Warning: 6 in 10 Financial Cyberattacks Start With Stolen Credentials—and That Should Worry CISOs More Than Malware
Reinforcing the Need for Phishing-Resistant Authentication, Continuous Monitoring of Account Behaviour, and Rapid Revocation of Compromised Access

Stolen credentials remain the most efficient entry point for financial cybercrime, accounting for roughly 60 percent of attacks targeting financial systems, according to a new warning from the UAE Cyber Security Council. The figure underscores a stubborn reality for security leaders: despite years of investment in advanced threat detection, the weakest link in financial security remains identity.
In comments carried by the Emirates News Agency, the council said compromised usernames and passwords continue to fuel fraud, identity theft, and unauthorised access to bank accounts and sensitive personal data. Financial information, it noted, remains among the most sought-after targets for cybercriminals, particularly as digital payments and mobile banking deepen their reach across the region.
The advisory urged both individuals and organisations to tighten basic cyber hygiene. Users were warned against storing sensitive passwords on unsecured devices, encouraged to remove untrusted applications, review privacy settings regularly, and keep operating systems and software fully updated. Two-factor authentication was highlighted as one of the most effective defences against account takeover, with the council emphasising that incremental safeguards can significantly reduce risk.
Crucially, the council also pointed out that financial breaches often begin far from the bank itself. Cybercriminals frequently compromise email or social media accounts first, then pivot toward financial platforms using recovered credentials and contextual information. Fake advertisements and phishing messages that mimic bank branding remain a common tactic, exploiting trust and urgency rather than technical vulnerabilities.
Why Stolen Credentials Is a Strategic Problem, Not a User Problem
For CISOs and technology leaders, the UAE warning on stolen credentials reinforces an uncomfortable truth: credential theft is no longer just a consumer awareness issue. It is a systemic risk that exposes weaknesses in identity governance, access control, and fraud detection across entire digital ecosystems.
This is especially relevant in Asia and the Middle East, where mobile-first financial services, super-apps, and rapid fintech adoption have expanded the attack surface dramatically. In many markets, a single identity is used across banking, government services, e-commerce, and social platforms. Once credentials are stolen, lateral movement becomes trivial.
The persistence of credential-based attacks also highlights the limits of perimeter-focused security. Attackers no longer need to breach infrastructure when valid credentials provide legitimate access. From the defender’s perspective, these attacks often look like normal user behaviour—until money is gone or data has been exfiltrated.
Implications for Asia’s Digital Economy
Across Asia, regulators are pushing cashless payments, digital IDs, and open banking frameworks to drive inclusion and efficiency. While these initiatives bring economic upside, they also amplify the impact of credential compromise. A single account takeover can cascade across multiple services, especially where identity federation and weak authentication practices are common.
There is also a maturity gap. Large banks may enforce multi-factor authentication and behavioural analytics, but smaller financial institutions, fintech startups, and third-party service providers often lag behind. Attackers, unsurprisingly, follow the path of least resistance.
From a geopolitical perspective, credential theft remains attractive because it is low-cost, scalable, and difficult to attribute. It fits neatly into both organised cybercrime and state-aligned operations that seek financial gain, intelligence, or coercive leverage without triggering overt escalation.
What CISOs Should Take Away
The UAE Cyber Security Council’s message may sound familiar, but the implications of stolen credentials are not. Credential theft is not declining; it is thriving precisely because it works. For security leaders, this means doubling down on identity as the new control plane—enforcing phishing-resistant authentication, continuous monitoring of account behaviour, and rapid revocation of compromised access.
Equally important is extending those controls beyond the enterprise. Third-party access, consumer-facing platforms, and employee personal accounts are now part of the same risk equation. Until identity security is treated as critical infrastructure, stolen logins will remain the front door to financial cybercrime—in the UAE, across Asia, and well beyond.



