UAE Breach Shows $5 Million Ransom Pressure Behind Cyber Threats
The National reports that a hacker demanded more than $5 million after breaching a UAE private-sector company, as officials warn that AI, ransomware and misinformation are expanding the country’s cyber risk.

A hacker demanded more than $5 million after breaching a private-sector company in the UAE, according to cyber security chief Dr Mohamed Al Kuwaiti’s account reported by The National.
The amount was a ransom demand, not a confirmed payment.
The disclosure came from Dr Mohamed Al Kuwaiti, the UAE Government’s cyber security chief, during an Arab Media Summit discussion in Dubai.
Company records and operational systems were damaged, and the intruder tried to expose stolen material after claiming knowledge of the organisation.
Some of the material later appeared on Telegram and the dark web.
The company was not named, and the timing of the phone call was not disclosed.
That leaves the attack as a public warning rather than a case study with a visible victim, but the operational pattern is clear: intrusion, infrastructure damage, extortion pressure and attempted public exposure of stolen records.
Public agencies coordinated with company-side teams to contain the incident and keep the stolen information from spreading further.
The episode adds a concrete ransom figure to a broader threat picture in which critical industries, financial institutions and public trust are all targets.
In August, the UAE Cyber Security Council said national teams had detected and contained advanced, organised attacks against aviation, energy and education before vital systems were disrupted.
Those operations followed attacks on financial institutions in July, showing that the pressure is not limited to one sector or one type of organisation.
The daily scale is larger than the single ransom demand.
Al Kuwaiti has previously put the country’s exposure at hundreds of thousands of cyber attacks a day, with criminal groups combining AI, ransomware, breach operations and extortion tactics.
That mix changes both the speed of attacks and the amount of false or stolen material authorities must assess.
The panel also widened the definition of security risk beyond systems and networks.
Misinformation, rumours and manipulated content were described as part of a fifth-generation warfare environment in which decentralised threats, cyber terrorism and influence operations can target society as much as infrastructure.
Artificial intelligence is part of both sides of that contest.
UAE authorities are using AI to respond more rapidly to false information, while keeping human oversight in place so responses remain credible.
The same technology can also be misused for phishing, manipulated content and attacks that affect children, schools and public institutions.
The country’s response now combines technical defence, governance and public caution.
The UAE has introduced policies, compliance measures and ethical frameworks for AI, including autonomous systems, and launched the Cyber Factory in May to strengthen national defences and digital sovereignty.
More than half of government entities are automating processes with an emphasis on ethics and oversight.
Al Kuwaiti also put the positive share of AI interactions at 95 percent, while urging creators and influencers to use official sources and stay alert to falsified material.
That adoption does not remove the security burden; it raises the need to treat cyber resilience as a shared responsibility across government, companies and the public.




















