Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures

Group-IB ties the campaign to a broader fraud network using cloned political figures, fake government programs and browser-push alerts to harvest credentials and payment data.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures
Share

Key points

  • Group-IB has identified a Facebook impersonation campaign targeting users across the Middle East and North Africa with fake data bundles, cash payouts and subsidy schemes.
  • Victims are funneled through redirect chains to phishing pages harvesting Facebook credentials and card details.
  • Some flows end on browser-notification prompts that hijack the victim's device for follow-on scam delivery.
  • Group-IB links the activity to the Sniper Dz scam-as-a-service ecosystem, an Arabic-speaking fraud crew selling phishing kits and ready-made templates to lower-tier operators.
  • No victim count, financial losses or arrests have been reported.

What is Sniper Dz and why is it active again?

Sniper Dz is an Arabic-speaking fraud crew that sells phishing kits, hosting and pre-built landing pages through Telegram channels, letting lower-skill operators run impersonation campaigns at scale. The crew profits on volume. Surprising, then, that it's back in the open: our 12 June story reported Operation Ramz had dismantled its storefront and netted its alleged operator across 13 MENA jurisdictions. This campaign suggests the infrastructure, or something that inherited its playbook, survived the sweep.

What do the lures look like?

Fake pages impersonate politicians, national telcos, ministries handling social assistance and regional banks, localized down to dialect and carrier branding. Several carry follower counts and post histories designed to clear casual scrutiny. The hook is always mundane: free mobile data, a one-off cash payout framed as state compensation, or a subsidy enrollment timed to local cost-of-living pressure. Pages are spun up, pushed through paid promotion and replaced as Meta's enforcement catches up. The cycle repeats in hours.

Should you worry about credential theft beyond Facebook?

Yes. Stolen Facebook logins routinely surface in account-takeover attempts against payment apps and crypto exchanges in the weeks after a breach, because users frequently share passwords across Facebook and banking portals. The phishing flow doesn't have to succeed at card-harvesting to do lasting damage; a credential alone is enough. Group-IB published no victim count, and neither Meta nor the impersonated organizations have disclosed losses tied to this campaign.

What can users do?

Group-IB's guidance is brief: treat any Facebook post offering free data, government cash or subsidy enrollment as hostile by default; verify through the organization's own domain; and revoke browser-notification permissions granted to unfamiliar sites.

The broader problem is structural. Scam-as-a-service kits have collapsed the skill floor for impersonation fraud, and regions with high Facebook penetration and lighter consumer-protection enforcement are the most exposed. Several of the spoofed brands have issued public warnings confirming they don't run cash giveaways through Facebook. That's useful, but it reaches exactly the audience least likely to have clicked.

© 2026 Threat Vectr