Product1 publisherNot yet confirmed elsewhere2 min readPublished
The UAE says attack attempts quadrupled to 800,000 a day. The number that matters is hours.
Exploit windows in the Gulf have fallen from days to hours, Check Point says. That breaks patch schedules and phishing training written for a slower adversary, whatever the AI labelling.
The Product Desk

What happened
- The UAE Cyber Security Council said on August 10 it had contained coordinated attacks on aviation, energy and education dating back to February's fighting between Iran, Israel and the U.S.
- The council put the rate at about 800,000 attempts a day since February, four times the prewar level.
- Check Point says the interval between a vulnerability being disclosed and attackers trying it has in some cases dropped from days to hours.
- Al Kuwaiti said in April the attacks came from roughly 20 countries and more than 40 organizations, some with links to Iran.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Anything scheduled in days, patch windows included, is now behind the attacker's clock on the cases that matter, so segmentation and credential limits carry weight the fix used to carry.
- cost The extra 600,000 attempts a day are paid for in tooling licences and rostered analysts long before any of them lands on a system.
- contradiction CSIS places AI at every stage including target selection; Trellix keeps targeting and timing human. Which reading holds decides whether you are defending against volume or against judgment.
- exposure Banking, government services and grid control now sit on networks in the U.S. and Europe too, which makes the UAE's incident log a schedule others can expect rather than a Gulf peculiarity.
Nine attempts a second [17] is not a figure a duty roster meets directly; it is a filtering budget. Analysts working in shifts have held the line so far, by the council's own account [5], which means the automation in front of them decides what a human ever sees. Escalation thresholds tuned when the inbound rate was a quarter of the current one are now, in practice, a sampling rate rather than a queue.
The phishing side decays quietly. Awareness training teaches staff to notice the tells of a hand-written lure, and the council describes mail that is composed by a model, alongside automated flaw hunting and malware assembly [2]. Palo Alto Networks reports the same drift across the Gulf toward AI-assisted scams, password theft and fake corporate sites [12]. A control that depends on the attacker being careless has a shelf life.
The reporting also contains its own brake. The 800,000 figure in the August 10 statement is the figure Al Kuwaiti had already given in April [20], so four months of public record show a plateau rather than a climb. And the July intrusions at financial firms, assembled from phishing, software flaws and malicious code, were contained with no disruption to services [3]. The attempt rate is where it was in spring; the disruption column is still empty.
Vibin Shaju of Trellix calls the state actors' use of the technology a practical force multiplier rather than a fully autonomous weapon [11], which is the operationally useful framing. Multipliers change tempo and volume, not intent, and intent is where defenders get planning leverage. Haider Pasha of Palo Alto Networks names telecoms, energy and government services as the most tempting targets precisely because taking them down spreads damage past the first victim [14]. That is a target list, and lists can be pre-staged against.
Set against the speed story: the Justice Department's August 18 indictment of 17 Iranians covers a campaign running since 2013 that prosecutors say took research and designs from 144 U.S. universities and 42 companies [9]. Thirteen years [19]. The expensive part of that case was persistence, not tempo. A program re-pointed entirely at the hours-scale window [8] leaves the slow campaign funded by nobody.
The camera intrusions are the detail worth keeping. Check Point traced attempts on internet-connected cameras in the UAE, Qatar, Kuwait and Bahrain to Iranian operators starting February 28, and assessed that they wanted footage to correct missile targeting and estimate damage after strikes [16]. The asset that mattered there sat outside the data centre, and it was not the kind of thing a patch calendar is built around.
What to watch
- Whether a future council disclosure reports actual service disruption rather than a contained intrusion.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence42
- Adoption48
- Hype gap+28
- Incentives72
- Confidence44
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The UAE Cyber Security Council said on August 10 that it had detected and contained coordinated cyberattacks on the aviation, energy and education sectors since February, when fighting began between Iran, Israel and the U.S.
ReportedSupportedSource: UAE Cyber Security Council, via Rest of World3 sources— create a free account to open themView cited source - [2]
The council said AI is writing the hackers' phishing emails, hunting for flaws in software and building malicious programs faster than the teams guarding those systems can close the gaps.
ReportedSupportedSource: UAE Cyber Security Council3 sources— create a free account to open themView cited source - [3]
In July, national teams detected and contained attacks on financial firms involving phishing, software flaws and malicious code, with no disruption to services; the council said the attackers used AI to make the methods more complex.
ReportedSupportedSource: UAE Cyber Security Council3 sources— create a free account to open themView cited source - [4]
The council said hackers have made about 800,000 attempts a day since February, four times the prewar level.
ReportedSupportedSource: UAE Cyber Security Council2 sources— create a free account to open themView cited source - [5]
Analysts working in shifts have held the line so far.
- [6]
In April, Cyber Security Council head Mohamed Al Kuwaiti said there were about 800,000 hacking attempts a day on the UAE, up from as many as 200,000 before the war.
ReportedSupportedSource: Mohamed Al Kuwaiti, head of the UAE Cyber Security Council2 sources— create a free account to open themView cited source - [7]
The Center for Strategic and International Studies said Iranian hackers have used AI at every step during the war, from choosing targets to writing malicious code and fake messages that get people to click.
ReportedSupportedSource: Center for Strategic and International Studies3 sources— create a free account to open themView cited source - [8]
Ram Narayanan, Middle East country manager at Check Point Software Technologies, said the time between a vulnerability being disclosed and attackers trying to exploit it has in some cases fallen from days to just hours.
ReportedSupportedSource: Ram Narayanan, Check Point, to Rest of World2 sources— create a free account to open themView cited source - [9]
On August 18 the U.S. Justice Department charged 17 Iranians over a campaign running since 2013 that prosecutors say stole research and designs from 144 U.S. universities and 42 companies.
- [10]
Trellix researchers said Iranian-linked groups have been trying out AI to write the programs they use to break into systems, with humans still picking the targets and setting the timing while the technology scans for weaknesses and writes the code.
ReportedSupportedSource: Trellix researchers2 sources— create a free account to open themView cited source - [11]
Vibin Shaju, Trellix's vice president of solutions engineering for the region, said state-sponsored actors treat artificial intelligence as a practical force multiplier rather than a fully autonomous weapon.
ReportedSupportedSource: Vibin Shaju, Trellix, to Rest of World2 sources— create a free account to open themView cited source - [12]
Palo Alto Networks has tracked a rise in AI-assisted scams, password theft and fake company websites across the Gulf since February.
ReportedSupportedSource: Palo Alto Networks2 sources— create a free account to open themView cited source - [13]
Al Kuwaiti said in April that the attacks on the UAE came from about 20 countries and more than 40 organizations, including groups with links to Iran.
- [14]
Haider Pasha, Palo Alto Networks' chief security officer for Europe, the Middle East and Africa, said telecoms, energy and government services make the most tempting targets because knocking them out causes damage that spreads well beyond the first victim.
- [15]
The UAE has put government services and banking online and runs its power grid on computer networks, as the U.S. and Europe are now doing.
- [16]
Check Point traced break-in attempts on internet-connected cameras in the UAE, Qatar, Kuwait and Bahrain to Iranian hackers starting February 28, the day the war began, and assessed that the operators wanted footage to correct missile targeting and estimate damage after strikes.
- [17]
About 800,000 attempts a day works out to roughly nine attempts per second.
- [18]
The current rate is about 600,000 more attempts per day than the prewar figure of as many as 200,000.
- [19]
The campaign in the August 18 indictment spans about 13 years.
- [20]
The daily attempt figure cited in the August 10 statement is unchanged from the figure given in April.
Sources
1 independent publisher whose own reporting we read for this story.
- restofworld.orgThe UAE is fighting AI hackers with AI of its own
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- UAE Cyber Security CouncilFollow
- Mohamed Al KuwaitiFollow
- Cyber FactoryFollow
- CPX HoldingFollow
- Hadi AnwarFollow
- Check Point Software TechnologiesFollow
- Ram NarayananFollow
- Palo Alto NetworksFollow
- Haider PashaFollow
- TrellixFollow
- Vibin ShajuFollow
- Center for Strategic and International StudiesFollow
- U.S. Department of JusticeFollow