The Breach Brief  ·  Story Week UAE-004

What happens when
one stolen laptop never comes back?

Karim is a Finance Executive at a trading group in Dubai.
On a Tuesday evening in May, his laptop bag was stolen at the airport.
Twenty-three days later, a supplier called asking where their money had gone.

Dubai, UAE 20 – 24 Jul 2026 UAE PDPL 5-day story

This week’s story

Day 1  ·  Monday 20 Jul
The Trip

Karim, a Finance Executive in Dubai, was heading home from a two-day supplier offsite. At the airport, he set his laptop bag down for ninety seconds to reach for his boarding pass.

When he looked down, the bag was gone. Annoying. Expensive. He’d tell IT in the morning.

He did not think about the files on the laptop. That was the mistake.

Day 2  ·  Tuesday 21 Jul
What Was on the Laptop

He reported it stolen and IT wiped the device — or tried to. “It was password-protected,” he said. But a login password isn’t encryption: pull the drive, and the files just open.

On that drive: 216 suppliers’ bank details — IBANs, account names, payment cycles — and two years of customer payments. None of it encrypted. Nobody inside knew that yet.

Day 3  ·  Wednesday 22 Jul
The Silence

Twenty-three days. No alert. No flag. Inside the company, a replacement laptop was issued and month-end ran on time. The stolen laptop was a closed IT ticket.

Outside, the drive was read on day three — the payment cycles studied, a single supplier chosen to impersonate. They weren’t looking for a password. They were looking for a supplier to become.

Day 4  ·  Thursday 23 Jul
The Payment

A supplier of six years called: an invoice that showed as settled had never reached them. The payment had gone to an account that wasn’t theirs.

Nine days earlier, an email — matching the supplier’s details, invoice and cycle exactly — had asked Finance to change the bank details. Everything it needed had come from the stolen laptop. The breach was reported the same day it was discovered.

Day 5  ·  Friday 24 Jul
The Verdict
Live now

The timeline was reconstructed in full. Laptop stolen at 8:40 PM on 6 May. Reported to IT at 9:12 AM on 7 May, logged as a lost asset, remote wipe issued to a device that never reconnected. Drive read on 9 May. Bank-change email sent on 20 May. Redirected payment run on 29 May. Breach awareness established at 10:41 AM on 29 May — the moment the supplier’s call reached the finance manager. The breach was reported at 4:30 PM the same day.

Twenty-three days between the breach and the moment anyone inside knew to start the clock.

This is what the investigation found. Not as background. As verdict.

No one owned the alarm.
A breach has to be raised the moment it happens — not whenever someone eventually connects the dots. The laptop left the building on 6 May. The company became aware on 29 May. In between, the theft lived entirely inside an IT ticket: lost asset, wipe, replace, close. No one was assigned to ask whether a data breach had just occurred.
No one owned the data.
There was no named person responsible for what personal and financial data left the building on a device — no one whose job it was to ask why a two-year payment master and a customer ledger were living on a laptop that travelled through airports. So the question never got asked, and the habit was never governed.
Nothing guarded the door.
The laptop had a login password and no disk encryption. The export files were unencrypted. There was no log of who pulled the vendor master, or when. The one control that would have made the whole theft harmless — encryption that turns a stolen drive into noise — was never switched on.

In the UAE, data protection rules now apply, and the consequences for a breach are no longer hypothetical.

The investigators’ conclusion was the same one that appeared in the reports before it: the person who lost the laptop was not the problem. The absence of any system around that moment was.

Karim did everything a careful finance professional does. He checked his payments twice. He refused to work on a frozen screen. He reported the theft the next morning. He kept his files tidy and close.

That was the problem — because nothing around him was built to make any of it safe.

The 3-step protocol the investigators recommended:

1. Encrypt every device — and treat a lost one as a breach. Full-disk encryption on every laptop and phone, so a stolen drive is unreadable. And a named person who, the moment a device goes missing, asks what data was on it — and starts the breach protocol, not just the replacement order.

2. Govern data at rest. A clear rule on what data may be held offline and for how long — no unencrypted exports of payment or customer masters onto local machines. If it has to travel, it travels encrypted, and it’s deleted when the trip ends.

3. Train the people who touch the data. Not a policy handout. Training built around what finance, procurement and operations staff actually do every day — offline copies, device handling, bank-change requests — and what UAE data protection law requires in those specific moments.

Karim still works there. He knows what to do now. Does your team?

If your organisation needs to close this gap — the training exists, built for exactly this.
training.cybernym.io/login/?tab=demo

Cybernym.io — Cyber Instincts. Built, Not Taught.

Get each instalment
in your inbox

New chapter every day, Mon–Fri. Three minutes to read.
Built for finance, operations, and compliance teams across the UAE.

No spam. Unsubscribe any time. Your data is handled under UAE PDPL.

You're in — Day 2 arrives tomorrow

Watch your inbox.
Karim’s story continues tomorrow — and it gets worse before it gets better.