The UAE Cybersecurity Council said on Monday that the country’s national cyber defence systems had detected and blocked a series of advanced, organised cyberattacks targeting the aviation, energy and education sectors, with no interruption to critical services.
In a statement carried by state news agency WAM, the Council said the attacks were addressed proactively and immediately, and that intrusion attempts were contained before the attackers could achieve their objectives or affect the continuity of vital systems and services.
Dr Mohamed Al Kuwaiti, Head of Cybersecurity for the UAE Government, said the Cyber Factory positions the country as a global centre for advanced cybersecurity and a digital power shaping the future of the industry.
“The UAE stands as a leading model that not only protects but also innovates and leads by developing advanced technologies capable of detecting, preventing and deterring cyber threats effectively,” he said.
The campaign involved multiple attack vectors and techniques. According to the Council, these included attempts to breach digital systems and infrastructure, target operational accounts and data, run targeted phishing campaigns, and exploit users as an entry point into the environments being targeted.
National cybersecurity teams identified the malicious activity, tracked the attack paths and logged the indicators of compromise associated with the campaign. The Council said its national monitoring and response system had been operating at the highest level of readiness, with containment and protection measures applied at the same time as detection, which prevented the attackers from reaching their targets.
The Council did not identify the threat actor behind the campaign, name any affected organisation, or provide a timeline for when the activity was detected. It said the response reflected the country’s capabilities in early detection and proactive threat analysis.
The disclosure comes a month after a similar announcement. In July, the UAE said it had foiled a series of sophisticated cyberattacks on entities in the financial sector, again without disruption to services. The two statements point to sustained and repeated pressure on the sectors the country classifies as critical national infrastructure.
Aviation carries particular exposure in the Gulf. Airline operations, airport ground handling, cargo systems, maintenance providers and passenger data sit across a wide mesh of operators, contractors and third-party platforms, and each connection widens the attack surface. Compromising a staff account through phishing remains one of the cheapest and most reliable ways into that environment, which matches the entry method described by the Council in this case.
Energy and education present their own profiles. Energy operators run converged IT and operational technology estates where a breach on the corporate side can create risk on the industrial side. Education institutions hold large volumes of personal data and typically run with smaller security teams and looser identity controls than regulated industries.
The Council pointed to the UAE Cyber Factory, launched in May with strategic partner CPX Holding, as part of the country’s longer-term response. The initiative is tasked with designing and developing the next generation of cybersecurity capabilities through advanced programmes, technology and AI-powered systems.
The Council said it remains committed to strengthening national cyber resilience and protecting vital sectors against increasingly sophisticated threats.





