Residents across the Gulf Cooperation Council are being warned about a fraud scheme in which criminals use stolen bank card details to settle genuine government fines, utility bills and legal charges before collecting discounted payments from unsuspecting customers.
Cybersecurity firm Group-IB said fraudsters offer to pay legitimate bills at discounts of between 50% and 80%, asking customers to reimburse them through cryptocurrency or local bank transfers.
The arrangement can appear legitimate because the original payment is made directly to a government authority on behalf of a real customer. Group-IB said this makes the transactions less likely to trigger conventional bank monitoring systems.
Its Fraud Protection team identified about 300 related incidents across several major GCC retail banks between October 2025 and August 2026. In a verified sample involving 80 compromised cards linked to three government institutions, confirmed losses reached $2.01 million, equivalent to about Dh7.4 million.
The investigation highlights how criminals are adapting established banking security measures rather than simply bypassing them.
GCC banks commonly require 3D Secure authentication for online card payments, requiring customers to enter a one-time passcode or approve transactions through a banking application. Group-IB said the fraudulent payments in the cases it investigated successfully passed these checks.
The criminals had first taken control of victims’ phone numbers and banking accounts, allowing them to approve authentication requests themselves.
Group-IB said the operation generally follows three stages.
First, criminals operate more than 400 fake websites designed to resemble government portals and insurance services. The sites use at least 10 different disguises and have been promoted through Google Search advertisements targeting GCC users.
Victims are encouraged to provide personal and card information and approve requests that enable fraudulent eSIM swaps.
Attackers then use the hijacked phone numbers to intercept one-time passcodes and gain access to online banking accounts. They can increase transfer limits and approve 3D Secure transactions through banking applications. Group-IB said 90% of the account takeovers it examined were associated with new iOS device fingerprints from a cluster in Ramtha, Jordan.
In the final stage, criminals advertise discounted bill-payment services through specialised Telegram channels, recruiting members of the public to provide genuine bills that can be paid using stolen cards.
The UAE Cyber Security Council has previously warned that criminals are increasingly exploiting digital services and online networks to conduct fraud.
Group-IB urged residents to access government and insurance services through official applications or bookmarked websites rather than sponsored search advertisements.
It also warned people to avoid third parties offering unusually large discounts on government payments, saying participation could expose customers to financial losses or legal consequences.
The company recommended stronger checks by banks and government portals for high-value payments following recent device registrations, eSIM changes or increases in transaction limits.
