United Arab Emirates

Phishing simulation for the UAE’s
WhatsApp, courier and bill lures.

In the UAE, attackers pose as couriers demanding customs fees, utility and telecom providers chasing unpaid bills, and government services offering visa or fine updates, often over WhatsApp and SMS.

Regulators & frameworks
UAE IA Standard v2.1, Dubai DESC ISR v3.1, CBUAE Operational Risk Regulation, Federal PDPL
Channels to rehearse
WhatsApp, SMS, voice calls, email and Teams
Local lure patterns
Customs and parcel fees, utility and telecom bills, visa and government-service updates
KeenSec evidence
Simulation results, reporter logs, certificates, policy acknowledgements

Simulated UAE lures

Fees, bills and visas:
the pretexts that work here.

Simulated versions of pretexts widely used against people in the UAE, each paired with a landing page and a lesson.

Simulated example
WhatsApp

“Government services” · unknown number

Residence visa: pending fine

A fine is linked to your residence visa file. Clear it today to avoid travel restrictions: gov-services-portal.example

  • Government services don’t chase fines on WhatsApp
  • Travel threat creates panic

Regulators and frameworks

The UAE frameworks
your auditor asks about.

FrameworkApplies toKeenSec evidence
UAE Information Assurance Standard v2.1Federal entities and critical information infrastructure entitiesSimulation results, training completions, policy acknowledgements
Dubai DESC ISR v3.1Dubai Government entitiesAwareness training records and certificates
CBUAE Operational Risk Management Regulation (C 1/2026)Licensed financial institutions, from 14 September 2026Simulation results by team, reporter logs, training records
Federal PDPL (Decree-Law 45 of 2021)Organisations processing personal data; executive regulations pendingData-handling training and policy acknowledgements

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

Questions buyers ask

Frequently asked questions.

Which UAE frameworks does KeenSec help with?

KeenSec helps produce awareness evidence for the UAE Information Assurance Standard v2.1, Dubai DESC ISR v3.1, the CBUAE Operational Risk Management Regulation and the Federal PDPL. Your auditor decides compliance.

Can we run WhatsApp phishing simulations in the UAE?

Yes. KeenSec simulates WhatsApp lures such as visa fines, delivery fees and payroll changes, with a just-in-time lesson for anyone who taps the link.

Does any UAE framework require phishing simulation?

We don’t claim that. Simulation results are one strong form of evidence that your awareness programme works, alongside training records and policy acknowledgements.

Let’s connect the dots

Rehearse the lures the UAE sees.
Prove it at audit.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo