🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Threat Intelligence › article

Threat Intelligence

Hajj 2026 Scams: How Fraudsters Target Pilgrims and NCA’s Cyber Drills

> By ChenHo | Aug 04, 2026 | 3 min read

For millions of Muslims, the pilgrimage to Mecca is a lifelong dream. But for organized cybercriminal syndicates, it is a highly lucrative data harvesting season. Throughout 2026, Saudi authorities have been battling an unprecedented wave of digital fraud, where scammers deploy sophisticated social engineering and spoofed portals to siphon millions from unsuspecting pilgrims before they even set foot in the Kingdom.

⚠️ THREAT INTELLIGENCE ADVISORY:
Financial threat actors are actively spoofing official Saudi tourism and Hajj registration portals (like Nusuk) to execute credential harvesting and financial fraud. The Saudi National Cybersecurity Authority (NCA) has activated emergency cyber drills to defend critical travel infrastructure.

Hajj 2026 Scams

Claim / Threat Activity Source Status
Proliferation of fake Hajj permits and unauthorized travel packages via WhatsApp and Telegram Ministry of Hajj and Umrah Verified (Ongoing campaign)
Spoofed versions of the official ‘Nusuk’ platform designed to steal banking credentials NCA Security Alerts Verified
Critical disruption of Saudi airport OT systems by scammers Social Media Rumors Disputed (No evidence of OT breach)
> TABLE_OF_CONTENTS [toggle]

Table of Contents

Context / Motivation: A Lucrative Season

The motivation behind the Hajj 2026 Scams is purely financial. The annual pilgrimage attracts millions of global travelers, many of whom are elderly or not digitally native. Scammers exploit the high demand and limited quotas for Hajj visas by offering “expedited” or “VIP” services through unofficial channels. By leveraging the emotional urgency of the pilgrimage, threat actors bypass typical critical thinking filters, convincing victims to wire money or input their Personally Identifiable Information (PII) into fraudulent domains.

Technical Analysis (TTPs)

The attackers rely heavily on AI-enabled social engineering and credential harvesting. Tactics include purchasing sponsored ads on search engines and social media platforms that direct victims to highly realistic, typosquatted versions of the official Saudi Nusuk platform. Once on the fake site, users are prompted to upload passport copies, national IDs, and input credit card details. To counter this, the Saudi National Cybersecurity Authority (NCA) has launched a massive Cybersecurity Enhancement Program. Through the centralized Haseen portal, the NCA is orchestrating round-the-clock threat hunting and recently executed large-scale cyber drills involving over 300 national entities to simulate incident response against these exact TTPs.

Impact Assessment

The severity of this threat is High for individuals and Medium for institutional infrastructure. While the core Saudi government servers remain heavily fortified, the real damage occurs at the endpoint-the user. Victims face severe financial losses and identity theft, often only realizing they have been scammed when they are turned away at airports or border checkpoints with invalid visas. The reputation of legitimate travel agencies is also collaterally damaged.

Mitigation Recommendations

  1. Strict Domain Verification: Pilgrims and agencies must ensure all registrations and payments are conducted exclusively through the official nusuk.sa domain or government-authorized partners.
  2. Endpoint Anti-Phishing: Travel agencies should deploy DNS-level filtering and anti-phishing training to prevent staff from inadvertently processing fake permits or falling for spoofed B2B communications.
  3. Zero Trust Payments: Never transfer funds to personal bank accounts, crypto wallets, or unverified third-party gateways promising “backdoor” Hajj approvals.

For ongoing tracking of regional cyber threats targeting the Middle East, keep monitoring CyberAsia.


> subscribe_to_intel

Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.

> establish_connection:
[X/Twitter]
[Telegram]

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Hajj 2026 Scams: How Fraudsters Target Pilgrims and NCA’s Cyber Drills is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: ChenHo

ChenHo is a Lead Threat Hunter and CTI Technical Contributor at CyberAsia, covering hacktivism networks, distributed denial-of-service (DDoS) telemetry, industrial SCADA systems, and emerging open-source intelligence (OSINT).

> related_intel --suggest