UAE Hit With 640,000 Cyberattacks in One Day as Iran & AI Fuel a New Digital War
The battlefield in the Middle East is no longer limited to missiles, drones and bombs. Increasingly, the war is happening inside computer networks, government systems and critical infrastructure, and the United Arab Emirates says it recently faced an astonishing 640,000 cyberattacks in a single day.
The disclosure came from Dr. Mohamed Al Kuwaiti, head of the UAE Government Cyber Security Council, during an interview with CNN’s Becky Anderson. Al Kuwaiti said the UAE recorded approximately 640,000 cyberattacks on Tuesday, September 15, as the country continues dealing with an aggressive and sustained campaign against its digital infrastructure.

The number is particularly significant because it represents attempted cyber activity occurring alongside the broader military and geopolitical conflict in the region. While physical attacks are highly visible, cyberattacks can be launched remotely, anonymously and at enormous scale. A successful intrusion into an airport, bank, power system, telecommunications network or government agency could potentially create disruption without a single missile being fired.
UAE Says Iran and the IRGC Are Behind Many of the Attacks
The obvious question following a cyberattack of this magnitude is simple: Who is doing it? According to Al Kuwaiti, investigators have identified what he described as strong digital evidence pointing toward Iran.
“There are great footprints that show who is actually behind those attacks,” Al Kuwaiti told CNN. He specifically identified Iran as one of the main players and said Iran’s Islamic Revolutionary Guard Corps, or IRGC, is behind many of the attacks targeting the UAE.
That allegation comes from the UAE’s top cybersecurity official and should be understood as an attribution by UAE authorities, rather than proof that every one of the hundreds of thousands of daily attacks originated from Iran. Cyberattacks can involve criminal organizations, politically motivated hackers, proxy groups and state-sponsored operations, and identifying the ultimate operator behind an attack can be extremely difficult.
Still, the UAE has previously reported unusually high levels of cyber activity connected to the broader regional conflict. In February, Al Kuwaiti said between 90,000 and 200,000 breach attempts were hitting UAE infrastructure every day, with 128 confirmed cyber incidents reported since the beginning of 2026 at that point. The country’s government administration and financial sectors were among the most targeted.
By March, WIRED Middle East reported that Al Kuwaiti was seeing approximately 530,000 cyber incidents per day, up from about 270,000 before the latest escalation in regional tensions. Now the reported number has reached 640,000 for a single day.
AI Is Making the Cyberwar Faster
One of the biggest changes in the cyber battlefield is artificial intelligence. AI can potentially help attackers automate tasks that previously required significant amounts of human labor, including creating convincing phishing messages, identifying vulnerabilities, generating malicious code and adapting attacks to their targets.
Al Kuwaiti told CNN that AI has dramatically accelerated cyberattacks. At the same time, however, the UAE is using the same technology to fight back.The country’s strategy is essentially to use AI against AI, employing automated systems to detect, defend and disrupt cyber threats before they can cause serious damage.
That creates an increasingly strange technological arms race. Attackers use artificial intelligence to find weaknesses faster, while defenders use artificial intelligence to identify those attacks faster. Humans, meanwhile, remain in the middle trying to determine whether the computer is protecting them or trying to ruin their afternoon.
The Attacks are Targeting Critical Infrastructure
The UAE’s recent cyber incidents have not been limited to government computers.
In July, the UAE Cyber Security Council announced that it had stopped sophisticated attacks targeting the country’s financial sector. Investigators said the campaigns involved phishing and malicious software, although financial services continued operating without reported disruption.
Then in August, UAE authorities said organized attacks had targeted aviation, energy and education. The attacks reportedly attempted to breach digital infrastructure, compromise operational accounts and use phishing campaigns to exploit employees and other users as entry points.
According to the Cyber Security Council, those attacks were detected and contained before the targeted systems were compromised. The significance is obvious. Taking control of someone’s email account is one thing. Getting into an airport’s operational network or an energy company’s infrastructure is something else entirely. Cybersecurity experts have warned for years that critical infrastructure is an attractive target because a successful attack can create consequences far beyond stolen information.
The UAE Is Building a Cybersecurity Factory
The UAE is responding by investing heavily in its own cybersecurity capabilities.
In May, the country launched the UAE Cyber Factory, a program created by the Cyber Security Council in partnership with CPX Holding. The initiative is designed to develop next-generation cybersecurity technologies, including systems that use artificial intelligence to identify and respond to threats. The timing is hardly accidental.
The UAE Cyber Security Council said the country had recorded more than 800,000 cyberattacks per day during some periods in recent months, demonstrating just how enormous the volume of malicious activity can become. The 640,000 attacks reported this week therefore represent an enormous number, but they are also part of a much larger pattern of sustained digital attacks against the UAE.
Cyberwarfare is no Longer Just About Stealing Data
Al Kuwaiti has also warned that the threat extends beyond traditional hacking.
Cyber operations can be used to spread misinformation, manipulate public opinion, distribute deepfakes and create confusion during a crisis. UAE officials have described some of these activities as part of what they call “fifth-generation warfare.”The distinction is important because the objective may not always be to steal money or destroy a computer system. The objective can instead be to manipulate people.
A fake government announcement, fabricated video or convincing AI-generated recording can potentially spread across social media within minutes. By the time authorities establish that it is fake, millions of people may have already seen it. Al Kuwaiti has therefore emphasized the importance of human oversight even as the UAE increases its reliance on AI. The government has also urged social media users and content creators to verify information through official sources before spreading it.
A $5 Million Ransom Demand Shows What Is at Stake
The UAE’s cybersecurity chief has also described a separate attack in which a hacker reportedly contacted him and demanded more than $5 million in ransom after compromising a private-sector organization.
According to Al Kuwaiti, the attacker destroyed data connected to the company’s infrastructure and attempted to distribute stolen information through Telegram and the dark web. UAE authorities worked with the private sector to contain the incident and prevent further distribution of the stolen material.
That incident illustrates another side of the cyberwar: not every attacker is necessarily trying to advance a government or military objective. Some simply want money. The problem for governments is that the two types of attacks can look remarkably similar from inside the network.
The New Battlefield Is Invisible
The UAE’s experience illustrates how dramatically modern conflict has changed.
A country can intercept a missile because it can see the missile coming. A cyberattack can be launched from thousands of miles away, routed through multiple countries and disguised to make investigators believe someone else is responsible. And unlike a missile attack, there may be no obvious moment when the attack begins.
The UAE says its cybersecurity teams are monitoring threats around the clock and using AI to detect, analyze and stop malicious activity. The country has also demonstrated that it can defend critical systems against coordinated attacks targeting financial services, aviation, energy and education.
But the sheer volume of reported attacks shows the scale of the challenge. 640,000 attacks in 24 hours is not simply a cybersecurity statistic. It is a glimpse into what warfare increasingly looks like in the digital age. The next major attack on a country may not begin with fighter jets crossing a border. It could begin with someone sitting behind a computer, thousands of miles away, sending a piece of code into a network and waiting to see what happens.






































Want to join the conversation?
Create an account or sign in to share your thoughts, vote,
and reply to other readers.
Showing 0 of 0 comments
Don't have an account?
Already have an account?