Social Engineering in the UAE: Flower Deliveries

Our team has found an interesting social engineering method that could potentially be used by cyber criminals. This method could be used to trick someone into giving up their home location by pretending to be a flower delivery company that has a shipment ready to be delivered to them by an anonymous person.

Then, the social engineer will text them on WhatsApp and ask for their home location to deliver the gift.

Actual screenshot

This is an actual screenshot our team has obtained from Twitter. It shows the person unhesitatingly replying to the Whatsapp message with their home location. Without asking what company sent him, who the gift is from, or even who he (the delivery guy) is.

Here is a piece of advice: never send your location to strangers before verifying they are legit and actually work for a delivery company. Be careful.

