United Arab Emirates
Phishing simulation for the UAE’s
WhatsApp, courier and bill lures.
In the UAE, attackers pose as couriers demanding customs fees, utility and telecom providers chasing unpaid bills, and government services offering visa or fine updates, often over WhatsApp and SMS.
- Regulators & frameworks
- UAE IA Standard v2.1, Dubai DESC ISR v3.1, CBUAE Operational Risk Regulation, Federal PDPL
- Channels to rehearse
- WhatsApp, SMS, voice calls, email and Teams
- Local lure patterns
- Customs and parcel fees, utility and telecom bills, visa and government-service updates
- KeenSec evidence
- Simulation results, reporter logs, certificates, policy acknowledgements
Simulated UAE lures
Fees, bills and visas:
the pretexts that work here.
Simulated versions of pretexts widely used against people in the UAE, each paired with a landing page and a lesson.
Bill payments desk · billing@utility-notice.example
Final notice: service disconnection
Your electricity and water account has an overdue balance. Settle today to avoid disconnection. Pay securely via the link below.
Pay now- Look-alike domain
- Disconnection threat
“Government services” · unknown number
Residence visa: pending fine
A fine is linked to your residence visa file. Clear it today to avoid travel restrictions: gov-services-portal.example
- Government services don’t chase fines on WhatsApp
- Travel threat creates panic
Regulators and frameworks
The UAE frameworks
your auditor asks about.
| Framework | Applies to | KeenSec evidence |
|---|---|---|
| UAE Information Assurance Standard v2.1 | Federal entities and critical information infrastructure entities | Simulation results, training completions, policy acknowledgements |
| Dubai DESC ISR v3.1 | Dubai Government entities | Awareness training records and certificates |
| CBUAE Operational Risk Management Regulation (C 1/2026) | Licensed financial institutions, from 14 September 2026 | Simulation results by team, reporter logs, training records |
| Federal PDPL (Decree-Law 45 of 2021) | Organisations processing personal data; executive regulations pending | Data-handling training and policy acknowledgements |
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
Questions buyers ask
Frequently asked questions.
Which UAE frameworks does KeenSec help with?
KeenSec helps produce awareness evidence for the UAE Information Assurance Standard v2.1, Dubai DESC ISR v3.1, the CBUAE Operational Risk Management Regulation and the Federal PDPL. Your auditor decides compliance.
Can we run WhatsApp phishing simulations in the UAE?
Yes. KeenSec simulates WhatsApp lures such as visa fines, delivery fees and payroll changes, with a just-in-time lesson for anyone who taps the link.
Does any UAE framework require phishing simulation?
We don’t claim that. Simulation results are one strong form of evidence that your awareness programme works, alongside training records and policy acknowledgements.
Let’s connect the dots
Rehearse the lures the UAE sees.
Prove it at audit.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo