UAE Warns of AI-Powered Scams Targeting Jobs, Homes and Identity
Artificial intelligence is now a core tool in the toolkit of cybercriminals operating in the United Arab Emirates, with authorities reporting a surge in deeply personalized fraud schemes that exploit trust in digital employment platforms, home security systems, and personal data.
AI-generated job offers now mimic real companies on LinkedIn and WhatsApp, targeting job seekers with convincing job postings for remote roles in tech, logistics, and finance. Victims are often asked to receive and forward money under pretenses like "payment verification" or "onboarding deposits," unknowingly becoming conduits for money laundering. Dubai Police confirmed over 1,800 complaints related to such scams between January and September 2026, with many victims later facing legal scrutiny despite being deceived.
To combat this, Dubai Police created a dedicated unit in early 2026 to investigate AI-facilitated economic crimes, while the Dubai Electronic Security Center (DESC) deployed Sarab — a public AI model capable of detecting manipulated video at 91% accuracy. Developed entirely by Emirati engineers and made available via open-source platforms, Sarab analyzes motion, facial alignment, and audio-video sync to expose deepfakes, helping banks, media, and government agencies verify digital content.
One in three reported smart home breaches this year involved unsecured surveillance cameras, according to the Ministry of Interior. Criminals are exploiting default passwords, outdated firmware, and network exposure to gain access to live feeds — turning devices meant for protection into tools for espionage and blackmail. TP-Link Tapo C200/C120 models were identified in September 2026 as vulnerable to local network exploits if firmware was not updated, though authorities stress any device is at risk without basic safeguards.
The Ministry urges all residents to:
• Immediately change default passwords to complex, unique combinations
• Enable two-factor authentication where supported
• Update firmware every 30 days
• Isolate IoT devices on a separate Wi-Fi network
• Disable remote access unless essential
• Report suspicious activity immediately through Dubai Police’s e-crime portal or the national hotline 800-7477
Response times to emerging threats have shifted from days to minutes. The DESC now operates an around-the-clock threat cell that deploys security patches to critical government systems within 30 minutes of identifying an AI-enabled exploit, supported by cloud-based AI tools like MDASH, developed in partnership with Microsoft and Core42.
Public awareness remains central to the national strategy. The "Don’t Get Played" campaign, launched in October 2026 by the DESC, uses a digital persona named "Yado Salama" — a relatable Emirati grandmother — to demonstrate how deepfake voice calls, fake HR emails, and fraudulent job ads work. The initiative has reached 11 million residents through social media, school programs, and mall kiosks, with a Dh230,000 prize fund incentivizing citizen-created educational content.
The UAE Cyber Security Council, alongside the Ministry of Human Resources and Emiratisation, has warned that deepfakes now produce full-length, convincing videos — not just short clips — and that voice cloning has been used in real-world scams to impersonate bank officials and government representatives.
Brigadier Saeed Mohammed Al Hajri of Dubai Police emphasized: "The criminals aren’t hiding. They’re broadcasting. And they’re counting on your haste. Slow down. Verify. Report."
The national digital safety strategy, updated in July 2026, now treats every resident as a frontline defender. Authorities stress that no technology can replace vigilance — especially when a compromised camera, a clicking link, or a too-good-to-be-true job offer can become the gateway to a crime you never intended to join.