OptiFi Technologies
Cybersecurity

How UAE trading companies actually lose money to email fraud

Nothing breaks, no alarm sounds, and a real person authorises a real payment. The controls that stop it cost almost nothing and are usually switched off.

·2 min read

The dominant financial cyber loss for UAE businesses is not ransomware and not a dramatic breach. It is an invoice paid to the wrong bank account, and it is not technically sophisticated.

How it works

An attacker gains access to one mailbox — usually through a reused password or a convincing phishing page. They do not announce themselves. They read quietly for weeks, learning who pays whom, how invoices are phrased, and which supplier relationships involve amounts worth taking.

Then they intervene in a genuine conversation. An invoice thread that has been running for a fortnight receives a message about updated banking details, sometimes from a lookalike domain, sometimes from the real compromised account. The tone is right because they have been reading the tone.

Nothing breaks. No alarm sounds. A real person in finance authorises a real payment following the real process, and the money is gone before the supplier chases it.

Why UAE trading companies specifically

Because the pattern fits. An importer or distributor sends and receives payment instructions constantly, often internationally, often in amounts large enough to be worth the attacker's several weeks of patience. And many are owner-managed, with no procurement function and no second signature to catch it.

The controls that actually stop it

  • Multi-factor authentication on every mailbox, including the owner's — the account most worth protecting and most often exempted
  • An alert when a mailbox starts forwarding externally, which is the classic first sign of a compromise in progress
  • External-sender marking, so a lookalike domain is visible to the person reading the message
  • SPF, DKIM and DMARC configured, so your own domain cannot be used against your own staff
  • A finance rule: changed bank details are verified by phone to a number you already held, never to a number in the email

That last one is procedural, costs nothing, and is the control that actually stops the loss. Every technical measure can be worked around by a sufficiently patient attacker; a phone call to a number they do not control cannot.

What it costs to fix

In most UAE tenants we review, nothing. The organisation already pays for a licence tier that includes the technical controls and has never switched them on — Microsoft 365 Business Premium is the common case.

Configuration is a day or two of work. The finance rule is a conversation. Set against a single successful redirection, the arithmetic is not close.

We do this as cybersecurity work in Dubai, and the mail-side controls sit in business email and Exchange setup. The technical half of the defence is mostly already licensed — the Microsoft 365 settings most UAE tenants never switch on.

Free consultationCallWhatsApp