The scale of cyberattacks via phishing emails is increasing, and the United Arab Emirates Cyber Security Council is making it clear that the threat is far from being brought under control. In a recent warning, the Council told the Emirates News Agency (WAM) that over 75% of cyberattacks now begin with phishing emails or deceptive messages, highlighting how attackers continue to rely on simple, deceptive tactics to gain access to sensitive systems.
See also: Dutch Police: Breach via phishing attack

The advisory, shared with WAM, highlights email fraud as a major entry point for breaches involving personal accounts, financial data and institutional systems. These messages are often designed to appear legitimate, making them difficult to detect at a glance and easy to activate without verification.
The numbers behind cyberattacks via phishing emails highlight why the problem persists. According to the Council, more than 3.4 billion phishing emails are sent globally every day, targeting individuals across a variety of sectors and regions.
These messages are not limited to basic scams. Many are designed to steal login credentials, distribute malware, or collect personal information that can later be used in identity theft, extortion, or broader cyber campaigns. The volume ensures that even a small success rate can lead to a significant impact.
The Council noted that this type of fraud continues to spread widely, often exploiting gaps in user awareness and digital behavior rather than weaknesses in technology alone.
The UAE Cyber Security Council described how cyberattacks via phishing emails are typically structured to push users into quick action. The messages may request urgent payments, urge users to verify accounts or direct them to login pages via embedded links.
In many cases, these emails impersonate trusted entities such as banks or service providers. Others rely on offers that seem unusually attractive, luring users into clicking links or sharing information without proper checks.
The Council also highlighted common signs, such as emails with spelling or grammatical errors, unclear sender identities and requests for personal data without valid justification. Despite being widely recognised indicators, such tactics continue to be used because they still manage to evade users’ attention.
See also: GitHub Phishing: Fake OpenClaw tokens to steal crypto wallets

The trend of cyberattacks via phishing emails places significant responsibility on users, particularly as attackers continue to improve the way these messages are presented. The Council stressed that individuals and employees remain a primary target, making awareness a critical part of any defense strategy.
To reduce exposure, the Council advised users to avoid interacting with suspicious links or messages and to avoid scanning QR codes in untrusted environments. It also stressed the importance of keeping login credentials private and enabling multi-factor authentication on all accounts.
Regular system updates and application patches were also highlighted as necessary steps to limit vulnerabilities that may be exploited following a phishing attempt.
Beyond prevention, the UAE Cyber Security Council has stressed the importance of early reporting in dealing with cyberattacks via phishing emails. Users who spot suspicious messages are encouraged to report them immediately rather than ignoring or deleting them.
Timely reporting allows security teams to analyze patterns, identify ongoing campaigns, and take action to block further attacks. In large-scale phishing operations, even a single reported message can help detect and stop broader activity.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Council reiterated that rapid action at the user level can significantly reduce the overall impact of these attacks.
See also: Device code phishing attack has targeted 340+ organizations

The continued dominance of phishing email attacks reflects a broader trend in the cybersecurity landscape. While organizations invest in advanced tools and systems, attackers continue to rely on methods that require minimal technical effort but deliver consistent results.
