Fraudsters Impersonate Local Organisations to Lure Victims to Suspicious Links

Customers of telecommunications companies have asserted that their senders take the form of official entities, such as Emirates Post, Etisalat and du, to force users to open them, exposing them to fraud.

A technical expert called for attention to website addresses: government websites should end with b.gov.ae or.ae for companies in the United Arab Emirates, like Emirates Post, which is currently spreading fraudulent messages in its name, warning against sites that don't end with those names.

He called for banning the sender and deleting the suspicious message, which represents bait, or bait for scammers.

And in detail, Emarat Al Youm spotted emails sent to customers, one of which said, "We're the UAE mail. We cannot connect your shipment, because the address of the shipment you provided does not match the postal code, please update through the following link".

And another message says, "Emirates mail… Your mailman accidentally lost your shipment. Please fill in your details via the link to update".

The third message was, "We tried to connect your shipment, please confirm your data or the shipment will be returned".

As stated in another message: "Your shipping address doesn't include the home number, so it can't be connected, please update the data on the link", and the link guarantees an email address that contains a grammatical error. It came in another message: "Balance your reward points from Du… Point ends today, so it's important to log in to get your prize".

Princess Aziz (Moffah) said she had recently received several emails with the name Emirates Post, from figures outside the country, trying to convince her that there was a problem with her own firing.

She said, "I suspected the whole thing was a scam, so I decided not to open the links sent to me, and then I verified that they were fraudulent".

Ibrahim Khaled (a doctor) confirmed that his phone detected a number of messages claiming he had shipments with UAE mail facing problems in sending them, either because of the address or due to the inability of the postman to access them, but he doubted the links sent to the messages, because they contained language errors, so that the letter "Emirates" in the word "Emirates" and other links to unknown sites were missing, and after referring to the owners of experience and expertise, he knew they were sites aimed at bank account theft.

Mohamed Mr. Engineer said he had received annoying messages over the past few days, asking for access to certain links.

He continued: "After logging into the link, I was asked for data, such as a bank account number, and then I realized they were aiming to steal my bank account, so I decided to leave the site immediately before submitting any data".

For his part, information technology expert Sami A Nour reported that "phishing is a form of fraud, and fraudsters use random messages, asking recipients to access a link, which is the fish the bait catches".

He explained that "scammers have resorted to this method because it's easier and faster, because phone fraud retargeting is no longer useful in the current period, and it takes a long time, unlike text messages".

He added: "There are a number of signs that non-professionals can detect in these phishing and fraudulent messages, firstly the language of the racket, the scammers are not residents of the country – even if they have previously lived there – and the messages are written in a weak format, in Arabic or English, because they are not the native language of the scammers".

He continued: "The other thing is to send from an external number, the licensed entities within the state are called letters for example (name of the bank), (name of the entity), and although the ad starts with the sender's name with AD, fraudulent messages are often made up of phone numbers, whether from within the state or from outside". Sami A Nour pointed out that "the signs also include non-connectivity, so if your phone number is from (communications) and you received messages from (Do), make sure that the message is fraudulent, and vice versa, and if you are a resident of the Northern Emirates, for example, and you received a message from electricity, water from Dubai, or Sharjah, then the message is definitely fraudulent". He called for careful attention to website addresses, and checking to see if they're addresses you know, government websites should end up with b.gov.ae or.ae for companies in the UAE, like Emirates Post which is currently spreading fraudulent messages in its name, warning against sites that don't end with those names.

He explained that in the event of encountering a fraudulent message, a photo or copies of the message should be taken and reported to the official authorities, then the sender must be blocked and the message deleted from the phone, with the need not to access or interact with anonymous links, and the concerned party can be contacted and questioned if the person has a list of messages sent to him or her. For his part, legal adviser, Dr. Mohsen al-Khabani, said: "Criminal gangs that take technology out of space for their fraudulent operations have emerged, hunting through emails received by the recipient, urging him to take urgent action, and usually carrying logos of service organizations, known destinations".

He added: "By addressing the legal side of this issue, it is clear that the UAE legislator is keen to update the laws and legislation on combating cybercrime, even if criminal gangs invented methods of cyber hacking and cybercrime; however, the law still prevents strict penalties in this regard. Taking a false name or misrepresentation for the purpose of seizing money and personal data, and the penalties in this regard are preventable".

Al Khabani explained that Article 40 of Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrime provides that anyone who unlawfully obtains movable property, a benefit, a document or a signature on such a document for themselves or another person faces at least one year in prison and a fine of between AED 250,000 and AED 1 million, or either penalty. By using any means of fraud, taking a false name or impersonating a false identity through an information network, electronic information system or other information technology medium.

He continued: "Although these laws, with which the UAE legislature decides deterrent penalties to ensure a secure cyber environment to ensure the use of these technologies in a positive way, it is necessary for the prevention of these crimes that there be a precautionary role from those who receive suspicious messages, by verifying the official email of the company or entity, From the links before clicking on them by moving the pointer over the link to see the actual address to which it will be transferred and whether it matches the official website of the sender".

I'm going to do this. The Good Witch:

• Imprisonment and a fine is a penalty for seizing himself or others of money transferred using methods of electronic fraud.

Sami A Nour:

• External numbers, the use of slang phrases and linguistic errors are the most prominent signs of fraudulent messages.

Source: Emarat Al Youm