Single malicious program could disrupt an airport or essential service, says Dr Mohamed Al Kuwaiti
A single malicious program could disrupt an airport, halt part of an essential service, or cripple critical digital infrastructure, the UAE’s top cybersecurity official has warned, describing cyberwarfare as a growing threat to the systems that keep daily life running.
Dr Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government, told Khaleej Times that the country is currently facing an average of around 600,000 cyberattacks a day, a figure that rose to about 800,000 a day at the peak of recent regional conflict. Before tensions in the region escalated, the daily figure stood at roughly 200,000.
Al Kuwaiti said cyber threats were shifting from conventional cybercrime toward attacks designed to disrupt or destroy the digital infrastructure behind essential services. He grouped the threats facing the country into three categories: cybercrime, cyberterrorism, and cyberwarfare.
Cybercrime, he said, covers theft, fraud, espionage, and the spread of rumours and other malicious activity. Cyberterrorism involves the use of social media, online games, and other digital platforms to spread false ideas, undermine social cohesion, and encourage radicalisation. The third category, cyberwarfare, targets the digital infrastructure that supports critical services, and it is the area he identified as the fastest-growing concern.
The warning follows a series of attempted attacks on the country’s key sectors over the past year. The UAE Cybersecurity Council said in August that it had detected and thwarted coordinated attacks on the aviation, energy, and education sectors, with intrusion attempts contained before they could affect vital systems or services. In July, the council reported foiling a wave of attacks on the financial sector, and in February it said it had stopped attacks of a “terrorist nature” targeting the country’s digital infrastructure.
Al Kuwaiti said the methods behind these attacks have changed, with hostile actors increasingly using artificial intelligence. AI tools are being used to write malicious code, craft phishing campaigns, and combine fraud with disinformation across multi-stage operations, he said. The threats span distributed denial-of-service attacks, ransomware, data breaches, data leaks, wiper malware, and website defacement.
The council has previously said that more than 70 per cent of the threat actors targeting the UAE are state-sponsored groups.
In response, the UAE has continued to strengthen its defences using the same technology. Al Kuwaiti said the country uses AI for protection, deterrence, and recovery, while the Cybersecurity Council issues more than 200 threat intelligence bulletins a day to government and private sector entities to help contain attacks before they spread. Earlier this year, the council launched a national programme to develop the next generation of cybersecurity capabilities, part of a wider effort to keep pace with evolving threats.
Al Kuwaiti said many intrusions still begin by exploiting individual users as an entry point into larger systems, underlining the role of everyday digital habits in the country’s overall defence. He said the UAE continues to refine its systems to maintain its position as a global leader in cybersecurity.

