New scam alert: Think twice before lending your phone
The emergence of this new scam comes against a backdrop of persistently high scam activity in the UAE
30 January, 2026
TT
16
A new scam circulating around is raising concerns among cybersecurity professionals and financial institutions, not because it relies on phishing links or fake emails, but because it exploits something far more basic: physical access to a smartphone.
The scam typically begins with a seemingly harmless request from a stranger asking to borrow a phone for a quick call. Once the device is handed over, the individual quietly activates call and, in some cases, SMS forwarding in the background. From that point on, sensitive information such as one-time passwords (OTPs), bank alerts and account verification codes can be redirected to another number without the owner’s knowledge.
Security specialists warn that the attack is particularly dangerous because it bypasses many of the digital red flags consumers and businesses have been trained to watch for. There are no suspicious links, no spoofed emails and no urgent payment requests. Instead, the compromise happens in seconds, offline, and often goes unnoticed until financial or account damage has already occurred.
The technique relies on built-in phone features rather than malware. Call forwarding can be enabled through device settings or by dialing *21* followed by a destination number and the # key. While SMS forwarding often requires carrier-specific services, call diversion alone can be enough to intercept OTP-based authentication, which remains widely used across banking, fintech and enterprise platforms.
The technique relies on built-in phone features rather than malware. Call forwarding can be enabled through device settings or by dialing *21* followed by a destination number and the # key. While SMS forwarding often requires carrier-specific services, call diversion alone can be enough to intercept OTP-based authentication, which remains widely used across banking, fintech and enterprise platforms.
Telecom experts advise users to immediately dial ##002# if their phone has been out of their possession, as this universal command cancels all call and SMS forwarding. Even without a suspected incident, users are encouraged to dial the code proactively to ensure no forwarding has been activated.
New research
The emergence of this tactic comes against a backdrop of persistently high scam activity in the UAE. New research by the Global Anti-Scam Alliance, conducted in partnership with Trend Micro, shows that seven in ten UAE residents have encountered a scam, with the average individual facing one scam attempt every three days.
According to the study of 1,000 UAE residents, more than half experienced at least one scam in the past year, with affected individuals targeted an average of 2.8 times annually. Shopping scams remain the most common, affecting 70 per cent of victims, followed by investment scams at 67 per cent and unexpected money scams at 66 per cent. One in three residents reported financial losses, although nearly half were able to recover at least part of the money through payment service providers.
The sheer volume of scam encounters is also straining reporting systems. While 79 per cent of victims reported at least one incident, half said no action was taken or they were unsure of the outcome. The most common reason for not reporting was the absence of financial loss, cited by more than half of respondents, highlighting the challenge of capturing early-stage or attempted fraud.
Beyond financial impact, scams are also affecting wellbeing and workplace confidence. Two thirds of victims reported feeling stressed during the experience, while over half said the incident had a moderate to significant impact on their mental wellbeing. For employers, this raises broader concerns around employee distraction, productivity loss and susceptibility to future attacks.
Despite the risks, awareness levels in the UAE remain high. Nearly all respondents said they take steps to verify whether an offer is legitimate, such as checking email domains or searching for external reviews. However, experts warn that as scam tactics become more personalised and increasingly AI-driven, awareness alone is no longer sufficient.
“Online scams have unfortunately become a persistent part of consumers’ digital experiences, not only in the UAE but worldwide,” said Frank Kuo, chief consumer business officer at Trend Micro. “As scammers increasingly employ AI to create more personalised and persuasive scams, a greater focus on prevention has never been more paramount.”
Jorij Abraham, managing director of the Global Anti-Scam Alliance, added that criminals are adapting faster than individual consumers can respond, reinforcing the need for deeper collaboration between platforms, financial institutions and authorities to reduce exposure and limit harm.
For businesses, the rise of low-tech, high-impact scams such as call-forwarding abuse underscores the importance of strengthening multi-factor authentication beyond SMS, reinforcing employee awareness around physical device security, and reviewing incident-response processes that account for offline attack vectors.
As scam methods continue to evolve, the latest threat serves as a reminder that cybersecurity risks are no longer confined to screens and inboxes, but increasingly hinge on everyday human interactions and trust.
Read: Job seekers beware: Dubai Police warn of work visa scams




















