Iran-linked cyberattacks disrupt UAE services and spread fake ‘MOI’ alerts
Iran-linked cyberattacks surged amid the regional conflict, sending fake MOI alerts and disrupting UAE banking, infrastructure and surveillance systems.
The United Arab Emirates faced a coordinated campaign of Iran-linked cyberattacks during the recent Iran–Israel–US confrontation, officials and cybersecurity analysts say. Residents received fraudulent text messages purporting to be from the Ministry of Interior while parallel intrusions targeted banks, surveillance systems and critical infrastructure. Authorities have cautioned the public to ignore unauthorised alerts and to rely only on official communication channels as investigations continue.
Fake MOI alerts triggered warnings across the UAE
A wave of text messages instructing recipients to report “security incidents” circulated on mobile phones in the UAE during the height of the conflict. The messages were sent under the name “MOI” but the Ministry of Interior later denied issuing them and warned the public they were fraudulent. The false alerts contributed to confusion and prompted official advisories telling residents not to respond and to verify information via authorised government platforms.
Volume and nature of attacks overwhelmed systems
UAE cybersecurity officials reported a sharp spike in malicious activity weeks before the kinetic strikes began, with attacks attributed to Iran-linked proxies escalating dramatically after the conflict started. Analysts described campaigns that combined high-volume scanning, phishing emails and destructive malware, moving from data collection to sabotage in some cases. Banking systems in the Gulf experienced web-server disruptions that temporarily halted transactions, highlighting the operational reach of the attackers.
Critical infrastructure and surveillance systems targeted
Beyond financial services, the campaign aimed at a range of infrastructure and operational networks across the region. Security sources indicate intrusions on surveillance systems and attempts to access CCTV and home security feeds, raising concerns about both operational intelligence gathering and post-strike damage assessment. In Jordan, reported malware activity targeted the environmental controls of wheat storage sites, an example of how adversaries tested unconventional avenues to inflict economic harm.
Information operations intensified psychological pressure
Cyber activity was accompanied by a concerted information operation intended to amplify fear and uncertainty in Gulf societies. Threatening messages addressed to civilians and evocative social posts, including images of landmark buildings, were used to prod alarm and self-censorship. The spread of graphic or misleading footage online led authorities to make arrests for sharing unverified material, and many residents and journalists began deleting posts or avoiding public dissemination of footage for fear of repercussions.
Experts describe a coordinated, hybrid campaign
Security firms tracking the campaign described it as multi-pronged and deliberate, blending influence operations with technical intrusions. Analysts noted that Iran and associated groups have been preparing and refining asymmetric cyber capabilities for years, deploying proxies to sustain activity even when domestic connectivity was constrained. While some intrusions were loudly publicised by attackers seeking psychological effect, researchers cautioned that the actual operational impact varied, with some claims exaggerated for effect.
Government measures and public guidance intensified
UAE authorities and regional partners responded by tightening digital defences and issuing guidance to organisations and citizens. Officials urged people to change passwords on connected cameras and to report suspicious emails or messages to cybersecurity bodies. Public communications emphasized the use of verified channels for alerts and updates, while companies in the region moved to contingency arrangements such as remote working after the threat list published by hostile actors included major multinational firms.
The recent campaign underscores the growing centrality of cyberspace to contemporary conflict, where reputational damage and disruption can be achieved without large-scale kinetic strikes. As investigations proceed, Gulf states are strengthening incident response, public messaging and cooperation with international partners to reduce vulnerabilities and to deter future asymmetric operations.