Fraud and Cyber Risk Briefing: Practical Steps for Businesses Operating in the UAE
Date Posted:Fri, 3rd Apr 2026
Periods of instability or conflict, creates opportunity. As organisations adapt to the current disruption (such as changing suppliers, accelerating decisions, or managing staff and operations across borders), fraudsters and cyber actors move quickly to exploit gaps. They seek gaps in controls, oversight, and communication, often targeting moments where operational pressure weakens normal decision-making.
I am seeing an increase in fraud and cyber risk exposure across the Middle East, particularly those with cross-border supply chains and financial flows.
There is a consistent pattern where operational pressure, speed of decision-making, and reduced visibility are creating the exact conditions in which fraud thrives.
For BCCD members operating in or through the UAE, this is particularly relevant. The UAE’s role as a regional and international hub means it often sits at the centre of cross-border activity and, consequently, cross-border risk.
Recent messaging from both the UK government and UAE authorities has highlighted the need for increased cyber vigilance, particularly in relation to phishing campaigns, social engineering, and attempts to exploit geopolitical developments as a means of deception.
Supply Chain Pressure
One of the most immediate and often overlooked fraud risks in the current conflict environment is supply chain fraud.
As pressure mounts on organisations to maintain continuity by securing goods, managing logistics, and meeting client demand, means that procurement and operational teams are being forced to move faster, often with less visibility than usual.
This is precisely where fraud emerges. Where there is pressure, there is opportunity. Where there is opportunity, there is fraud.
In many cases, the fraud is not sophisticated it is simply well timed; and we are seeing a clear increase in:
- False suppliers entering the chain during periods of disruption
- Legitimate suppliers being impersonated, particularly where banking details or routes have changed
- Shortened onboarding and verification processes, creating gaps in due diligence
- Last-minute changes to delivery or payment instructions, often justified by “regional disruption”
What we are seeing in practice
Across our casework, investigations and intelligence work, several trends are becoming more pronounced:
- Supplier and payment fraud linked to disruption
Changes in logistics, banking arrangements, or counterparties are being exploited through false payment instructions and impersonation.
- Geopolitically themed phishing
Emails referencing sanctions, regional updates, or security alerts are being used to create urgency and credibility.
- Increased reliance on third parties
As organisations expand or adapt quickly, due diligence (vetting, screening & background checks) can lag creating exposure through partners, agents, or intermediaries.
- Executive impersonation
Fraudsters are targeting finance teams using spoofed senior leadership communications, often tied to “urgent” regional developments.
- ESG and sustainability-related fraud
We also seeing an influx of false or exaggerated environmental, social, or ethical claims that are being used to secure contracts, particularly where organisations are under pressure to demonstrate responsible sourcing. In some cases, documentation or certifications are fabricated or misrepresented, exposing businesses to financial, regulatory, and reputational risk.
What this means for businesses now
This is not a time for wholesale redesign of control frameworks, now is the time for targeted, practical adjustments and extra vigilance:
- Reintroduce friction into supply chain decisions
Any new supplier, change in payment details, or urgent procurement request should trigger independent verification. This should be on a “no exception” basis.
- Revalidate critical suppliers
Focus on those recently onboarded or operating in affected jurisdictions. Confirm ownership, banking details, and operational legitimacy.
- Challenge urgency
Requests framed around disruption, delay, or regional pressure should be treated with increased scepticism, not reduced scrutiny.
- Increase internal awareness (immediately)
Short, targeted reminders to staff about phishing, impersonation, and supplier fraud can materially reduce exposure.
- Tighten escalation routes
Ensure employees know exactly how to report suspicious communications or transactions, and that those reports are acted on immediately.
• Control communication channels
Avoid approving financial or supplier changes via informal or unverified channels (e.g. WhatsApp, personal email).
A shifting risk environment
The UAE remains a stable and well-regulated environment, and authorities continue to reinforce strong cybersecurity and financial crime messaging. However, the external environment is fluid and BCCD members must respond accordingly.
Fraud and cyber risk during periods of instability are rarely complex, but they are highly effective because they exploit timing, pressure, and human behaviour.
Author: Neil Miller, Founder & CEO at TenIntelligence