Skip to content

AI making ransomware attacks more effective in UAE as employees fail to detect malicious attempts

83 percent of UAE ransomware victims say AI made attacks more effective, report finds
Share this article

More than eight in ten UAE organizations that suffered a ransomware attack in the past year say artificial intelligence made the assault more effective. Over a third admit their employees were deceived by AI-generated messages that appeared genuine. The data was reported in a new study released by cybersecurity firm Proofpoint on Wednesday.

AI is making attacks harder to spot and stop

Proofpoint’s findings suggest that ransomware in the Emirates has moved well beyond a simple encryption protocol and evolved into a sustained extortion campaign powered increasingly by AI tools that make phishing, impersonation and credential theft harder to identify and distinguish from regular business communication. 

Among UAE organizations hit by ransomware, 36 percent said AI significantly increased the effectiveness of the attack and a further 47 percent said it somewhat increased effectiveness, putting the combined figure at 83 percent. Only 9 percent reported no evidence that AI had played a role at all. 

Proofpoint said hackers are now using AI to draft more convincing phishing lures, write targeted impersonation messages, and carry out faster reconnaissance of an organization’s structure and communication patterns. 

“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” said Ryan Kalember, Chief Strategy Officer at Proofpoint. “Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organizations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

Phishing emails, QR codes, phone calls remain popular hacking methods 

The report found that the leading entry points into UAE companies were overwhelmingly dependent on human interaction. Phishing emails and other electronic mail methods served as the initial entry point in 30 percent of incidents. Malicious attachments were the most commonly identified initial threat cited in 57 percent of cases, followed by QR code phishing at 55 percent and telephone-based social engineering at 45 percent. 

Asked why ransomware was able to bypass their existing security controls, 36 percent of UAE firms said employees failed to identify these attempts as malicious since they appeared genuine. Meanwhile 30 percent pointed to users engaging directly with the phishing content. 

Paying the ransom doesn’t end the ordeal 

Despite years of guidance from law enforcement and security agencies advising against paying hackers, 81 percent of affected UAE companies paid a ransom. Yet nearly half of those that paid, around 41 percent, were still hit with a second extortion demand afterward. Proofpoint said this reflects how ransomware has shifted from a single payment event to an ongoing negotiation, with attackers holding multiple forms of leverage at once: continued disruption, stolen data and public disclosure. 

Data theft is the real cost that companies pay

More than four in five UAE organizations surveyed confirmed that data was stolen during their ransomware attack. Proofpoint said this shows a broader shift in which campaigns are less about disrupting systems and more about acquiring data, identities and persistent access that can be monetized through repeated demands, sold on criminal forums and dark web marketplaces. These are later used for more attacks by other bad actors. 

UAE faces a bigger challenge than other countries

The UAE reported the highest rate of AI-enhanced attack effectiveness among the 12 countries surveyed, at 83 percent, along with high ransom payments, at 81 percent. By contrast, user interaction was the biggest success factor in Japan and India, both at 49 percent, and Singapore at 48 percent. In these markets the biggest factor was users engaging with malicious content rather than being fooled by AI impersonation. 

UAE authorities issue warnings

The report lands alongside escalating warnings from the UAE Cyber Security Council. Earlier this month, the Council said the national cybersecurity ecosystem had contained a wave of sophisticated attacks on the financial sector, delivered through phishing campaigns and malicious software, and cautioned that criminals are increasingly turning to AI to develop more advanced techniques. The Council has also reported that daily attack attempts on the country’s digital infrastructure have roughly tripled this year to more than 600,000 amid heightened regional tensions. 

About The Coin Headlines

The Coin Headlines strives to bring trust into crypto media. At a time when every soundbite and headline can move the markets from red to green and vice-versa, The Coin Headlines promises to bring verified, credible and timely news and analysis from the world of crypto, blockchain, Web3, tech and markets. Founded in 2026, The Coin Headlines is based in the UAE with a team of experienced journalists and editors covering breaking news and updates from around the world.

From covering the biggest events to interviewing some of the most popular KOLs in the industry, The Coin Headlines keeps you informed of the latest trends and insights.

At The Coin Headlines our focus is clear: Real-time news updates, market movements, whale transfers, macroeconomic trends, tech and AI and geopolitical breaking news. The news we report goes through a strict editorial audit before its published to ensure the readers only get verified and credible information. We realize the world of crypto is dynamic, volatile, and many times, confusing. At The Coin Headlines we break down these complex issues into simple articles which cater to not just the experienced trader but also the student and first-time investor who wants to understand the space before committing to it.