A new Proofpoint report reveals that 83% of UAE organisations believe AI has significantly increased the effectiveness of ransomware attacks. The study highlights a shift from simple encryption to sustained extortion, with attackers using AI to create highly convincing phishing and impersonation campaigns that exploit human trust and identities.
Based on a survey of 953 cybersecurity professionals across 12 countries, including the UAE, all from organizations that had experienced a ransomware attack, the research shows that modern ransomware has evolved beyond an encryption event into a sustained extortion campaign. Attackers are increasingly stealing credentials and sensitive data before deploying ransomware, using trusted communications to gain initial access and applying continued pressure through repeated extortion demands.
The findings land amid escalating warnings from the UAE Cyber Security Council. In early July, the Council confirmed the national cybersecurity ecosystem had contained a wave of sophisticated attacks on the financial sector, delivered through phishing campaigns and malicious software, and cautioned that criminals are increasingly using AI to develop more advanced techniques. The Council has also reported that daily attack attempts on the country’s digital infrastructure have roughly tripled this year to more than 600,000 amid heightened regional tensions.
“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” said Ryan Kalember, Chief Strategy Officer at Proofpoint. “Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organizations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”
Key UAE findings from Proofpoint’s 2026 AI-Era Ransomware Report include:
- People are the primary ransomware attack surface, and AI is making it worse. With AI, attackers can create more convincing phishing lures, write more targeted impersonation messages, and do faster reconnaissance of organizational structures and message patterns. Among the UAE organizations that experienced a ransomware attack, 36% said that AI significantly increased the attack’s effectiveness. Another 47% said that it somewhat increased effectiveness. Combined, 83% said AI made the attack more effective. Only 9% reported no evidence of AI use at all.
- The leading entry methods are all human-dependent. When UAE organizations identified the primary point of entry for their ransomware incident, the results pointed overwhelmingly to human interaction. Phishing emails and other email-based social engineering attacks were the initial entry vector in 30% of incidents. Malicious attachments (57%) were identified as the most common initial threat, followed by QR code phishing (55%) and telephone-oriented attack delivery (45%). This demonstrates that today’s most successful ransomware campaigns continue to rely on trusted communications and user interaction throughout the attack lifecycle.
- Payment leads to escalation, not resolution. Despite years of guidance from law enforcement and security agencies advising against paying a ransom, more than four in five (81%) of affected UAE organizations paid a ransom. Yet, nearly half (47%) of those that paid faced a second extortion demand, highlighting ransomware’s evolution from a single payment event into an ongoing negotiation in which attackers hold multiple forms of leverage at the same time: continued encryption, stolen data, and the threat of public disclosure.
- Encryption is no longer the endgame. More than four in five (83%) of organizations surveyed in the UAE confirmed that data was stolen during the incident. Today’s ransomware campaigns are less about locking systems and more about acquiring data, identities, and persistent access. These can be monetized through repeated demands, sold on criminal marketplaces, or used as launching pads for secondary attacks.
- Attacks succeed through manipulation. When UAE respondents were asked why the ransomware attack was able to bypass their existing controls, 36% of organizations said employees did not suspect the attack because it appeared authentic, while 30% attributed the incident to users interacting with malicious content – evidence that AI is making social engineering increasingly difficult to distinguish from legitimate business communications.
- Ransomware impact varies by country. Respondents in the UAE reported the highest rates of AI-enhanced attack effectiveness (83%), in addition to high ransom payments (81%). Meanwhile, user interaction as a bypass factor was highest in Japan (49%), India (49%), and Singapore (48%). In these markets, the most common failure mode was users engaging directly with malicious content rather than being deceived by impersonation.
The findings reinforce that organizations can no longer treat ransomware primarily as a malware problem. As AI makes phishing, impersonation and credential theft increasingly convincing, preventing ransomware means protecting people, identities and trusted communications before attackers ever reach the endpoint.





