Group-IB, a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, has unveiled a critical investigation revealing how organized cybercriminals are exploiting legitimate payment infrastructure across the Gulf Cooperation Council (GCC) region. Image courtesy: Group-IB
Scammers use stolen credit cards to pay real public bills at a discount, tricking bank security while collecting clean payments
Press Release
DUBAI, UAE — Group-IB, a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, has unveiled a critical investigation revealing how organized cybercriminals are exploiting legitimate payment infrastructure across the Gulf Cooperation Council (GCC) region.
In a novel scheme, scammers are using stolen credit cards to pay real government bills and fines for people at a discount, secretly turning routine bill payments into a way to cash out stolen money, while bypassing bank security.
Between October 2025 and August 2026, Group-IB’s Fraud Protection team detected approximately 300 related incidents across several major retail banks. In a validated subset of 80 compromised cards spanning three government institutions, confirmed losses reached USD 2.01 million. The scheme illustrates the significant financial impact that can result from the abuse of legitimate payment infrastructure.
A Shift in Fraud Mechanics
Strict banking rules across the GCC now require 3D Secure (3DS), the standard extra security verification step which requires online card payments to be confirmed with a one-time passcode or bank app approval. While these measures have shut down basic fraud tactics, like digital wallet top-ups, cybercriminals have created multi-step schemes to work around these protections.
This is where attackers aren’t breaking security checks, they are passing them. In every confirmed case examined by Group-IB, fraudulent transactions passed valid 3DS authentication. By taking over victims’ phone numbers and banking accounts, fraudsters approved the security prompts themselves, leaving bank systems with no visible signs of fraud.
The operation spans three distinct functional layers:
- Phishing (Acquisition Layer): Promoted via verified Google Search ads with GCC geo-targeting, over 400 phishing resources across 10 disguise patterns clone government portals and insurance services. Victims surrender personal data, card numbers, and approve telecommunication prompts that authorize fraudulent eSIM swaps.
- Account Takeover (Jordan Checker Group): Using the hijacked eSIM number to intercept OTPs and masking location via GPS spoofing, attackers take over online banking accounts, raise transfer limits, and approve 3DS challenges in-app. Telemetry linked 90% of these takeovers to new iOS device fingerprints originating from a geohash cluster in Ramtha, Jordan.
- Bill-Discount Cash-Out Market (CIVIC DRAIN): Operating across specialized Telegram channels, fraudsters recruit members of the public by offering to settle legitimate traffic fines, utility bills, and legal charges at discounts between 50% and 80%. The cybercriminals pay the full bill on official government portals using stolen card details and collect clean discounted funds (via cryptocurrency or local bank transfers) from the customer.
Because the payment goes directly to a trusted government entity on behalf of a real citizen, single-channel bank monitoring rarely flags the transaction as suspicious.
The Case for Cyber Fraud Fusion (CFF)
Single-channel bank monitoring views these transactions as routine payments to official billers, missing the broader threat. Group-IB exposed the campaign through Cyber Fraud Fusion (CFF), connecting insights across web, mobile, and financial systems. By uniting Digital Risk Protection (DRP) for phishing takedowns, Threat Intelligence (TI) for mapping Telegram markets and crypto exit rails, Fraud Protection for cross-referencing 3DS prompts against live mobile risks (such as eSIM changes and GPS spoofing), and Investigations to trace financial flows, CFF exposed threat activity that siloed defenses missed.
Key Recommendations for Ecosystem Defense
Group-IB outlines key operational steps to mitigate multi-stage fraud:
- For Financial Institutions: Treat account-recovery flows relying on card PIN and SMS OTP as high-risk. Re-score high-value 3DS payments to government billers when preceded by recent device registrations, eSIM changes, or limit increases.
- For Detection Teams: Implement cross-channel correlation linking web, mobile, and payment telemetry under a single identity. Treat government portals as potential cash-out routes during active takeover indicators.
- For Government & Portal Operators: Implement risk checks for rapid repeat or high-value settlements and establish dedicated channels for CERTs and banks to report suspected fraudulent bill clearing.
- For the Public: The scheme relies on participants from the public seeking discounted settlements. Access government and insurance services only through official apps or bookmarks, not sponsored search results. A paid ad is not a trust signal. Be aware that a steep discount on paying a government bill through an unknown third party may be a fraud or money-laundering lure, which can carry financial or legal consequences.
Disclaimer: The contents of this press release was provided from an external third party provider. This website is not responsible for, and does not control, such external content. This content is provided on an “as is” and “as available” basis and has not been edited in any way. Neither this website nor our affiliates guarantee the accuracy of or endorse the views or opinions expressed in this press release.
© ZAWYA 2026
Click Here For The Original Source.
