Group-IB has uncovered a sophisticated fraud operation targeting payment systems across the Gulf Cooperation Council (GCC). The scheme used stolen payment cards to settle genuine government bills, fines and other charges.
According to Group-IB, the operation generated $2.01 million in confirmed fraudulent payments across a validated sample. Meanwhile, investigators identified about 300 related incidents across several major retail banks between October 2025 and August 2026.
The investigation found that criminals combined phishing, eSIM compromise, account takeover and authenticated 3D Secure payments. They then used legitimate government payment portals to convert stolen card access into usable funds.
Fraudsters Exploit Legitimate Government Payments
The scheme begins with phishing campaigns designed to steal personal and financial information. Group-IB identified more than 400 phishing resources using around 10 different disguise patterns.
These sites reportedly impersonated government and insurance services. Moreover, some campaigns appeared through paid search ads targeting users in the GCC.
Victims were persuaded to provide personal information, card details and authentication data. Attackers then used the information to compromise telecommunications accounts and perform eSIM swaps.
Once attackers had control of a victim’s phone number, they could intercept one-time passwords. They could also access online banking accounts and approve additional security checks.
Furthermore, Group-IB found that the confirmed fraudulent transactions passed valid 3D Secure authentication. This allowed the payments to appear legitimate during conventional transaction monitoring.
The criminals subsequently used stolen cards to pay genuine government obligations. These included traffic fines, electricity bills and property or rental-related charges.
Discounted Bills Became the Cash-Out Method
The investigation identified a second layer of the operation through underground channels. In particular, fraudsters used Telegram communities to find people seeking cheaper ways to settle legitimate government bills.
Customers were offered discounts ranging from 50% to 80%. The fraudsters then paid the full bill through an official government portal using compromised cards.
In return, customers provided funds to the criminals through cryptocurrency or local bank transfers. Consequently, the stolen card value moved through a transaction that initially appeared to be a legitimate payment to a government entity.
Group-IB said the validated sample included 80 compromised cards linked to approximately $2.01 million in confirmed fraudulent activity. The company also reported that activity on government payment portals became visible in October 2025 and peaked in January 2026.
The operation shows how criminals can combine several attack stages. A phishing campaign may appear as one threat, while an eSIM change, an account takeover, and an authenticated payment may appear unrelated.
However, when these signals are connected, they reveal a coordinated fraud chain.
Group-IB Calls for Cross-Channel Detection
Group-IB recommends that banks strengthen monitoring around account recovery, eSIM changes and high-value government payments. In addition, institutions should review transactions that follow new device registrations or increases in transfer limits.
The company also recommends connecting web, mobile and payment intelligence. This approach can help security teams identify relationships between phishing activity, compromised accounts and suspicious payments.
Government payment platforms can also strengthen their defences. For example, operators can introduce additional risk checks for rapid or high-value settlements.
Furthermore, Group-IB recommends stronger information sharing between financial institutions, government portals and computer emergency response teams.
For consumers, the company advises accessing government and insurance services through official applications or saved bookmarks. Users should also treat unusually large discounts on government bills with caution.
The investigation highlights a wider challenge for financial institutions. As attackers increasingly combine cybercrime with financial fraud, a single transaction may provide too little context to reveal the wider operation.
Therefore, connecting cybersecurity, fraud, and digital risk signals will become increasingly important for detecting sophisticated payment abuse across the GCC.








