Home » Emerging Technologies » Cyber Security » GCC Payment Fraud: Stolen Cards Used to Pay Government Bills
News Desk -

Share

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent and fight digital crime, has unveiled an investigation into GCC payment fraud. It shows how organized cybercriminals are exploiting legitimate payment infrastructure across the Gulf Cooperation Council (GCC) region.

In a novel scheme, scammers use stolen credit cards to pay real government bills and fines for people at a discount. This secretly turns routine bill payments into a way to cash out stolen money while bypassing bank security.

Between October 2025 and August 2026, Group-IB’s Fraud Protection team detected approximately 300 related incidents across several major retail banks. In a validated subset of 80 compromised cards spanning three government institutions, confirmed losses reached USD 2.01 million. The scheme shows the significant financial impact that can result from abusing legitimate payment infrastructure.

Strict banking rules across the GCC now require 3D Secure (3DS). This is the standard extra verification step that confirms online card payments with a one-time passcode or bank app approval. These measures have shut down basic tactics, such as digital wallet top-ups. However, cybercriminals have built multi-step schemes to work around them.

In this case, attackers are not breaking security checks. They are passing them. In every confirmed case Group-IB examined, fraudulent transactions passed valid 3DS authentication. Fraudsters took over victims’ phone numbers and banking accounts. They then approved the security prompts themselves, leaving bank systems with no visible signs of fraud.

The operation spans three functional layers. The first is phishing, which acts as the acquisition layer. Promoted through verified Google Search ads with GCC geo-targeting, over 400 phishing resources across 10 disguise patterns clone government portals and insurance services. Victims surrender personal data and card numbers. They also approve telecommunication prompts that authorize fraudulent eSIM swaps.

The second layer is account takeover, linked to a group Group-IB calls the Jordan Checker Group. Using the hijacked eSIM number, attackers intercept OTPs and mask their location through GPS spoofing. They then take over online banking accounts, raise transfer limits and approve 3DS challenges in the app. Telemetry linked 90% of these takeovers to new iOS device fingerprints. These originated from a geohash cluster in Ramtha, Jordan.

The third layer is the bill-discount cash-out market, which Group-IB calls CIVIC DRAIN. It operates across specialized Telegram channels. Fraudsters recruit members of the public by offering to settle traffic fines, utility bills and legal charges at discounts between 50% and 80%. The cybercriminals pay the full bill on official government portals using stolen card details. They then collect the discounted funds from the customer, via cryptocurrency or local bank transfers.

Because the payment goes directly to a trusted government entity on behalf of a real citizen, single-channel bank monitoring rarely flags it. Such systems view these transactions as routine payments to official billers. As a result, they miss the broader threat.

Group-IB exposed the campaign through Cyber Fraud Fusion (CFF), which connects insights across web, mobile and financial systems. CFF combines four capabilities. Digital Risk Protection (DRP) handles phishing takedowns. Threat Intelligence (TI) maps Telegram markets and crypto exit rails. Fraud Protection cross-references 3DS prompts against live mobile risks, such as eSIM changes and GPS spoofing. Investigations traces financial flows. Together, these exposed threat activity that siloed defenses missed.

Group-IB also outlined operational steps to mitigate multi-stage fraud. For financial institutions, it advises treating account-recovery flows that rely on card PIN and SMS OTP as high-risk. It also recommends re-scoring high-value 3DS payments to government billers when they follow recent device registrations, eSIM changes or limit increases.

For detection teams, Group-IB recommends cross-channel correlation that links web, mobile and payment telemetry under a single identity. Teams should also treat government portals as potential cash-out routes during active takeover indicators.

For government and portal operators, the company suggests risk checks for rapid repeat or high-value settlements. It also advises dedicated channels for CERTs and banks to report suspected fraudulent bill clearing.

For the public, the scheme relies on people seeking discounted settlements. Group-IB advises accessing government and insurance services only through official apps or bookmarks, not sponsored search results. A paid ad is not a trust signal. A steep discount on a government bill paid through an unknown third party may be a fraud or money-laundering lure. It can carry financial or legal consequences.

The findings show how GCC payment fraud can pass standard checks and look like routine activity. Group-IB’s recommendations point to shared, cross-channel visibility as a practical way to detect it.