HomeTopics 2cybercrimePhishing on the Fly: Scammers Target UAE Passengers with Fake Official Messages

Phishing on the Fly: Scammers Target UAE Passengers with Fake Official Messages

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

The United Arab Emirates (UAE) has become a global hub for travel and tourism. However, this growth also attracts cybercriminals seeking to exploit unsuspecting victims. A recent rise in phishing scams targeting UAE passengers using Nigerian and Ethiopian phone numbers highlights the evolving tactics used by fraudsters. This article explores this specific scam campaign, delves into the broader issue of travel-related phishing attacks, and offers 10 crucial tips to help travelers stay safe from these digital threats.

Fake Flights and Phony Fees: Unveiling the UAE Passenger Scam

In July 2024, UAE residents reported receiving suspicious text messages from unknown Nigerian and Ethiopian phone numbers. Here’s a breakdown of the scam:

  • Impersonation: The messages pose as official airline or travel agency communications, often mentioning well-known UAE carriers like Emirates or Etihad Airways.
  • Urgency and Fear: The messages typically create a sense of urgency, claiming issues with flight bookings, missed payments, or passport irregularities.
  • Phishing Links: The messages often include phishing links that, when clicked, can lead to fraudulent websites designed to steal personal information or financial details like credit card numbers.

This specific scam campaign highlights the evolving tactics used by cybercriminals to exploit travelers’ anxieties and limited familiarity with local regulations.

A Global Grounding: The Rise of Travel-Related Phishing Attacks

Travel-related phishing attacks are a global phenomenon, targeting individuals at various stages of their journeys:

  • Pre-Departure Scams: Phishing emails or messages might impersonate airlines, hotels, or booking platforms to steal payment information or travel documents.
  • In-Transit Scams: Fraudsters might target travelers with fake airport Wi-Fi login pages or messages claiming urgent visa or customs issues requiring immediate payment.
  • Post-Travel Scams: Phishing attempts could impersonate travel agencies or loyalty programs offering fake refunds, rewards, or deals that steal personal information.

Travelers need to be aware of these evolving tactics to protect themselves throughout their journeys.

10 Takeoff Tips: Avoiding Travel-Related Phishing Scams

Here are 10 crucial tips to safeguard yourself from travel-related phishing attacks:

  1. Verify Communication: Always verify the legitimacy of any communication claiming to be from an airline, travel agency, or official source. Contact the organization directly using phone numbers or email addresses listed on their official website.
  2. Beware of Urgency: Phishing attempts often create a sense of urgency to pressure you into clicking on links or disclosing information without proper verification.
  3. Suspicious Links: Do not click on links embedded within suspicious text messages or emails. It’s safer to navigate directly to the official website of the airline or travel agency.
  4. Secure Wi-Fi: Avoid using unsecured public Wi-Fi networks at airports or hotels for sensitive transactions like online banking or entering credit card information. Consider using a mobile hotspot or Virtual Private Network (VPN) for added security.
  5. Strong Passwords & MFA: Utilize strong, unique passwords for all travel-related online accounts and enable Multi-Factor Authentication (MFA) where available.
  6. Official Apps: Download travel apps directly from official app stores and avoid third-party app marketplaces that might harbor malicious software.
  7. Data Backups: Consider creating backups of travel documents and important information before your trip in case your device gets lost or compromised.
  8. Phishing Awareness: Educate yourself about common phishing tactics and red flags to identify and avoid suspicious messages.
  9. Travel Insurance: Consider travel insurance that might offer protection against financial losses resulting from phishing scams.
  10. Report Phishing Attempts: Report suspicious phishing messages to the relevant authorities and the organization being impersonated to help track down scammers.

Conclusion: A Secure Journey Awaits

Travel-related phishing scams can disrupt trips and lead to financial losses. By staying informed about common tactics, practicing caution with online communication, and prioritizing travel cybersecurity, you can navigate the digital world with confidence and ensure a smooth, secure journey. Remember, a little cybersecurity awareness can go a long way in protecting yourself from scams and safeguarding your valuable travel plans. So, pack your bags, embrace your sense of adventure, and prioritize cybersecurity for a worry-free travel experience.

Ouaissou DEMBELE
Ouaissou DEMBELE
Ouaissou Dembele is a cybersecurity strategist with over 13 years of experience in purple teaming, governance, risk and compliance (GRC), and security program leadership across the Middle East and Africa. He is Director at Sainttly Group, a UAE-based group comprising Saintynet Cybersecurity, Cybercory Magazine, CISO Paradise, and Digitallium Software, and serves as Editor-in-Chief of Cybercory. At Saintynet Cybersecurity, he leads cybersecurity strategy and delivery across consulting, SOC and MSSP services, regulatory compliance, and training, guiding governments, banks, telecoms, and enterprises in identifying and mitigating evolving threats. His work includes national-level SOC initiatives for African governments. His mission is to empower organizations with resilient, scalable, and future-ready cybersecurity. Before Sainttly Group, he held consulting roles across the MEA region, working with global organizations on security architecture, operations, and compliance programs. He is an experienced speaker and trainer, regularly contributing to industry conferences and professional events, and works in English, French, and Arabic. His certifications include CCNP Security, CCNA Security, CCNA R&S, CEH, and ITIL, alongside the CCIE Security written exam. He delivers certification preparation training for CISSP, CISM, CISA, CCSP, PMP, and ISO 27001, and holds a Master's Diploma in Network Security (2013). As Editor-in-Chief of Cybercory.com, he is a trusted voice in the regional cybersecurity community and an advisor to organizations seeking to strengthen their security posture and resilience.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img