Skip to content

Dubai SIM-Swap Scam Exploiting Regional Tensions

alt text

SIM-Swap Fraud Social Engineering Identity Abuse Crisis-Themed Scam

Overview

Scammers targeted Dubai residents by impersonating officials from a fictitious “Dubai Crisis Management” department falsely presented as linked to Dubai Police. Attackers sought sensitive personal and digital identity data that could later be used to perform SIM-swap fraud.

The activity was reported shortly after Iranian missile and drone activity affecting the UAE information environment. Threat actors appear to be exploiting fear and uncertainty during a regional crisis to increase social-engineering success.

Technical Specifications

Attribute Details
Incident Type Social-engineering driven SIM-swap fraud campaign
Target Region Dubai / UAE residents
Primary Pretext Fake “Dubai Crisis Management” authority calls/messages
Requested Data UAE Pass credentials, Emirates ID details
Fraud Objective Socially engineer telecom operators to transfer victim number to attacker SIM
Authentication Impact Interception of SMS OTP and 2FA verification codes
Likely Follow-on Abuse Banking account access, identity theft, broader account takeover

Affected Products

  • Mobile subscriber accounts vulnerable to SIM reassignment fraud
  • UAE Pass / digital identity-linked services exposed through credential disclosure
  • Banking and online services relying on SMS-based OTP/2FA
  • Residents receiving unsolicited calls/messages from impersonated “official” actors
  • Status: Active social-engineering risk; public warnings issued

Technical Details

Social Engineering Modus Operandi

  • Attackers initiate unsolicited calls or messages while posing as crisis-management or police-linked authorities.
  • Communication uses urgency and fear related to regional security developments.
  • Victims are pressured to disclose identity and authentication-linked details.

Data Abuse Path

  • UAE Pass credentials and Emirates ID details are targeted as high-value identity signals.
  • Collected data can be reused to pass operator verification checks.
  • Attackers then attempt SIM transfer requests through carrier support channels.

SIM-Swap Outcome

  • Victim phone number is moved to attacker-controlled SIM.
  • SMS-based OTP and verification messages are redirected to attacker device.
  • Enables unauthorized access to financial and high-value digital services.

Attack Scenario

  1. Reconnaissance:

    • Threat actor acquires basic resident contact data (phone numbers and profiles).
  2. Pretexting Call/Message:

    • Attacker impersonates crisis-response or law-enforcement authority.
  3. Credential/Identity Harvesting:

    • Victim is convinced to share UAE Pass credentials and/or Emirates ID details.
  4. Carrier Social Engineering:

    • Attacker submits fraudulent SIM transfer request using harvested identity data.
  5. Account Takeover and Monetization:

    • Attacker intercepts OTP/2FA messages, accesses banking/services, and performs fraud.

Impact Assessment

  • Unauthorized modification of subscriber SIM ownership and account recovery channels
  • Fraudulent transactions and account setting changes in dependent services
  • Potential downstream identity misuse across linked digital platforms
  • Exposure of personal identity data (UAE Pass / Emirates ID-linked details)
  • Interception of private SMS OTP and verification traffic
  • Elevated risk of further credential theft and account compromise
  • Victims may lose access to their mobile number and critical services temporarily
  • Service lockouts and account recovery disruption during active fraud response
  • Operational strain on telecom and financial support channels

Mitigation Strategies

Official Guidance (Dubai Authorities)

  • Do not share personal, banking, or verification information with unknown callers/texts
  • Authorities do not request confidential data or OTP codes by phone/SMS
  • Report suspicious contacts through official channels such as 901 or Dubai eCrime platform
  • Independently verify any claimed official communication via known official numbers/channels

Account Security Hardening

  • Request SIM-lock PIN controls with mobile carriers where available
  • Prefer app-based authenticator 2FA instead of SMS-based 2FA when supported
  • Set stricter recovery controls and account alerts on banking/critical services

Awareness and Response

  • Conduct user awareness messaging on crisis-themed social engineering tactics
  • Train support teams to recognize SIM-swap indicators and escalation triggers
  • Monitor for unusual SIM replacement requests and rapid post-swap account activity

Resources and References


Last Updated: March 3, 2026