AI cybercrime risks facing UAE residents and businesses have become measurably worse, with the average time for an attacker to move through a compromised network falling to 29 minutes in 2025, down from 48 minutes the previous year, according to the CrowdStrike 2026 Global Threat Report.
The fastest recorded intrusion in the same period took just 27 seconds from initial access to lateral movement inside an organisation’s network.
Yassin Watlal, CrowdStrike’s Senior Director of Systems Engineering for the Middle East, Turkey and Africa, said AI has changed who can carry out these attacks, not only how fast they happen. ‘AI has dropped the barrier of entry for a lot of the threat actors,’ he said. ‘The less sophisticated actors now can do things that they were not able to either do, or it would take a lot of time.’
AI cybercrime risks are accelerating on both sides
Attacks by AI-enabled adversaries increased by 89% in 2025, the CrowdStrike Global Threat Report found. The same report recorded that more than 90 organisations had their own legitimate AI tools exploited by threat actors to generate malicious commands and steal sensitive data.
The nature of intrusions has also shifted. 82% of cybersecurity detections in 2025 were malware-free, up from 51% in 2020, according to the report’s findings blog. Attackers are increasingly using stolen credentials to log in rather than forcing their way through technical vulnerabilities. ‘They will want to log in, not break in,’ Watlal said.
In one documented intrusion, data exfiltration began within four minutes of initial access. That compression leaves security teams little margin: an attack can spread through a network before an analyst has finished reviewing the first alert that triggered it.
AI is accelerating both sides of that race. Attackers use it to automate reconnaissance, craft more convincing phishing messages, and produce malware faster. Defenders need it to investigate alerts and respond at comparable speed.
Since April 2025, multiple threat actors have also exploited a critical vulnerability in Langflow AI, a widely used tool for building AI agents and workflows, to establish persistence, steal credentials and deploy malware, according to CrowdStrike’s AI monitoring guidance. ChatGPT was mentioned in criminal forums 550% more than any other AI model tracked in the same period, the threat report infographic noted.
What residents and businesses should do now
For residents, Watlal’s advice is practical and immediate: enable multi-factor authentication on personal accounts, verify unexpected requests through a separate channel, and pause before approving a login or clicking a link.
‘Things go so quickly in life that quite often we respond to something that then we regret, or we approve something that then we regret,’ he said.
The risk of impersonation is one reason that pause matters. Voice can be cloned. Phishing messages can be written in fluent, targeted language adapted to the recipient’s country or role. Watlal said the goal for many attackers is now identity theft rather than technical exploitation: someone with valid credentials does not trigger the same alarms as someone breaking through a firewall.
For businesses, the questions go further. Companies deploying AI agents internally need to define what information those systems can reach, what actions they can take without human approval, and where a person must remain in the loop. ‘What can we ask the AI to do safely and then put guardrails around it?’ Watlal said.
That question is becoming urgent. AI agents, unlike chatbots, do not simply return an answer. They can be assigned an objective and take multiple steps to complete it, including writing code, calling other software and acting on data. A wrong decision by an agent does not end at a wrong answer: it can turn into an action.
Some frontier AI researchers are separately debating longer-term risks around autonomous systems. Anthropic chief executive Dario Amodei has argued that safety systems and independent oversight need time to keep pace with frontier development. But Watlal’s point is that the more immediate risks do not require hypothetical futures. They are already affecting organisations in the region today.
CrowdStrike tracked 24 new adversaries in 2025, bringing its total to more than 281 actively monitored groups.
