Threat Intelligence
~/ › Threat Intelligence › article
Hajj 2026 Scams: How Fraudsters Target Pilgrims and NCA’s Cyber Drills
> By ChenHo | Aug 04, 2026 | 3 min read
For millions of Muslims, the pilgrimage to Mecca is a lifelong dream. But for organized cybercriminal syndicates, it is a highly lucrative data harvesting season. Throughout 2026, Saudi authorities have been battling an unprecedented wave of digital fraud, where scammers deploy sophisticated social engineering and spoofed portals to siphon millions from unsuspecting pilgrims before they even set foot in the Kingdom.
⚠️ THREAT INTELLIGENCE ADVISORY:
Financial threat actors are actively spoofing official Saudi tourism and Hajj registration portals (like Nusuk) to execute credential harvesting and financial fraud. The Saudi National Cybersecurity Authority (NCA) has activated emergency cyber drills to defend critical travel infrastructure.

| Claim / Threat Activity | Source | Status |
|---|---|---|
| Proliferation of fake Hajj permits and unauthorized travel packages via WhatsApp and Telegram | Ministry of Hajj and Umrah | Verified (Ongoing campaign) |
| Spoofed versions of the official ‘Nusuk’ platform designed to steal banking credentials | NCA Security Alerts | Verified |
| Critical disruption of Saudi airport OT systems by scammers | Social Media Rumors | Disputed (No evidence of OT breach) |
Table of Contents
- Context / Motivation: A Lucrative Season
- Technical Analysis (TTPs)
- Impact Assessment
- Mitigation Recommendations
Context / Motivation: A Lucrative Season
The motivation behind the Hajj 2026 Scams is purely financial. The annual pilgrimage attracts millions of global travelers, many of whom are elderly or not digitally native. Scammers exploit the high demand and limited quotas for Hajj visas by offering “expedited” or “VIP” services through unofficial channels. By leveraging the emotional urgency of the pilgrimage, threat actors bypass typical critical thinking filters, convincing victims to wire money or input their Personally Identifiable Information (PII) into fraudulent domains.
Technical Analysis (TTPs)
The attackers rely heavily on AI-enabled social engineering and credential harvesting. Tactics include purchasing sponsored ads on search engines and social media platforms that direct victims to highly realistic, typosquatted versions of the official Saudi Nusuk platform. Once on the fake site, users are prompted to upload passport copies, national IDs, and input credit card details. To counter this, the Saudi National Cybersecurity Authority (NCA) has launched a massive Cybersecurity Enhancement Program. Through the centralized Haseen portal, the NCA is orchestrating round-the-clock threat hunting and recently executed large-scale cyber drills involving over 300 national entities to simulate incident response against these exact TTPs.
Impact Assessment
The severity of this threat is High for individuals and Medium for institutional infrastructure. While the core Saudi government servers remain heavily fortified, the real damage occurs at the endpoint-the user. Victims face severe financial losses and identity theft, often only realizing they have been scammed when they are turned away at airports or border checkpoints with invalid visas. The reputation of legitimate travel agencies is also collaterally damaged.
Mitigation Recommendations
- Strict Domain Verification: Pilgrims and agencies must ensure all registrations and payments are conducted exclusively through the official
nusuk.sadomain or government-authorized partners. - Endpoint Anti-Phishing: Travel agencies should deploy DNS-level filtering and anti-phishing training to prevent staff from inadvertently processing fake permits or falling for spoofed B2B communications.
- Zero Trust Payments: Never transfer funds to personal bank accounts, crypto wallets, or unverified third-party gateways promising “backdoor” Hajj approvals.
For ongoing tracking of regional cyber threats targeting the Middle East, keep monitoring CyberAsia.
> subscribe_to_intel
Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Hajj 2026 Scams: How Fraudsters Target Pilgrims and NCA’s Cyber Drills is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
Threat Intelligence
Threat Intelligence
Hacker vs Hacktivist: 5 Dangerous Differences in Modern Cyber Warfare
> read
Threat Intelligence