GCC Scam Alert: Stolen Cards Used to Pay Government Bills

Fraudsters in the GCC are using stolen credit cards to pay genuine government bills before offering customers discounts of 50%-80%, with Group-IB detecting about 300 related incidents between October 2025 and August 2026.
GCC Scam Alert: Stolen Cards Used to Pay Government Bills
Written By:
Somatirtha
Reviewed By:
Manisha Sharma
Published on: 

Residents across the Gulf Cooperation Council (GCC) region are being warned about a sophisticated fraud scheme in which criminals use stolen credit card details to pay genuine government fines, utility bills, and legal charges, then offer to settle those bills at discounts of 50% to 80%. 

The scheme allows fraudsters to turn stolen card funds into cash while making the transactions appear legitimate to banks and payment systems.

Cybersecurity firm Group-IB identified about 300 related incidents between October 2025 and August 2026, highlighting the operation’s scale and risks for residents who accept unusually steep discounts on official payments.

Fraudsters Pay Genuine Government Bills

According to Group-IB, criminals use stolen credit card details to pay genuine government bills and fines through official portals. They then approach customers and offer to settle those bills at a 50% to 80% discount.

They collect the discounted amount through cryptocurrency or local bank transfers. Since the original payment is made directly to a trusted government body on behalf of a genuine customer, the transactions can appear legitimate and are rarely flagged by bank monitoring systems.

Between October 2025 and August 2026, Group-IB's Fraud Protection team detected about 300 related incidents across several major retail banks in the GCC.

In a validated sample involving 80 compromised cards linked to three government institutions, confirmed losses reached USD 2.01 million (about AED 7.4 million).

How Criminals Bypass Fraud Detection

GCC banks use 3D Secure (3DS), which requires customers to confirm online card payments through a one-time passcode or approval through their banking application.

Group-IB said the criminals are not bypassing these security checks. Instead, they are successfully passing them.

In every confirmed case, fraudulent transactions cleared 3DS authentication. The attackers had taken control of victims' phone numbers and bank accounts and could therefore approve security prompts themselves.

Three Stages of Operation

Group-IB identified three key stages in the fraud operation.

First, criminals created more than 400 fake websites using 10 disguise patterns to imitate government portals and insurance services. They promoted these websites through verified Google Search ads targeting users across the GCC.

In the second stage, attackers used hijacked eSIM numbers to intercept one-time passwords and take control of online banking accounts. They also used GPS spoofing, increased transfer limits, and approved 3DS challenges.

Group-IB said 90% of these account takeovers were linked to new iOS device fingerprints from a cluster in Ramtha, Jordan.

The final stage involved specialized Telegram channels used to recruit people by offering discounted settlements of fines, utility bills and legal charges.

Residents Warned Against Steep Discounts

Group-IB has advised residents to access government and insurance services only through official applications or bookmarked websites. It also warned that a website appearing in paid search results does not guarantee it is legitimate.

Residents have also been urged to avoid third parties offering unusually steep discounts on government bills. Such arrangements could be connected to fraud or money laundering and may expose individuals to financial or legal consequences.

Analytics Insight UAE: Top Tech News Website in UAE, Dubai & Middle East
www.analyticsinsight.ae