Months after the disclosure of a data breach involving personal data and identity documents belonging to hundreds of participants in Abu Dhabi Finance Week, the incident continues to raise questions about data protection and digital risk management at one of the Gulf’s leading international financial platforms. Reports revealed in February 2026 that more than 700 passports and identity cards were accessible on an unsecured cloud server linked to the event’s participant registration system. On 12 March 2026, the Spanish National Cybersecurity Institute (INCIBE-CERT) addressed the data breach in a published article on its specialized cybersecurity blog, outlining details of the breach, how the documents were exposed, and the measures taken by the event organizers after discovering the vulnerability.
The issue takes on additional significance as Abu Dhabi prepares to host a new edition of its Finance Week in December 2026. The breach thus brings the incident back into focus, not merely as a technical flaw that was contained, but as a test of trust in the digital infrastructure underpinning Abu Dhabi’s efforts to establish itself as a global financial centre.
Data Breach Exposes Hundreds of Participants
In February 2026, a data breach linked to Abu Dhabi Finance Week, one of the most prominent international financial gatherings in the Gulf region, was disclosed. The incident occurred following the 2025 edition of the event, which attracted more than 35,000 participants from around the world, with participating institutions representing assets worth more than USD 62 trillion.
According to the Financial Times, more than 700 passports and government-issued identity cards were found stored on an unsecured cloud server linked to the event’s participant registration system. The documents were accessible online using a standard web browser, without the need for specialized tools or technical skills.
The incident attracted widespread attention due to the nature of the individuals whose data was included. The documents included information belonging to a number of prominent figures in politics, finance, and investment, including former British Prime Minister David Cameron, billionaire hedge fund manager Alan Howard, and American investor and former White House communications director Anthony Scaramucci.
Press reports also named other individuals among those affected by the incident, including Richard Teng, CEO of Binance and former CEO of the Abu Dhabi Global Market, and Lucie Berger, the EU Ambassador to the UAE.
Vulnerability in a Third-Party Storage Environment
According to the available information, the breach was not the result of a direct intrusion into Abu Dhabi Finance Week’s systems by a criminal actor, but was instead linked to a cloud storage environment managed by an external service provider.
The vulnerability was discovered by independent security researcher Ronny Suchowski while searching for unprotected cloud storage services. According to reports, the documents were publicly accessible for at least two months before the server was secured following the disclosure of the issue.
Abu Dhabi Finance Week’s management stated that the incident involved “a storage environment managed by a third-party service provider” concerning a limited group of participants from the 2025 edition, confirming that the environment was secured immediately upon identification of the vulnerability. It also stated that its initial review showed that data access activity was limited to the researcher who discovered the issue.
The event management also announced that registered participants within the scope of the incident were notified directly, in a step aimed at containing the immediate consequences of the breach.
Identity Documents, Invoices, and Internal Documents
The exposed data was not limited to images of passports and identity cards. According to reports, the available files also included invoices and internal documents, broadening the scope of potential risk beyond identity data exposure to the possible retention or unauthorized use of administrative and business information.
The risks of exposing such documents are not limited to privacy violations, as passport and identity card images can be used for identity theft or to carry out more precisely targeted phishing attacks. This risk is particularly significant when it concerns prominent political and financial figures, as leaked identity data can be combined with other publicly available information to carry out fraud or more sophisticated forms of digital targeting.
Incident Receives International Attention
On 12 March 2026, the Spanish National Cybersecurity Institute INCIBE-CERT addressed the incident in a specialized bulletin, noting that the breach became public in mid-February following media reports of potential access to participants’ personal documents. The center noted that the files included copies of passports, identity documents, and other data used in the participant accreditation process.
Coverage of the incident by a specialized cybersecurity body represents an important development compared to the initial coverage, which focused primarily on the Financial Times’ disclosure of the breach, as it placed the incident within a broader context concerning data security, cloud services, and personal information protection.
Abu Dhabi Finance Week at the Heart of the Emirate’s Financial Ambitions
The sensitivity of the incident is heightened by the position Abu Dhabi Finance Week holds on the international stage. The 2025 edition attracted more than 35,000 participants from 175 nationalities and featured more than 800 speakers and around 394 sessions, while participating entities representing assets worth more than USD 62 trillion.
Through the event, Abu Dhabi seeks to strengthen its position as a global center for capital and investment and to attract financial institutions, investment funds, and policymakers from around the world.
As such, the significance of the breach extends beyond the volume of data exposed. As the event’s prominence, number of participants, and value of the assets represented by participating institutions increase, so too do expectations regarding the level of protection afforded to the data collected through it, particularly identity and accreditation data.
From a Technical Flaw to a Data Governance Question
The exposure of material of this level of sensitivity raises fundamental questions regarding data governance, regulatory oversight, and institutional accountability. If a country seeks to present itself as a global financial centre, aspires to attract international capital and host elite forums, the exposure of participants’ data at one of its prominent financial events raises broader questions regarding the standards in place to protect personal information and manage third-party risk.
The incident specifically highlights the importance of managing risks associated with external service providers, since financial institutions’ and international events’ reliance on specialized cloud storage and data management companies does not eliminate their own responsibility for protecting that data. A flaw in an environment managed by a third party can have the same consequences that may result from a direct breach of primary systems.
Moreover, containing the vulnerability after its discovery does not eliminate the need to review how it remained accessible for such a long period, and whether monitoring and security testing procedures before the incident were sufficient to detect it at an earlier stage.
Privacy Artificial Intelligence, and Surveillance
Concerns regarding data protection are compounded by the country’s growing reliance on AI-based surveillance technologies. While these systems are usually justified as tools for enhancing security and efficiency, they can significantly undermine individual privacy and have been subject to continued criticism from human rights organizations, which warn of the potential of misuse, a lack of transparency, and weak legal safeguards against abuse.
That said, the Abu Dhabi Finance Week incident itself provides no evidence that government surveillance technologies were used to access or leak the data. The published facts indicate a flaw in a storage environment managed by a third party. However, the two incidents intersect around a broader question concerning data governance, privacy safeguards, and institutions’ ability to protect sensitive personal information.
Abu Dhabi Prepares for a New Edition of Its Finance Week
The latest development in the matter comes as Abu Dhabi prepares to host the fifth edition of Abu Dhabi Finance Week from 7 to 10 December 2026. On 27 July, the emirate announced that the event would feature more than 800 speakers and over 70 specialized events, and is expected to attract more than 35,000 participants.
Abu Dhabi is presenting the new edition as reaffirmation of international financial institutions’ confidence in the emirate’s business environment, while the 2026 program focuses on topics including digital financial assets, tokenization, private investments, artificial intelligence, trade and energy, and real estate and infrastructure.
This announcement makes data protection even more closely tied to the event’s future. As thousands of senior investors, officials, and policymakers return to Abu Dhabi, the ability of the institutions concerned to demonstrate the effectiveness of their security measures will be part of the trust the emirate seeks to establish with the global financial sector.
A Test of Trust Rather Than Merely a Cyber Incident
Despite the vulnerability being closed and affected participants notified, the incident revealed shortcomings in data protection and third-party risk management and raised questions about the effectiveness of the security controls in place.
Ultimately, the issue is not only about a cloud server that was secured, but about how an institution hosting prominent political and financial figures handles highly sensitive data, and its ability to ensure that the measures to protect such data are proportionate to the standing it seeks to establish.
As the 2026 Abu Dhabi Finance Week approaches, the data breach is shifting from a technical incident that occurred in the past to an ongoing test of trust. Abu Dhabi’s efforts to establish itself as a global financial centre depend not only on the volume of capital it attracts or the number of participants in its conferences, but also on its ability to demonstrate that the digital infrastructure supporting this ambition enjoys the same level of reliability and protection.
In this context, the broader lesson of the incident may be that cybersecurity is no longer a technical issue separate from the reputation of financial centres, but has become part of their ability to build and maintain trust in a global environment where the sensitivity of personal and financial data continues to grow.

