Are you or your company wanted internationally?Check Now β†’
Wirestork logo
Services
Share
Homeβ€ΊBlogβ€ΊSaudi Law
Saudi LawLegal Q&A

How Can You Protect Yourself From Nafath and Absher Phishing Scams?

JW
James Whitfield
International Legal Analyst
|
15 July 2026Β·2 min read
phishing SMS impersonating the Absher platform beside a shield representing account protection in Saudi Arabia

Protecting yourself from Nafath and Absher phishing scams comes down to one core habit: only ever access these services through their official website or official app, and never share your username, password, or one-time confirmation code with anyone. Saudi Arabia's Ministry of Interior has repeatedly warned of SMS and email campaigns impersonating Absher to steal login credentials, and the same caution applies to Nafath, the Kingdom's unified digital identity platform.

AI Summary

This article explains how to protect yourself from phishing scams impersonating Nafath and Absher, Saudi Arabia's official digital identity and government services platforms. It covers how these scams typically operate, the warnings issued by the Ministry of Interior, and the concrete steps to verify official channels, avoid credential theft, and recover if you have already been targeted.

Generated by AI Β· Not legal advice

Key Takeaways
  • Phishing campaigns impersonating Absher and Nafath typically arrive by SMS or email with a link to a fake login page designed to steal usernames, passwords, and one-time passcodes.
  • The only official channels for Absher are the absher.sa website and the official Absher Individuals and Absher Business apps β€” any other link or domain should be treated as suspicious.
  • Never share your username, password, or confirmation code with any person or entity, including anyone claiming to represent a government service or facilitate a transaction on your behalf.
  • If you suspect your credentials were compromised, change your password immediately through the official app or a self-service machine, and report suspicious numbers or messages through official reporting channels.

How These Scams Typically Work

Documented phishing campaigns targeting Absher have followed a consistent pattern: an SMS or email is sent urging the recipient to update their information on the Absher portal, with a link to a fake domain designed to closely resemble the real one. The fake site presents a cloned login page, and after entering credentials, some versions prompt for a one-time passcode sent to the victim's real registered mobile number β€” a technique aimed at bypassing multi-factor authentication on the genuine platform.

Official Warnings From the Ministry of Interior

Absher has issued repeated public warnings stressing that beneficiaries should not respond to any message or communication claiming to facilitate services on their behalf, and should never share personal data, usernames, passwords, or confirmation codes with any entity or individual. The platform has specifically flagged lookalike domains designed to mimic its name, and confirmed that its only official channels are the absher.sa website and the official Absher Individuals and Absher Business mobile apps.

How to Protect Yourself

  • Only access Absher or Nafath through absher.sa, nafath.sa, or their official apps downloaded from recognised app stores β€” never through a link sent by SMS or email
  • Never share your username, password, or one-time confirmation code with any person or organisation, including anyone claiming to help you complete a government transaction
  • Check the domain carefully before entering any login details β€” phishing domains often use small variations or extra words around the real platform name
  • Be sceptical of any message urging urgent action, such as "update your information immediately," since urgency is a common pressure tactic in these campaigns

If You Think You've Already Been Targeted

Change your password immediately through the official Absher app or website, or through a self-service machine if your account may already be compromised. If your registered mobile number may also have been affected, update it through the official channel as well, and monitor your account for any unauthorised activity. Suspicious numbers or messages can be reported through official reporting channels rather than ignored.

Key Takeaways

  • Phishing scams impersonating Absher and Nafath typically arrive by SMS or email with a link to a cloned login page.
  • Only use the official absher.sa or nafath.sa websites and their official apps β€” never a link from an unsolicited message.
  • Never share your username, password, or one-time confirmation code with anyone, regardless of how legitimate the request sounds.
  • If compromised, change your password immediately through official channels and report the suspicious message.

Conclusion

Nafath and Absher phishing scams rely on urgency and convincing imitation, not sophisticated hacking β€” which means the most effective protection is simple discipline: access these platforms only through their official app or website, and never hand over your password or confirmation code to anyone, however official they sound. If something feels off, it almost certainly is, and verifying directly through the official channel costs a few minutes against a potentially serious loss of access to your government and financial accounts.

Questions This Article Answers

JW
About the Author
James Whitfield
International Legal Analyst

James Whitfield is Wirestork international legal analyst focusing on DIFC Courts jurisprudence, ADGM regulations, and common law principles within the UAE financial free zones. He holds an LLM in International Arbitration from the National University of Singapore.