{"id":501,"date":"2026-08-04T15:30:00","date_gmt":"2026-08-04T15:30:00","guid":{"rendered":"https:\/\/cyberasia.io\/article\/blog\/hajj-2026-scams-how-fraudsters-target-pilgrims-and-ncas-cyber-drills\/"},"modified":"2026-08-17T08:58:12","modified_gmt":"2026-08-17T08:58:12","slug":"hajj-2026-scams-how-fraudsters-target-pilgrims-and-ncas-cyber-drills","status":"publish","type":"post","link":"https:\/\/cyberasia.io\/article\/threat-intelligence\/hajj-2026-scams-how-fraudsters-target-pilgrims-and-ncas-cyber-drills\/","title":{"rendered":"Hajj 2026 Scams: How Fraudsters Target Pilgrims and NCA&#8217;s Cyber Drills"},"content":{"rendered":"<p>For millions of Muslims, the pilgrimage to Mecca is a lifelong dream. But for organized cybercriminal syndicates, it is a highly lucrative data harvesting season. Throughout 2026, Saudi authorities have been battling an unprecedented wave of digital fraud, where scammers deploy sophisticated social engineering and spoofed portals to siphon millions from unsuspecting pilgrims before they even set foot in the Kingdom.<\/p>\n<p style=\"background-color: #0f0f0f;color: #ffffff;padding: 15px;border-left: 5px solid #ef4444;border-radius: 4px;font-size: 16px;margin-bottom: 25px;line-height: 1.8\"><strong style=\"color: #f97316\">\u26a0\ufe0f THREAT INTELLIGENCE ADVISORY:<\/strong><br \/>\nFinancial threat actors are actively spoofing official Saudi tourism and Hajj registration portals (like Nusuk) to execute credential harvesting and financial fraud. The Saudi National Cybersecurity Authority (NCA) has activated emergency cyber drills to defend critical travel infrastructure.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/upload-1785335421-0.png\" alt=\"Hajj 2026 Scams\" style=\"max-width:100%;height:auto\" \/ loading=\"eager\" fetchpriority=\"high\"><\/p>\n<table style=\"width: 100%;border-collapse: collapse;margin-bottom: 25px\">\n<thead>\n<tr style=\"background-color: #1a1a1a;color: #fff\">\n<th style=\"padding: 10px;border: 1px solid #333;text-align: left\">Claim \/ Threat Activity<\/th>\n<th style=\"padding: 10px;border: 1px solid #333;text-align: left\">Source<\/th>\n<th style=\"padding: 10px;border: 1px solid #333;text-align: left\">Status<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 10px;border: 1px solid #333\">Proliferation of fake Hajj permits and unauthorized travel packages via WhatsApp and Telegram<\/td>\n<td style=\"padding: 10px;border: 1px solid #333\">Ministry of Hajj and Umrah<\/td>\n<td style=\"padding: 10px;border: 1px solid #333;color: #facc15\">Verified (Ongoing campaign)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 10px;border: 1px solid #333\">Spoofed versions of the official \u2018Nusuk\u2019 platform designed to steal banking credentials<\/td>\n<td style=\"padding: 10px;border: 1px solid #333\">NCA Security Alerts<\/td>\n<td style=\"padding: 10px;border: 1px solid #333;color: #facc15\">Verified<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 10px;border: 1px solid #333\">Critical disruption of Saudi airport OT systems by scammers<\/td>\n<td style=\"padding: 10px;border: 1px solid #333\">Social Media Rumors<\/td>\n<td style=\"padding: 10px;border: 1px solid #333;color: #ef4444\">Disputed (No evidence of OT breach)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2  style=\"color: #facc15;\">Table of Contents<\/h2>\n<ul>\n<li><a href=\"#context\">Context \/ Motivation: A Lucrative Season<\/a><\/li>\n<li><a href=\"#technical\">Technical Analysis (TTPs)<\/a><\/li>\n<li><a href=\"#impact\">Impact Assessment<\/a><\/li>\n<li><a href=\"#mitigation\">Mitigation Recommendations<\/a><\/li>\n<\/ul>\n<h2 id=\"context\"  style=\"color: #facc15;\">Context \/ Motivation: A Lucrative Season<\/h2>\n<p>The motivation behind the <strong style=\"color: #f97316\">Hajj 2026 Scams<\/strong> is purely financial. The annual pilgrimage attracts millions of global travelers, many of whom are elderly or not digitally native. Scammers exploit the high demand and limited quotas for Hajj visas by offering \u201cexpedited\u201d or \u201cVIP\u201d services through unofficial channels. By leveraging the emotional urgency of the pilgrimage, threat actors bypass typical critical thinking filters, convincing victims to wire money or input their Personally Identifiable Information (PII) into fraudulent domains.<\/p>\n<h2 id=\"technical\"  style=\"color: #facc15;\">Technical Analysis (TTPs)<\/h2>\n<p>The attackers rely heavily on AI-enabled social engineering and credential harvesting. Tactics include purchasing sponsored ads on search engines and social media platforms that direct victims to highly realistic, typosquatted versions of the official Saudi <em>Nusuk<\/em> platform. Once on the fake site, users are prompted to upload passport copies, national IDs, and input credit card details. To counter this, the Saudi National Cybersecurity Authority (NCA) has launched a massive <em>Cybersecurity Enhancement Program<\/em>. Through the centralized <em>Haseen<\/em> portal, the NCA is orchestrating round-the-clock threat hunting and recently executed large-scale cyber drills involving over 300 national entities to simulate incident response against these exact TTPs.<\/p>\n<h2 id=\"impact\"  style=\"color: #facc15;\">Impact Assessment<\/h2>\n<p>The severity of this threat is <strong style=\"color: #f97316\">High<\/strong> for individuals and <strong style=\"color: #f97316\">Medium<\/strong> for institutional infrastructure. While the core Saudi government servers remain heavily fortified, the real damage occurs at the endpoint-the user. Victims face severe financial losses and identity theft, often only realizing they have been scammed when they are turned away at airports or border checkpoints with invalid visas. The reputation of legitimate travel agencies is also collaterally damaged.<\/p>\n<h2 id=\"mitigation\"  style=\"color: #facc15;\">Mitigation Recommendations<\/h2>\n<ol>\n<li><strong style=\"color: #f97316\">Strict Domain Verification:<\/strong> Pilgrims and agencies must ensure all registrations and payments are conducted exclusively through the official <code>nusuk.sa<\/code> domain or government-authorized partners.<\/li>\n<li><strong style=\"color: #f97316\">Endpoint Anti-Phishing:<\/strong> Travel agencies should deploy DNS-level filtering and anti-phishing training to prevent staff from inadvertently processing fake permits or falling for spoofed B2B communications.<\/li>\n<li><strong style=\"color: #f97316\">Zero Trust Payments:<\/strong> Never transfer funds to personal bank accounts, crypto wallets, or unverified third-party gateways promising \u201cbackdoor\u201d Hajj approvals.<\/li>\n<\/ol>\n<p>For ongoing tracking of regional cyber threats targeting the Middle East, keep monitoring <a href=\"https:\/\/cyberasia.io\/\">CyberAsia<\/a>.<\/p>\n<hr style=\"border: 1px solid #333;margin: 40px 0\">\n<div style=\"padding: 20px;border: 1px solid #facc15;border-radius: 4px\">\n<h3 style=\"color: #facc15;margin-top: 0;font-family: 'Fira Code', monospace\">> subscribe_to_intel<\/h3>\n<p style=\"color: #9ca3af;font-size: 0.95rem\">Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. <a href=\"https:\/\/cyberasia.io\/privacy-policy\/\" style=\"color: #9ca3af;text-decoration: underline\">Privacy Policy<\/a>.<\/p>\n<div style=\"display: flex;gap: 10px;margin-top: 15px;flex-wrap: wrap\">\n<p>        <button type=\"button\" style=\"padding: 10px 20px;background: #facc15;color: #000;border: none;font-weight: bold;cursor: pointer;font-family: 'Fira Code', monospace\">> initialize<\/button>\n    <\/div>\n<\/div>\n<div style=\"margin-top: 20px;font-size: 0.95rem;font-family: 'Fira Code', monospace\">\n    <span style=\"color: #9ca3af\">> establish_connection: <\/span><br \/>\n    <a href=\"https:\/\/twitter.com\/cyberasia_io\" target=\"_blank\" style=\"color: #facc15;text-decoration: none;margin-right: 15px\" rel=\"noopener\">[X\/Twitter]<\/a><br \/>\n    <a href=\"https:\/\/t.me\/cyberasiaio\" target=\"_blank\" style=\"color: #facc15;text-decoration: none;margin-right: 15px\">[Telegram]<\/a>\n<\/div>\n<h3>Mitigation &#038; Prevention Strategies<\/h3>\n<p>Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:<\/p>\n<ul>\n<li><strong>Patch Management:<\/strong> Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.<\/li>\n<li><strong>Isolate OT Networks:<\/strong> SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.<\/li>\n<li><strong>Continuous Monitoring:<\/strong> Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.<\/li>\n<\/ul>\n<hr>\n","protected":false},"excerpt":{"rendered":"<p>For millions of Muslims, the pilgrimage to Mecca is a lifelong dream. But for organized cybercriminal syndicates, it is a highly lucrative data harvesting season. Throughout 2026, Saudi authorities have been battling an unprecedented wave of digital fraud, where scammers deploy sophisticated social engineering and spoofed portals to siphon millions from unsuspecting pilgrims before they [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":500,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[362,361,48,360,343,146],"threat_actors":[],"class_list":["post-501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-intelligence","tag-credential-harvesting","tag-nca","tag-phishing","tag-saudi-arabia","tag-scam","tag-social-engineering"],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/comments?post=501"}],"version-history":[{"count":6,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/501\/revisions"}],"predecessor-version":[{"id":3864,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/501\/revisions\/3864"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media\/500"}],"wp:attachment":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media?parent=501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/categories?post=501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/tags?post=501"},{"taxonomy":"threat_actor","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors?post=501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}