Skip to content Skip to Search
Skip navigation

Middle East hit by wave of brand impersonation scams

International Holding Company said in a disclosure to the Abu Dhabi Securities Exchange that scammers are using the company's name for fraudulent investment opportunities Reuters
The financial markets in Abu Dhabi and Dubai are expecting increased institutional investments in the upcoming months
  • Fake websites and spoof emails
  • Logos and employee names used
  • Job seekers also targeted

Cybersecurity experts in the Middle East are warning of a rise in brand impersonation attacks which persuade unsuspecting consumers to part with sensitive information. 

International Holding Company, a global investor based in Abu Dhabi, said in a disclosure to the Abu Dhabi Securities Exchange last week that scammers are using the company’s name and logo and employees’ names “to advertise fraudulent investment opportunities and tenders online”.

In return, investors are asked to provide their personal and business information, and credit card and bank details to pay supposed tender fees to proceed with the investment.

Brand impersonation involves the mimicking of known brands where hackers exploit the trust of users to extract sensitive information through fake websites, spoofed emails or deceptive transactions.

Apart from the victims, impersonation also tarnishes the reputation and credibility of the targeted company. 

Russian cybersecurity company Kaspersky said its anti-phishing system foiled 500 million attempts to access fraudulent websites globally in 2022, underlining the pervasive nature of the threat.

Emad Haffar, a senior analyst at Kaspersky, told AGBI that research measured a 77 percent increase in the UAE in phishing detections during the second quarter of 2023 compared to the first.

LinkedIn, a professional networking platform, has not been immune to brand impersonation scams. 

Earlier this year, cybercriminals, posing as HR managers from high-end fashion brands, promised dream jobs for victims on the platform, and lured them into downloading fraudulent files. 

Kaspersky experts identified a malware named Ducktail, designed to steal user logins and passwords. The scam is not exclusive to the UAE, having been detected in Turkey, Iraq and Lebanon. 

During the 2022 Fifa World Cup in Qatar, scammers exploited the event’s popularity by creating phishing websites, apps and social media accounts masquerading as official sources. 

Operating predominantly in the Middle East, the criminals offered fake match tickets and fan merchandise, preying on users’ eagerness to participate in the festivities. The ruse involved collecting detailed personal information through fraudulent forms.

In Saudi Arabia last year, cybercriminals impersonated a leading recruitment firm, creating over 1,000 fake versions of its websites. 

Scammers targeted individuals seeking domestic staff and requested a nominal processing fee, apparently for hiring. Though the transaction never occurred, it provided scammers access to victims’ bank details. 

“Protecting a brand is hard, and repairing a brand that’s been damaged is even harder,” said Mimecast, an American-UK cybersecurity firm, in its State of the Email Security Report 2023.

Register now: It’s easy and free

AGBI registered members can access even more of our unique analysis and perspective on business and economics in the Middle East.

Why sign uP

  • Exclusive weekly email from our editor-in-chief
  • Personalised weekly emails for your preferred industry sectors
  • Read and download our insight packed white papers
  • Access to our mobile app
  • Prioritised access to live events

I’ll register later