Back
CASE #5
Case file
Cyber security
July 17, 2026

UAE Banks Were Attacked Last Week. The Attackers Used AI to Write the Emails.

WHAT IS IT ABOUT

AI-poweredphishing occurs when cybercriminals use artificial intelligence to generatehighly personalised fraudulent emails that replicate the tone, format, andcontext of legitimate business communications. Unlike traditional phishing,AI-generated emails contain no grammar errors, reference real supplier names,and match the communication patterns of the target. The UAE Cyber SecurityCouncil confirmed this method was used in coordinated attacks on the UAEfinancial sector in July 2026.

THE INCIDENT

UAEbanks were attacked last week. The government stopped them. But one detail inthe announcement almost nobody talked about: the attackers were using AI — notto break into systems, but to write the emails.

TheUAE Cyber Security Council confirmed it. AI-generated phishing campaigns,designed to look legitimate, specific, and impossible to detect throughstandard training.

Theemail arriving in your finance team's inbox tomorrow — correct supplier name,right format, right tone — may not have been written by a person. The UAE faces800,000 cyberattack attempts every day. The ones stopped last week wereannounced. The ones that were not stopped were not.

WHAT THIS REVEALS

Standardphishing training teaches employees to spot errors — bad grammar, strangeaddresses, unusual urgency. AI removes every one of those signals. The emailarrives perfectly formatted, in the right context, at the right time.

MostUAE businesses have not updated their phishing training since AI became widelyavailable to attackers. The training designed for the old threat is no longersufficient on its own.

PREVENTION FRAMEWORK

 Rebuildphishing training around verification processes, not spotting visual errors

 Applya mandatory 24-hour hold on all bank detail change requests — no exceptions

 Verifypayment instructions by phone using numbers from your own records, not theemail

 Requiretwo-person sign-off for all financial instructions above a defined threshold

 Documentand test the verification process — do not rely on individual judgement underpressure

IF THIS HAS ALREADY HAPPENED

Donot delete emails or change passwords before documenting the current state —preserve headers and the full email thread as evidence. If a financial transferwas made, call your bank fraud team immediately by phone. File a report withDubai Police Cyber Crime Unit. Engage a specialist before taking furthertechnical action — the incident may indicate a broader compromise beyond thephishing email itself.

Contact us nowView on Linkedin
NORDSTAR NOTE

Incybersecurity assessments across UAE businesses, the most consistent gap is notin technology — it is in process. Businesses have firewalls and antivirus. Theydo not have a documented, tested process for when a payment request arrives byemail. AI phishing exploits exactly that gap.

AI Phishing Verification Checklist — UAE Finance Teams

A one-page process checklist covering the five verification steps that stop AI-generated phishing before it reaches the payment stage.
Thank you! Your submission has been received.
Oops! Something went wrong while submitting the form.