logo
Triple extortion, AI phishing: UAE banks face evolving cyber threats

Triple extortion, AI phishing: UAE banks face evolving cyber threats

Khaleej Times4 days ago

From hyper-personalised phishing emails to ransomware attackers leaking stolen data before encryption, cyber threats in the banking and financial sectors are growing faster than many institutions can adapt.
At the FutureSec Summit 2025, hosted by Khaleej Times in Dubai on Wednesday, cybersecurity leaders warned that even tightly regulated sectors, such as BFSI (Banking, Financial Services, & Insurance), are now facing more complex, intelligent, and coordinated cyberattacks.
"More than 95 per cent of cyber incidents still begin with social engineering," said Hala Elghawi, Regional Cybersecurity Risk Specialist. "Phishing emails have become highly sophisticated, especially with AI-generated spear phishing. These are tailored to specific individuals, making them incredibly hard to detect — even by trained professionals."
Elghawi added that traditional ransomware attacks have evolved into what experts are calling triple extortion tactics: "Attackers now first exfiltrate data and leak it online, then encrypt systems, and finally demand ransom. If companies hesitate, they escalate by threatening to publish or sell the data. The pressure is intense."
She also pointed to the rising availability of malware-as-a-service platforms, which have made it easier and cheaper for less technically skilled actors to launch serious attacks.
Regulation, culture, and AI
While regulation in the UAE is evolving rapidly, experts emphasised that compliance alone is not enough.
"The Central Bank of the UAE took a very forward-looking step in 2024 with two key regulations," said Rohit Bajpai, Head of Internal Audit at Gulf Islamic Investments. "One was the introduction of open finance rules, extending data-sharing frameworks to insurance firms under customer-consent models. The second was a regulatory sandbox that allows firms to safely test AI and digital tools in a controlled environment."
These shifts, he noted, create an environment that fosters innovation without compromising risk controls.
But according to Linoy Kidd, Chief Information Officer at HSBC MENAT, the human element remains just as critical:
"Cybersecurity must be part of the organisational DNA. It's not just about XDR or MFA. It's about accountability at every level, first line, second line, and third line of defence," she said. "Training, awareness, and a culture of vigilance are just as important as technology."
Multi-cloud chaos
Expanding the conversation beyond finance, Georges Farah, Head of Container Security for Kaspersky (Middle East, Turkey, and Africa), echoed that the shift to hybrid and multi-cloud environments is creating serious visibility challenges.
"With every additional cloud provider, you get more flexibility but also more blind spots," Farah said. "Only about 51% of organisations today say they have fully unified visibility across their infrastructure. That's where attackers thrive."
He cautioned against a common mistake: trying to enforce the same low-level configurations across different cloud providers.
"You need a top-down approach," he explained. "Start with master policies in plain English, what data needs to be protected and why—then translate those into cloud-specific tools and configurations. Automate what you can, but make sure it's strategic, not reactive."
Despite the evolving threat landscape, speakers expressed optimism that AI could be as much a solution as a risk if adopted correctly.
"Machine learning lets us detect threats faster, identify patterns, and even automate containment," said Elghawi. "Instead of replacing people, it should free them to focus on strategy and innovation."

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Dubai's biggest lender Emirates NBD to start charging for remittances to certain countries
Dubai's biggest lender Emirates NBD to start charging for remittances to certain countries

The National

time37 minutes ago

  • The National

Dubai's biggest lender Emirates NBD to start charging for remittances to certain countries

Emirates NBD, Dubai's largest bank by assets, will start charging fees for international transfers made to certain countries through its app or online banking platform from September 1. The bank will charge a fee of Dh26.25 for remittances, including those made through DirectRemit, it said in an email to customers. DirectRemit is a platform that allows customers to transfer money via online or mobile banking in 60 seconds. However, transfers to India, Pakistan, Egypt, Sri Lanka, the Philippines, and the UK will continue to be offered free of charge to all Emirates NBD customers, a bank representative clarified in a statement. "Additionally, Emirates NBD is expanding its DirectRemit offerings to over 30 new countries ... [and] customers will no longer be charged any correspondent bank fees [in addition to the Dh26.25 fee]," the representative said. The lender will also charge a fee of up to Dh26.25 for recalling and cancelling local and international transfers, it said. The move by the lender may prompt other banks to introduce fees on remittances and may be a boon for exchange houses that offer lower charges, analysts said. 'Introducing a Dh26.25 fee from September 2025 marks a shift, and as the largest local bank sets the tone, it's possible others may follow,' Dhruv Tanna, associate vice president at DIFC-based investment and wealth management firm Phillip Capital, told The National. Some lenders such as RAKBank already impose a fee for international transfers, charging Dh15.75 for the Philippines and Dh26.25 for India, according to its website. Mashreq bank has zero fees for Pakistan and India, but charges a flat fee of Dh26.25 for the Philippines, according to its website. Others such as FAB have zero transfer fees for instant transfers to countries including India, Pakistan, Philippines, Sri Lanka, the UK and the EU, according to its website. International transfers are rarely entirely free as banks recover their costs indirectly, analysts said. "While some digital channels advertise zero fees, most banks have always made money either through transfer charges or by applying a margin to the exchange rate, or both," said Ben Bolger, founder of Squirrel Education, a company that teaches school children financial independence. Opportunity for exchange houses Exchange houses with more competitive fees are likely to benefit as banks impose charges on international transfers. 'For exchange houses, this presents a renewed opportunity to attract price-sensitive customers with lower transfer fees and competitive rates," Mr Tanna said. "Still, many mid-to high-income customers may continue to choose banks for the convenience, even with a nominal charge." Mr Bolger said that as banks adjust their terms, consumers could reconsider their options. "Exchange houses, which tend to offer more competitive rates and transparent pricing, may become increasingly attractive, despite the convenience of transferring money directly through your bank," Mr Bolger said. Emirates NBD's move to charge fees for remittances may prompt other lenders to follow suit, but it also "opens the door wider" for exchange houses and digital apps offering zero fees and better value, Jay Adrian Tolentino, a UAE-based financial coach, said. This will particularly benefit expats sending money to their home countries on a regular basis, he added. Based on World Bank data, remittances to low- and middle-income countries are expected grow by 2.3 per cent in 2024 and 2.8 per cent in 2025, reaching $690 billion in 2025.

Dubai to host prestigious Sibos 2029 global banking conference
Dubai to host prestigious Sibos 2029 global banking conference

Khaleej Times

time37 minutes ago

  • Khaleej Times

Dubai to host prestigious Sibos 2029 global banking conference

Dubai will host the Sibos 2029, the annual conference, exhibition and networking event organised by the Society for Worldwide Interbank Financial Telecommunication (SWIFT), according to UAE Banks Federation (UBF). Sibos conference and exhibition is one of the most important and largest events that connects thousands of executives, decision makers, technology providers, and thought leaders from across the industry to share experiences and views. SWIFT enables more than 11,000 financial institutions and corporations in more than 200 countries and territories to connect and exchange financial information securely and reliably, enhancing trade and financial transactions. The UAE was the first country in the Middle East and Africa to be selected by the global financial and banking sector to host Sibos in 2013. The UAE is the only country in the Middle East and Africa that has been ever chosen to host Sibos conference and exhibition since its establishment in 1978. This high-level event was held in several international financial centres such as Singapore, Geneva, Toronto, London, Amsterdam, and Beijing. The selection of the UAE to host Sibos 2029 reflects efforts made by UBF in cooperation with Dubai International Financial Centre, Dubai World Trade Centre, and Dubai Department of Economy and Tourism, and the support of the Central Bank of the UAE. 'The selection of Dubai to host Sibos 2029 is a testament to UAE's prominent position as a regional and global financial and banking centre," said Abdulaziz Al-Ghurair, chairman of UBF. "This selection also reflects international financial and banking industry's appreciation for UAE's efforts and innovative initiatives in developing and simplifying payments, adopting digital transformation to meet the needs of the banking and financial sector, and developing secure and efficient systems in line with the proactive policies of Central Bank of UAE, which places the security and efficiency of bank transfers as a top priority,' he added. Jamal Saleh, director-general of UBF and chairman of SWIFT User Group Steering Committee in the UAE, said Sibos 2029 is the most important international event in the field of payments, which is a fundamental pillar of socio-economic development. 'Central Bank of the UAE's initiatives in payments meet the requirements of various stakeholders and help achieve the objectives of the National Payment Systems Strategy, launched in 2019 to develop innovative payment solutions and enhance customer experience. It is enhancing the UAE's position in technological development, innovation, and security in the banking and financial sector,' he added. Marianne Demarchi, chief executive, Swift EMEA, said: 'Sibos brings the industry together on an unmatched scale, and we're delighted to be bringing the conference back to Dubai in 2029. The Emirate is a truly global financial hub in a geographically strategic location, and will be a fitting setting for the vibrant dialogue and debates that Sibos is famous for facilitating each year.'

Kaspersky: ChatGPT-mimicking cyberthreats surge 115% in early 2025
Kaspersky: ChatGPT-mimicking cyberthreats surge 115% in early 2025

Zawya

timean hour ago

  • Zawya

Kaspersky: ChatGPT-mimicking cyberthreats surge 115% in early 2025

In 2025, nearly 8,500 users from small and medium-sized businesses (SMBs) faced cyberattacks where malicious or unwanted software was disguised as popular online productivity tools, Kaspersky reports. Based on the unique malicious and unwanted files observed, the most common lures included Zoom and Microsoft Office, with newer AI-based services like ChatGPT and DeepSeek being increasingly exploited by attackers. Kaspersky has released threat analysis and mitigation strategies to help SMBs respond. Kaspersky analysts explored how frequently malicious and unwanted software are disguised as legitimate applications commonly used by SMBs, using a sample of 12 online productivity apps. In total, Kaspersky observed more than 4,000 unique malicious and unwanted files disguised as popular apps in 2025. With the growing popularity of AI services, cybercriminals are increasingly disguising malware as AI tools. The number of cyberthreats mimicking ChatGPT increased by 115% in the first four months of 2025 compared to the same period last year, reaching 177 unique malicious and unwanted files. Another popular AI tool, DeepSeek, accounted for 83 files. This large language model launched in 2025 immediately appeared on the list of impersonated tools. ' Interestingly, threat actors are rather picky in choosing an AI tool as bait. For example, no malicious files mimicking Perplexity were observed. The likelihood that an attacker will use a tool as a disguise for malware or other types of unwanted software directly depends on the service's popularity and hype around it. The more publicity and conversation there is around a tool, the more likely a user will come across a fake package on the internet. To be on the safe side, SMB employees – as well as regular users – should exercise caution when looking for software on the internet or coming across too-good-to-be-true subscription deals. Always check the correct spelling of the website and links in suspicious emails. In many cases these links may turn out to be phishing or a link that downloads malicious or potentially unwanted software ', says Vasily Kolesnikov, security expert at Kaspersky. Another cybercriminal tactic to look for in 2025 is the growing use of collaboration platform brands to trick users into downloading or launching malware. The number of malicious and unwanted software files disguised as Zoom increased by nearly 13% in 2025, reaching 1,652, while such names as 'Microsoft Teams' and 'Google Drive' saw increases of 100% and 12%, respectively, with 206 and 132 cases. This pattern likely reflects the normalization of remote work and geographically distributed teams, which has made these platforms integral to business operations across industries. Among the analyzed sample, the highest number of files mimicked Zoom, accounting for nearly 41% of all unique files detected. Microsoft Office applications remained frequent targets for impersonation: Outlook and PowerPoint each accounted for 16%, Excel for nearly 12%, while Word and Teams made up 9% and 5%, respectively. Share of unique files with names mimicking the popular legitimate applications in 2024 and 2025 The top threats targeting small and medium businesses in 2025 included downloaders, trojans and adware. Phishing and Spam Apart from malware threats, Kaspersky continues to observe a wide range of phishing and scam schemes targeting SMBs. Attackers aim to steal login credentials for various services — from delivery platforms to banking systems — or manipulate victims into sending them money through deceptive tactics. One example is a phishing attempt targeting Google Accounts. Attackers promise potential victims to increase sales by advertising their company on X, with the ultimate goal to steal their credentials. Beyond phishing, SMBs are flooded with spam emails. Not surprisingly, AI has also made its way into the spam folder — for example, with offers for automating various business processes. In general, Kaspersky observes phishing and spam offers crafted to reflect the typical needs of small businesses, promising attractive deals on email marketing or loans, offering services such as reputation management, content creation, or lead generation, and more. Learn more about the cyber threat landscape for SMBs on Securelist. To mitigate threats targeting businesses, their owners and employees are advised to implement the following measures: Use specialized cybersecurity solutions that provide visibility and control over cloud services (e.g., Kaspersky Next). Define access rules for corporate resources such as email accounts, shared folders, and online documents. Regularly backup important data. Establish clear guidelines for using external services. Create well-defined procedures for implementing new software with the involvement of IT and other responsible managers. About Kaspersky Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky's deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company's comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and over 200,000 corporate clients protect what matters most to them. Learn more at

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store