The missiles crossed the Gulf in February 2026. The hackers followed — armed with artificial intelligence.
Since the conflict between Iran, Israel, and the U.S. began, the United Arab Emirates has detected and contained coordinated cyberattacks targeting its aviation, energy, and education sectors. The numbers are stark: roughly 800,000 hacking attempts per day, four times the prewar level, according to the UAE's Cyber Security Council.
What makes this different from previous cyber campaigns is the technology waging war. AI is now writing phishing emails, hunting software flaws, and building malicious programs faster than defense teams can patch vulnerabilities. A weakness that once took days to exploit can now be weaponized within hours.
"The biggest change is speed," said Ram Narayanan, Middle East country manager at Check Point Software Technologies. "AI is now influencing almost every stage of a cyberattack."
The AI-Powered Threat
Iranian hackers have deployed AI at every step of their operations — from target selection to code generation to crafting deceptive messages that trick employees into surrendering credentials, according to the Center for Strategic and International Studies.
On August 18, the U.S. Justice Department charged 17 Iranians over a campaign running since 2013 that allegedly stole research and designs from 144 American universities and 42 companies. The same actors are now weaponizing generative AI against Gulf infrastructure.
"State-sponsored actors treat artificial intelligence as a practical force multiplier rather than a fully autonomous weapon," explained Vibin Shaju, Trellix's vice president of solutions engineering for the region. Humans still pick targets and set timing. The AI scans for weaknesses and writes the code.
The attacks came from approximately 20 countries and more than 40 organizations, including groups with links to Iran, according to Dr. Mohamed Al Kuwaiti, head of the UAE Cyber Security Council.
What Happened
The timeline reveals an escalating campaign:
February 2026: UAE cybersecurity systems repelled terrorism-related attacks targeting government platforms and ransomware deployment. Attackers used AI to build their tools.
Late February: Check Point traced break-in attempts on internet-connected cameras across UAE, Qatar, Kuwait, and Bahrain to Iranian hackers. The goal: footage to correct missile targeting and estimate strike damage.
April 2026: Al Kuwaiti revealed the UAE was facing 800,000 daily hacking attempts, up from 200,000 before the war.
July 2026: National teams detected and contained attacks on financial firms involving AI-enhanced phishing, software exploits, and malicious code. No services were disrupted.
August 2026: Coordinated attacks on aviation, energy, and education sectors were tracked and stopped before spreading. Limited corporate accounts and devices were compromised, but critical infrastructure remained secure.
The UAE Fights Back
The response has been as technological as the threat. In May 2026, the UAE launched the "Cyber Factory" initiative — a partnership between the Cyber Security Council and CPX Holding, the country's national strategic cybersecurity partner.
The goal: design and build AI security systems domestically, giving the UAE "end-to-end ownership of its defenses."
"The UAE Cyber Factory brings together local talent, advanced engineering, and innovation built in the UAE," said Hadi Anwar, CEO of CPX, at the launch.
This is part of a broader push for "national cyber sovereignty" — reducing dependence on foreign technology by building defenses at home. The analysts manning the national operations center work in shifts, reading alerts in real-time and deciding which threats require action. They share intelligence across government bodies, banks, and international security firms.
Why This Matters
The UAE's experience illustrates a new reality in geopolitical conflict: AI has lowered the barrier to sophisticated cyber warfare while simultaneously raising the stakes for defense.
Telecoms, energy, and government services are prime targets because disrupting them creates cascading damage. The UAE has digitized everything — government services, banking, even its power grid. That connectivity is a strength economically but a vulnerability strategically.
Palo Alto Networks tracked a rise in AI-assisted scams, password theft, and fake company websites across the Gulf since February. The attacks aren't just about data theft; they're about positioning for potential disruption during future conflicts.
Critically, the UAE has so far held the line. No physical services were disrupted. No ransomware encrypted critical systems. The separation between corporate networks and operational technology proved effective.
The Bigger Picture
This is not isolated to the Middle East. Google's Threat Intelligence Group has documented government-backed hackers worldwide using generative AI for research, translation, and phishing. The toolset is becoming standardized.
But the UAE's response offers a template: combine human expertise with AI augmentation, invest in domestic capability, and maintain strict network segmentation.
As Narayanan put it: "The attackers used AI to make their methods more complex. Our job is to make our defenses smarter, faster, and more adaptive."
In the age of AI-powered cyberwar, the side that builds better defenders first may just win the war without firing a shot.