The Speed Trap: How AI Turned Cyberattacks Into an Hours-Long Race
The Emirates is building sovereign defenses as machine-speed intrusions force a rethink of national security infrastructure across the Gulf.

The New Tempo of Intrusion
Daily hacking attempts against Emirati infrastructure quadrupled since February 2026, reaching roughly 800,000 incidents. The Cyber Security Council attributes the surge to machine-learning systems that compress vulnerability-to-exploit cycles from days into single-digit hours, fundamentally altering the economics of digital defense.
Aviation grids, power networks, and university systems absorbed coordinated intrusions through August, according to the council. Human analysts working rotating shifts contained the breaches before lateral movement could occur, but the tempo has exposed a structural problem: adversaries now operate at machine speed while most institutional defenses still rely on human triage.
The shift began when regional conflict escalated in late February. Within 48 hours, security teams across the Gulf logged break-in attempts on internet-connected cameras in the UAE, Qatar, Kuwait, and Bahrain. Researchers at Check Point Software Technologies traced the campaign to Iranian operators and assessed the goal as real-time targeting correction for missile strikes, using municipal and private camera feeds to verify impact and adjust coordinates.
Mohamed Al Kuwaiti, who leads the Cyber Security Council, disclosed in April that the attempts originated from approximately 20 countries and more than 40 distinct groups, some with documented state linkage. By July, financial institutions were absorbing phishing runs and exploit chains built with generative tools, though no customer-facing services went offline.
What Changed in the Kill Chain
Automation entered every phase: reconnaissance, weaponization, delivery, and post-compromise movement. Phishing emails now carry context-aware language that mimics internal communication styles, making static filters less effective. Exploit kits scan disclosed vulnerabilities within hours of public disclosure, then auto-generate working payloads before patch deployment windows close.
Ram Narayanan, Middle East country manager at Check Point, frames the change as temporal. A flaw announced on a Tuesday morning might face active exploitation by Tuesday evening, compressing the patch-test-deploy cycle into an interval many IT departments cannot meet. The result is a growing inventory of known but unpatched exposures across enterprise and government networks.
Iranian-linked groups have embedded machine-learning workflows into their toolchains, according to Trellix, a U.S.-based security firm operating in the region. Humans still select targets and authorize operations, but algorithms handle scanning, code generation, and iterative testing. Vibin Shaju, Trellix's vice president of solutions engineering for the Middle East and Africa, describes the model as augmentation rather than autonomy: state-sponsored actors treat the technology as a force multiplier, not a replacement for strategic decision-making.
Telecoms, energy utilities, and government portals remain high-value targets because disruption cascades beyond the initial victim, according to Haider Pasha, chief security officer for Europe, the Middle East, and Africa at Palo Alto Networks. The firm has tracked a measurable uptick in credential-theft campaigns, fraudulent corporate domains, and social-engineering operations across Gulf Cooperation Council states since the February escalation.
The Sovereignty Play
The UAE launched its Cyber Factory initiative in May, a joint program between the Cyber Security Council and CPX Holding, the state's designated strategic cybersecurity partner. The mandate is to design, engineer, and deploy AI-driven defense systems domestically, reducing reliance on imported platforms and establishing what officials term "national cyber sovereignty."
Hadi Anwar, chief executive of CPX, positioned the factory as a talent and engineering hub that keeps intellectual property, threat intelligence, and operational control within national borders. The council frames the move as both a technical necessity and a strategic hedge: foreign vendors may withdraw support during conflict, and supply-chain dependencies create single points of failure.
The systems under development aim to match adversary speed by automating alert triage, threat correlation, and response orchestration. Analysts currently read incoming alerts in real time and decide which require immediate action; the new architecture is designed to handle that filtering autonomously, escalating only high-confidence incidents to human operators.
The UAE's national operations center already aggregates telemetry from government agencies, banks, and private-sector partners into a unified feed. Cyber Factory tools will plug into that infrastructure, applying pattern recognition and anomaly detection at a scale human teams cannot sustain during prolonged campaigns.
The Escalation Ladder
February brought ransomware attempts against government platforms, which the council labeled terrorism-related. By April, daily intrusion attempts had climbed from a pre-conflict baseline near 200,000 to the current 800,000 figure. July saw phishing and exploit chains targeting financial services, with attackers using generative models to increase payload complexity. August's coordinated strikes against aviation, energy, and education sectors marked the third distinct wave.
Check Point's analysis of the camera intrusion campaign, which began February 28, illustrates the operational value adversaries place on real-time intelligence. Municipal traffic cameras, building security feeds, and port monitoring systems all became reconnaissance assets, feeding geolocation and damage-assessment data back to operators adjusting strike packages.
The U.S. Justice Department charged 17 Iranian nationals in mid-August over a multi-year espionage operation that prosecutors allege stole research and intellectual property from 144 universities and 42 companies. The indictment does not explicitly tie those individuals to the Gulf campaigns, but the Center for Strategic and International Studies has documented Iranian use of AI tooling across the full attack lifecycle since the current conflict began.
Machine Versus Machine
Narayanan argues the Gulf is moving toward machine-to-machine cyber conflict, where algorithms probe defenses and automated systems respond without human latency. The transition is uneven: some sectors have deployed behavioral analytics and automated isolation, while others still rely on signature-based detection and manual incident response.
Speed asymmetry creates risk. An attacker who automates reconnaissance, weaponization, and delivery can cycle through dozens of targets in the time a defender takes to investigate one alert. Scaling human teams does not solve the problem; it only delays the breaking point.
The Cyber Factory model bets that sovereign, AI-native defenses can close the speed gap and preserve decision-making autonomy. Whether that architecture can keep pace with adversaries who iterate their own tooling in parallel remains an open question. The Emirates has bought time with human resilience and cross-sector coordination, but the next phase will test whether machines built in Dubai can outrun machines built elsewhere.

