Dr. Mohamed Al Kuwaiti said every Iranian missile or drone strike on a UAE target during the 2026 war was accompanied by a cyberattack on the same target.
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did UAE Cybersecurity Council chief Dr. Mohamed Al Kuwaiti report about Iran’s systematic pairing of every missile and drone strike aga. Article summary: Dr. Mohamed Al Kuwaiti described a coordinated hybrid campaign: he said every Iranian missile or drone strike against a UAE target—including ports, refineries and airports—was accompanied by a cyberattack aimed at that s. Topic tags: general, general web, user generated, government, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermar
The UAE’s cyber chief, Dr. Mohamed Al Kuwaiti, said the country faced a coordinated form of hybrid warfare in 2026: in his account, each Iranian missile or drone strike against a UAE target was accompanied by a cyberattack directed at that same target. The significance of the claim is not simply the volume of malicious activity, but the synchronization of physical strikes, digital disruption and pressure on public confidence. 6
Al Kuwaiti described attacks spanning critical sectors, including aviation and energy. The UAE Cyber Security Council said it had detected and contained coordinated activity against aviation, energy and education since fighting began in February. 2
Reported techniques included attempts to infiltrate networks, deploy ransomware and run systematic phishing campaigns against national platforms and vital sectors. 14 Al Kuwaiti also warned that cyber threats now extend beyond data theft: manipulated content and AI-enabled deception can target people, communities and critical services by weakening confidence in reliable information.
5
That makes the campaign broader than a conventional intrusion problem. A blocked network attack may still be paired with false narratives or manipulated media intended to create confusion, panic or distrust during a crisis.
The UAE reported about 800,000 attempted cyberattacks per day at the peak of the conflict—roughly four times the prewar level, according to reporting on Cyber Security Council figures. 2 Separately, Al Kuwaiti said the country recorded 640,000 cyberattacks on a Tuesday in September.
1
These figures should not be read as 800,000 or 640,000 successful compromises. They describe reported hostile or attempted activity, a category that can include blocked probes, phishing attempts and other unsuccessful events.
Al Kuwaiti said Iran’s Islamic Revolutionary Guard Corps was behind “many” attacks on the UAE and called Iran a major actor in the offensive. 1 That is an attribution by a UAE official. Public reporting does not independently establish IRGC responsibility for each cyber incident or each alleged strike-and-cyber pairing.
That distinction matters in cyber conflict, where operations can be routed through intermediaries, use shared tools or be conducted by aligned groups rather than directly identifiable state units.
The response, in Al Kuwaiti’s framing, depended on collective defence: government institutions and domestic and international private-sector operators sharing information and responding across interconnected systems. He has stressed that cybersecurity is a responsibility shared by government, industry and the wider community.
This approach is especially relevant for ports, airports, energy systems and communications networks, where ownership, operations and technical dependencies often cross public and private boundaries. The operational lesson is straightforward: resilience depends on rapid intelligence-sharing and coordinated response before an incident can cascade from one organization or sector to another.
Al Kuwaiti has called for a “Cyber Geneva Convention” to establish rules for cyberwarfare, protect digital assets and define when a major cyberattack on critical infrastructure should be regarded as an act of war. 3
His argument reflects a practical legal problem. A state may face cyber operations that disrupt civilian services while attribution remains contested and the consequences of a counterattack can cross borders or affect noncombatants. Clearer international norms would not eliminate those difficulties, but they could set expectations around civilian infrastructure, accountability and thresholds for state action.
The UAE has paired this norm-building agenda with international standards work. In July 2026, the International Telecommunication Union appointed Al Kuwaiti chair of the Arab Regional Group of ITU-T Study Group 17, the ITU body focused on information-security standardization, cybersecurity, identity management, privacy and emerging technologies. The UAE has also publicly supported international cooperation on misuse of AI and emerging technologies.
A separate joint advisory by the UK’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD warned that Iranian state cyber actors had used the CHOSEN BRICK spyware family against dissidents, activists and journalists since at least 2025. The advisory says the malware can collect contacts, emails and social-media messages, potentially enabling tracking of targets’ movements.
The campaign used spear-phishing and social engineering on platforms including WhatsApp and Telegram; the NCSC said the spyware could collect screen captures and messaging history.
There is no public evidence in the materials cited here that CHOSEN BRICK was used in the alleged UAE infrastructure campaign. Its relevance is instead illustrative: the same wider threat landscape can include disruptive operations against critical systems as well as targeted surveillance of individuals. Those are different missions, victims and technical contexts, and they should not be conflated.
For a country pursuing expanded AI adoption under its Centennial 2071 vision, the issue is not only preventing unauthorized access to networks. It is protecting the trust, communications and essential services that increasingly depend on digital systems.
Al Kuwaiti’s account of synchronized strikes and cyberattacks therefore points to a broader planning requirement: physical security, cyber defence, crisis communications and misinformation response must operate together. In a hybrid conflict, defending one layer alone may not be enough. 6
5
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Dr. Mohamed Al Kuwaiti said every Iranian missile or drone strike on a UAE target during the 2026 war was accompanied by a cyberattack on the same target.
Dr. Mohamed Al Kuwaiti said every Iranian missile or drone strike on a UAE target during the 2026 war was accompanied by a cyberattack on the same target. He described a hybrid threat that combined pressure on critical infrastructure with ransomware, phishing and influence operations, while attributing “many” attacks to Iran’s IRGC as a UAE government assessment.
Al Kuwaiti’s proposed “Cyber Geneva Convention” seeks clearer rules for attacks on civilian digital infrastructure, including when a major cyberattack should be treated as an act of war.