Kuwait's CITRA Processed 172 Cyber Fraud Reports in April as Website Scams Lead
Kuwait's CITRA reported 172 cyber fraud cases handled by the National Cyber Security Center in April 2026, with fraudulent websites accounting for the largest share of complaints at 87 reports.

Cybersecurity analysts reviewing cyber fraud reports on monitoring dashboards in an operations centre
Kuwait's Communications and Information Technology Regulatory Authority (CITRA) has published its April 2026 statistics on cyber fraud, revealing that the National Cyber Security Center processed a total of 172 reports during the month. Fraudulent websites were the most reported category, accounting for 87 of the total complaints filed, according to data reported by Arab Times Kuwait on 20 May 2026.
The figures cover a range of fraud types including fake websites, deceptive text messages, fraudulent voice calls, abuse of digital platforms and other online threats. Citizens and residents are directed to report incidents through the Sahel application using the dedicated Aman service, or through CITRA's official portal, where users can specify the precise nature of the fraud encountered.
Breaking down the April figures
The dominance of fraudulent websites in the April data is consistent with a broader shift in how digital fraud is operationalised across the GCC. Rather than relying on isolated phishing emails or individual message campaigns, organised fraud networks now build and deploy convincing replica websites impersonating government portals, banking institutions, telecom providers and e-commerce platforms. These sites are designed to harvest credentials, payment card data and personal identification information at scale, with minimal ongoing effort once the infrastructure is live.
The remaining 85 reports across April covered deceptive SMS campaigns, fraudulent voice calls including vishing attacks where callers impersonate officials from government departments or financial institutions, abuse of digital platforms including social media and messaging applications, and a residual category of emerging online threats that do not fit established classification types.
The scale of April's figures should be read alongside the longer enforcement context. Earlier CITRA and Interior Ministry data noted that since 2023, a dedicated digital coordination unit has shut down more than 2,300 scam websites and disconnected over 2,200 fraudulent WhatsApp numbers, working in coordination with telecommunications regulators. The April report reflects that this enforcement activity remains ongoing and that the underlying fraud supply is continuing to generate new infrastructure faster than takedown operations can eliminate it.
A pattern consistent with regional trends
Kuwait's April data does not sit in isolation. It reflects a GCC-wide pattern of rising digital fraud that security teams across the region are contending with simultaneously.
Kuwait's Ministry of Interior has previously noted that cyber fraud ranks among the most common crimes processed by its Cybercrime Combating Department, with fake messages and payment links impersonating official institutions and banks among the most frequently reported schemes. The Aman reporting service within the Sahel application represents Kuwait's primary citizen-facing mechanism for capturing this data, and its integration into a widely used government services application has likely contributed to higher reporting volumes compared to earlier years when reporting channels were less accessible.
Regional context reinforces the urgency. In Jordan, INTERPOL's Operation Ramz, the first coordinated cybercrime operation across 13 MENA countries, identified human trafficking victims being coerced into running financial fraud scams, underscoring that the fraud ecosystem extends well beyond individual opportunistic actors into organised criminal networks with significant operational infrastructure.
The UAE has reported parallel trends, with the UAE Cyber Security Council documenting a surge in digital identity threats and phishing campaigns targeting residents through fake government service portals. Saudi Arabia's National Cybersecurity Authority has similarly flagged social engineering and fraudulent platform abuse as among the most active threat categories facing the Kingdom's digital economy. Across all three markets, the operational mechanics are consistent: fraudulent infrastructure is stood up rapidly, exploits a short window of victim exposure before takedown, and is replaced by new infrastructure within days.
In Oman, e-commerce scams have been identified as driving 85 per cent of financial phishing activity, with attackers specifically targeting the country's growing online retail and payment infrastructure. Kuwait's website fraud figures suggest a comparable dynamic is operating in the Kuwaiti market, even if the specific sector targeting differs.
The enterprise compliance dimension
For B2B organisations operating in Kuwait, the CITRA data carries practical compliance implications that go beyond consumer protection. Fraudulent websites and phishing infrastructure are not only a consumer risk. Enterprise employees receiving fake messages impersonating government agencies or financial institutions represent the same attack vectors used in business email compromise and supply chain fraud, which typically carry significantly higher financial and reputational consequences than individual consumer losses.
Kuwait's regulatory direction mirrors that of its GCC neighbours. CITRA's framework and the Interior Ministry's Cybercrime Combating Department together represent a coordinated institutional response to digital fraud that is increasingly moving toward mandatory reporting expectations rather than voluntary disclosure. Organisations that have not yet mapped their incident response plans to Kuwait's specific reporting channels are exposed to a compliance gap that regulators across the region are beginning to scrutinise more actively.
Organisations with operations in the UAE and Saudi Arabia face parallel obligations under their respective national cybersecurity authorities to report incidents and maintain documented security incident response procedures. For enterprises operating across multiple GCC jurisdictions, the practical requirement is a jurisdiction-specific incident response matrix that identifies the relevant reporting authority, applicable timelines and notification thresholds in each country. A single regional policy is no longer sufficient.
Business email compromise remains among the highest-value fraud categories targeting enterprises in the GCC, and its entry vectors are precisely the fake websites and deceptive messaging channels that dominate Kuwait's April statistics. An employee who clicks a convincing replica of a government portal or bank login page on a personal device and reuses credentials across work systems creates an exposure that is operationally indistinguishable from a targeted spear-phishing campaign.
What security teams should act on
The CITRA April data points to three areas where enterprise security teams operating in Kuwait and across the GCC should review their current posture.
Employee awareness programmes should be updated to reflect the specific fraud methods CITRA has identified as most prevalent in April 2026, including fake website impersonation of government and banking institutions, SMS-based deception campaigns and vishing calls impersonating regulatory or law enforcement officials. Generic phishing awareness training that does not reflect current regional threat patterns is materially less effective than training built around the actual schemes being reported to national cyber authorities.
Managed detection and response capabilities should include coverage of fraudulent domain monitoring, specifically the identification of lookalike domains targeting the organisation's brand, supplier relationships or partner institutions. Fraudulent websites targeting enterprise employees frequently impersonate not just banks and government portals but also the organisation's own internal systems, HR platforms and payment approval workflows.
Incident response documentation should explicitly identify CITRA's reporting portal and the Aman service within the Sahel application as the applicable reporting channels for fraud incidents occurring in Kuwait, alongside the relevant contact points at the Interior Ministry's Cybercrime Combating Department. Where passkey and phishing-resistant authentication has not yet been deployed across client-facing and internal access systems, the Kuwait fraud data provides a current, jurisdiction-specific justification for accelerating that rollout.
The 172 reports processed by Kuwait's National Cyber Security Center in April represent the fraction of fraud incidents that were reported through official channels. The actual volume of fraud activity in the market during the same period is considerably higher. For enterprise security planners, the CITRA statistics are a minimum bound on the threat environment, not a ceiling.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.