrusions.

Lessons for businesses
– Phishing remains the number-one way in — combine simulations with awareness training.
– Enforce phishing-resistant multi-factor authentication everywhere it counts.
– Monitor for leaked credentials and enforce strong, unique passwords.

Goodbye 2024

2024 confirmed what regional security teams already knew: the UAE is a high-value target, and attackers are well-resourced and persistent. The organisations that came through best weren’t the ones with the most tools — they were the ones that had tested their defences, segmented their networks, and aligned with frameworks such as NESA/SIA, Dubai’s DESC (ISR) and the UAE PDPL. That’s the posture to carry into 2025.

Want to know how your organisation would hold up against the threats that defined 2024? A Rootsec penetration test or red team operation shows you — before an attacker does. Book a free consultation.