Advisory ID: NCC-CSIRT-2026-032
Summary:
The Nigerian Communications Commission Computer Security Incident Response Team (NCC-CSIRT) has identified a phishing campaign leveraging a fraudulent promotional webpage hosted on https://ibaidad.com/pella-jarvis-wedding. The campaign falsely promises 10GB of free mobile data and ₦5,000 airtime in exchange for users providing their mobile phone numbers and sharing the malicious link through WhatsApp. The campaign employs social engineering techniques to harvest user information and rapidly propagate itself through messaging platforms. Telecommunications Service Providers are advised to implement appropriate security measures to protect subscribers and mitigate the spread of the malicious campaign.
Damage: High
Probability: High
Description:
NCC-CSIRT has observed a phishing campaign hosted on the domain ibaidad.com, specifically the webpage:
https://ibaidad.com/pella-jarvis-wedding
The webpage falsely advertises a promotional offer claiming that users can receive 10GB of free mobile data and ₦5,000 airtime in celebration of an alleged wedding event.
Visitors are instructed to enter their mobile phone numbers before being directed to share the webpage with multiple WhatsApp contacts or groups to qualify for the purported reward. Such behaviour is consistent with social engineering campaigns designed to harvest user information while increasing the campaign's distribution through trusted contacts.
Independent threat intelligence sources have classified the domain as suspicious and associated with phishing activities. Although there is currently no evidence that the campaign exploits software vulnerabilities in mobile operating systems or telecommunications infrastructure, it poses a significant risk to subscribers through deception and manipulation.
Given the widespread use of mobile messaging platforms in Nigeria, Telecommunications Service Providers are encouraged to strengthen monitoring, web filtering, subscriber awareness, and threat intelligence activities to minimise the impact of this campaign.
Consequences:
Successful influence operations may result in:
- Collection of subscribers' mobile phone numbers and other personal information.
- Increased exposure of subscribers to phishing, fraud, and identity theft.
- Rapid propagation of malicious links through WhatsApp and other messaging platforms.
- Financial losses arising from subsequent scam campaigns.
- Reduced customer trust in legitimate promotional campaigns.
- Increased security and customer support incidents for Telecommunications Service Providers.
Threat Types:
- Phishing
- Social Engineering
- Fraudulent Promotional Campaign
- Credential and Personal Information Harvesting
- Mobile Messaging Abuse
- Malicious URL Distribution
Solutions/Mitigations:
NCC-CSIRT strongly recommends the following:
- Block the identified URL and associated domain through DNS filtering, secure web gateways, and other available network security controls.
- Monitor network traffic for access to the identified indicators and similar phishing infrastructure.
- Disseminate this advisory to relevant cybersecurity, fraud management, and network operations personnel.
- Notify subscribers through official communication channels about the ongoing phishing campaign.
- Advise subscribers not to provide personal information in response to unsolicited promotional offers or requests received via websites or messaging applications.
- Encourage subscribers to verify promotional offers only through official Telecommunications Service Provider channels.
References:
https://ibaidad.com/pella-jarvis-wedding
https://gridinsoft.com/online-virus-scanner/url/ibaidad-com
https://any.run/report/e48bd9676bfdb8c1121e7d4203171c8c21917f66057d806c1a323fe4534ce454/d78c7e83-3707-4959-a2b9-464e556dade4