Syria: Cybersecurity Center Warns of Phishing Links Targeting Exam Results

The Information Security Center at the National Agency for Network Services in Damascus has issued an urgent warning to students and their families regarding a surge in online fraudulent activity. As the country awaits the official announcement of national examination results, malicious actors are increasingly utilizing deceptive links and websites to compromise personal data.
According to the center, these fraudulent campaigns are primarily disseminated through imposter social media accounts. The schemes typically involve directing users to illegitimate platforms that mimic official educational portals. Once there, students or parents are prompted to enter their Google or Gmail account credentials under the guise of verifying their identity or accessing examination scores. The center confirmed that this process is designed to harvest login information, providing attackers with unauthorized access to accounts and any sensitive personal services linked to them.
In response to the threat, the Information Security Center has urged the public to rely exclusively on official, verified channels for the publication of examination results. Officials emphasized that users must exercise caution and avoid clicking on links distributed via unverified groups or suspicious social media pages.
For those who have already entered their account details into a potentially compromised site, the center outlined several immediate protective measures to mitigate potential damage. Users are advised to change their passwords immediately, enable two-step verification across all sensitive accounts, and review the list of devices currently connected to their profiles to identify and terminate any unauthorized access. Furthermore, the agency warned against sharing personal information or credentials with any unverified or suspicious third-party entities.
This advisory comes amid a broader state effort to strengthen digital safety in the country. Earlier this month, on August 8, the Information Security Center issued a separate security alert regarding the emergence of a malicious tool known as ‘Vipere.’ This advanced threat is capable of escalating privileges to the system level while concealing its activity within legitimate processes, effectively disabling event tracking and complicating the task for cybersecurity professionals attempting to detect and neutralize harmful activity. The dual warnings highlight an ongoing commitment by national technology authorities to protect the digital security of the Syrian public as online platforms continue to play a critical role in the dissemination of official academic and administrative information.
