The UK’s National Cyber Security Centre (NCSC) urged British organizations to review and strengthen defenses amid rapidly evolving Middle East conflict dynamics, warning that while there was “likely no current significant change” in the direct cyber threat from Iran to the UK, the assessment could change quickly. The NCSC highlighted a heightened risk of indirect cyber threat for organizations with assets or supply chains in the region, noting Iran’s state and state-aligned actors maintain cyber capabilities and recommending practical hardening steps to reduce compromise risk.
In the UAE, authorities warned of opportunistic social-engineering campaigns exploiting public anxiety after Iranian missile attacks, with scammers impersonating a fictitious “Dubai Crisis Management” entity to harvest UAE Pass and Emirates ID details that could enable SIM-swap attacks and subsequent mobile-banking account takeover. Separate reporting on the missile strikes described the UAE’s layered air-defense architecture (including THAAD and Patriot) that intercepted incoming ballistic missiles; while not a cyber incident, it provides operational context for the crisis environment in which cyber-enabled fraud and heightened cyber-risk advisories are emerging.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
A senior UAE cybersecurity official said state-linked Iranian hackers were using AI tools including ChatGPT and WormGPT to improve malware development, vulnerability discovery, and phishing campaigns against the UAE. He also said cyberattack volume had doubled during recent regional crises to more than 500,000 incidents per day, with the private sector facing greater exposure than government infrastructure.
The Government of Dubai Media Office said widely shared online claims about explosions, shortages of goods, and life in Dubai coming to a standstill were false and did not reflect conditions on the ground. Officials said many of the posts appeared to originate from accounts outside the UAE and urged the public to rely on official channels amid continued misinformation and AI-manipulated content.
Digital Dubai and the National Media Council urged UAE residents to verify videos and images before sharing them, warning that deepfake and AI-generated content can convincingly impersonate public officials. The advisory came amid heightened regional tensions and followed circulation of a video using deepfakes of senior Dubai government figures to spread an anti-misinformation message.
Abu Dhabi Police announced the arrest of 109 people of various nationalities for filming sites and events and posting inaccurate information on social media during ongoing regional developments. Authorities said the activity could spread rumours and harm public safety, and urged residents to rely on official sources and avoid sharing unverified footage.
Cybersecurity experts warned that more than 8,000 suspicious domains had been registered over the previous month to exploit the Middle East conflict, including over 200 fake sites impersonating a major GCC oil company, Gulf banks, and government services. The report also said UAE authorities had intercepted more than 1,200 malicious domains in the past quarter and highlighted risks such as credential theft, fraud, and possible access to critical infrastructure.
The UK National Cyber Security Centre urged British organizations to review and strengthen cyber defenses amid rapidly evolving events in the Middle East. The agency said there was no current significant change in the direct cyber threat from Iran to the UK, but warned the situation could change quickly and that organizations with regional operations or supply chains faced heightened indirect risk.
Within hours of missile strikes on Dubai, Dubai Police said scammers began impersonating a fake "Dubai Crisis Management" unit to steal UAE Pass, Emirates ID, and other sensitive data for SIM-swap attacks targeting bank accounts. Police urged residents to report suspected fraud through official channels and reiterated that they do not request confidential information by phone or text.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcekhaleejtimes.com
Open sourcekhaleejtimes.com
Open sourcekhaleejtimes.com
Open sourcetherecord.media
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.