CISO ME Issue 02 | Page 28

P
RANSOMWARE

AI makes UAE ransomware attacks more convincing

roofpoint has released its 2026

P

AI-Era Ransomware Report, revealing that Artificial Intelligence is making ransomware attacks significantly more effective by enabling cybercriminals to create more convincing phishing emails, impersonation campaigns and credential theft attacks. The findings suggest ransomware is increasingly succeeding by exploiting people, identities and trusted communications rather than technical vulnerabilities alone.
The report is based on a survey of 953 cybersecurity professionals across 12 countries, including the UAE, all from organisations that had experienced a ransomware attack. It concludes that ransomware has evolved beyond encrypting systems into a broader extortion model in which attackers steal credentials and sensitive data before deploying malware, enabling repeated demands for payment.
The findings come as the UAE Cyber Security Council continues to warn of a rise in sophisticated cyberattacks targeting critical sectors. Earlier this month, the Council
Ryan Kalember, Chief Strategy Officer at Proofpoint
AI hasn’ t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware.
confirmed it had contained a wave of attacks against the financial sector delivered through phishing campaigns and malicious software, while reporting that daily attacks on the country’ s digital infrastructure have increased to more than 600,000 amid heightened regional tensions.
Among UAE organisations affected by ransomware, 83 % said AI made attacks more effective, with 36 % reporting a significant increase and a further 47 % saying AI somewhat enhanced the success of the attack. Only 9 % reported no evidence that AI had been used.
The research highlights that people remain the primary attack surface. Phishing emails and other forms of email-based social engineering were identified as the initial entry point in 30 % of ransomware incidents. Malicious attachments were the most common delivery method, cited by 57 % of respondents, followed by QR code phishing at 55 % and telephone-oriented attacks at 45 %. The findings reinforce that today’ s ransomware campaigns continue to rely heavily on trusted communications and user interaction to gain initial access.
The report also shows that paying a ransom rarely brings an attack to an end. Despite repeated guidance from law enforcement agencies advising organisations not to pay, 81 % of affected UAE organisations did so. However, almost half( 47 %) of those that paid subsequently faced a second extortion demand, demonstrating that attackers increasingly exploit multiple forms of leverage, including encrypted systems, stolen data and the threat of public disclosure.
Data theft has also become central to modern ransomware operations. More than four in five( 83 %) UAE organisations confirmed that sensitive information had been stolen during the attack, highlighting how cybercriminals are increasingly focused on acquiring valuable data and credentials that can be monetised repeatedly or used in follow-on attacks.
Human error continues to play a significant role in successful attacks. More than one-third( 36 %) of respondents said employees failed to recognise malicious activity because it appeared authentic, while 30 % attributed the breach to users interacting with malicious content. The findings suggest AI is making phishing and impersonation campaigns increasingly difficult to distinguish from legitimate business communications.
“ AI hasn’ t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” said Ryan Kalember, Chief Strategy Officer at Proofpoint.“ Today’ s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”
28 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST