Agbi

rewrite this content and keep HTML tags as is: UAE thwarts cyberattacks on aviation, energy and education


rewrite this content and keep HTML tags as is:

  • Attack ‘advanced and coordinated’
  • Second major campaign in 2 months
  • July attempt linked to Iran

The UAE has thwarted “advanced and coordinated” hacking campaigns targeting its aviation, energy and education sectors, the country’s Cyber Security Council said.

The activity included attempts to breach digital infrastructure, access accounts and operational data, and use phishing campaigns to exploit staff as an entry point into organisations.

It is the second time in as many months that the council has disclosed a significant cyber campaign. On July 3, it said sophisticated intrusion attempts against financial-sector organisations had also been detected and contained.

The announcement follows a major cybersecurity report published earlier this month that found Iranian state-linked hackers had targeted academic and other organisations across the Middle East.

Static Kitten, an intelligence-gathering group linked to Iran, has sought access to universities using so-called spear-phishing emails – messages tailored to deceive staff into opening malicious files – according to analysis by US cybersecurity company CrowdStrike.

The council did not identify the attackers or say whether they were connected to a foreign government. Sam Tayan, director of sales for the Middle East, Turkey and Africa at cybersecurity company Illumio, declined to comment on whether Iran or Iran-linked actors were responsible, but placed the attacks in the context of wider regional instability.

“Cyber activity can become another means of applying pressure, gathering intelligence or creating uncertainty without crossing a physical border,” he told AGBI.

Publicising the successful response could also reassure businesses and the public, Tayan added. “At a time of heightened regional tension, this kind of transparency can help demonstrate that threats are being identified and contained, which is important for maintaining confidence in the systems and services people rely on.”

He said the announcements appeared intended to do more than notify the public that attacks had occurred. By revealing the sectors and methods involved, the council was giving organisations “practical intelligence they can use to strengthen their own defences”.

National cybersecurity teams traced the latest attack paths and contained the intrusions before the perpetrators achieved their objectives or disrupted vital systems and services, the council said in a statement on August 10.

Tayan said the disclosure of two major cyberattack campaigns in little more than a month pointed to a widening threat across the country’s critical industries.

“This deserves attention,” he said. “The UAE has faced a sharp increase in hostile cyber activity this year, but volume alone does not tell the full story.”

Analysts said in March that more than 60 hacker groups or collectives mobilised within hours of the start of the latest US-Israeli conflict with Iran. More than 100 cyber incidents were recorded across the Middle East in the first 72 hours.

The cyber world has long been contested by Iran and its adversaries. In 2016, suspected Iranian hackers successfully penetrated the Saudi foreign ministry, while the Stuxnet malware developed by the US and Israel disrupted centrifuges at Iran’s Natanz nuclear facility more than a decade ago.

Further reading:

Further reading:

Academic bodies are attractive to state-linked hackers because they hold sensitive research and intellectual property that align with national intelligence priorities.

Middle Eastern organisations accounted for 8 percent of all academic-sector cyber targeting observed globally between July 2025 and June 2026, according to CrowdStrike.

Mansour Alhmoud, Group-IB’s threat intelligence lead for the Middle East, Turkey and Africa, said companies should identify likely adversaries and their methods rather than wait for attacks.

“The shift is from asking, ‘How do we detect an attack?’ to ‘Who is my adversary and how do we stop them before they act?’” he said.

Artificial intelligence was allowing attacks to be developed, tailored and scaled more quickly by lowering the barriers to reconnaissance, convincing phishing campaigns and the automation of parts of the attack process, Tayan said.

“The lesson for organisations is that cyber risk can no longer be viewed purely as a crime or technology problem,” Tayan added. “It is increasingly tied to operational and geopolitical risk.”



Source link