Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures
Group-IB ties the campaign to a broader fraud network using cloned political figures, fake government programs and browser-push alerts to harvest credentials and payment data.

A sprawling fraud operation is hitting Facebook users across the Middle East and North Africa with imposter pages dressed up as politicians, telecom carriers and government welfare schemes, according to research from Group-IB.
The lures are mundane and effective. Free mobile data bundles. One-off cash payouts framed as state compensation. Subsidy enrollments timed to local cost-of-living pressures.
Victims who bite are funneled through redirect chains to phishing pages that scrape Facebook credentials, card details, or both. Some flows end on browser-notification prompts that hijack the victim's device for follow-on scam delivery long after the initial click.
Group-IB's analysts attribute the activity to the same scam-as-a-service ecosystem previously catalogued under the "Sniper Dz" banner, an Arabic-speaking fraud crew that has run phishing kits and ready-made templates available to lower-tier operators. Researchers have tracked the operation across Telegram channels where panels, hosting, and pre-built landing pages are traded openly. The crew profits on volume, not sophistication.
Targeted countries include Egypt, Algeria, Morocco, Tunisia and several Gulf states, with lures localized down to dialect and carrier branding. Impersonated entities span national telcos, ministries handling social assistance, and well-known regional banks. In several cases the fake pages carry follower counts and post histories designed to clear casual sniff tests.
The abuse vectors are not new. What's notable is the scale and the operational discipline. Pages are spun up, burned through paid promotion, and replaced as Meta's enforcement catches up. The cycle repeats in hours.
Credential reuse is the second-order risk. MENA users frequently share passwords across Facebook, webmail, and banking portals, and stolen Facebook logins routinely surface in account-takeover attempts against payment apps and crypto exchanges in the weeks that follow.
Group-IB did not publish a victim count, and neither Meta nor any of the impersonated organizations have disclosed financial losses tied to the campaign. No arrests have been reported. Several of the spoofed brands have issued public warnings on their official channels telling customers they do not run cash giveaways through Facebook.
Defensive guidance from the researchers is brief: treat any Facebook post offering free data, government cash, or subsidy enrollment as hostile by default; verify through the organization's own domain; and revoke browser-notification permissions granted to unfamiliar sites.
The broader pattern matters for platform-trust teams. Scam-as-a-service kits have collapsed the skill floor for impersonation fraud, and regions with high Facebook penetration and lighter consumer-protection enforcement remain the most exposed. Sniper Dz, by all available indicators, is still hiring.


