Cybersecurity firm uncovers a scheme in which fraudsters pay real government bills with stolen cards, then pocket the ‘clean’ money from unsuspecting customers who think they are getting a bargain
GCC residents that have been offered a deep discount to settle a traffic fine, utility bill or legal charge may unwittingly be helping criminals cash out stolen money, according to a new investigation by cybersecurity firm Group-IB.
The scheme takes place when fraudsters use details of stolen credit cards they possess to pay genuine government bills and fines on official portals. They offer to pay victims’ bills or charges at 50 to 80 per cent off, then collect the discounted amount from the customer through cryptocurrency or local bank transfers.
Between October 2025 and August 2026, Group-IB’s Fraud Protection team detected about 300 related incidents across several major retail banks in the Gulf Cooperation Council (GCC) region.
In a validated sample of 80 compromised cards linked to three government institutions, confirmed losses reached $2.01 million (about Dh7.4 million).
The UAE Cyber Security Council has previously warned that online fraud now exploits digital services, smart applications and online networks to lure victims in ways that are often difficult to detect until after the crime has been committed.
Dr Mohamed Hamad Al Kuwaiti, Head of Cybersecurity for the UAE Government, has said that “no single entity or government can achieve cyber security on its own”, stressing that coordination between government bodies, the private sector and other nations is essential.
How the fraud gets past bank security
GCC banks require 3D Secure (3DS), the extra step that asks customers to confirm online card payments with a one-time passcode or bank app approval. While this has shut down simpler tactics such as digital wallet top-ups, Group-IB said the fraudsters are not breaking the checks but passing them.
In every confirmed case, the fraudulent transactions passed valid 3DS authentication. Criminals took over victims’ phone numbers and banking accounts, then approved the security prompts themselves, leaving banks with no visible sign of fraud.
Three stages of the operation
Group-IB said the operation runs in three layers.
Firstly, more than 400 fake websites, using 10 disguise patterns, imitate government portals and insurance services. It said they were promoted through verified Google Search ads targeting GCC users. Victims hand over personal data and card numbers, and approve phone prompts that authorise fraudulent eSIM swaps.
Secondly, using the hijacked eSIM number to intercept one-time passcodes, and masking their location through GPS spoofing, attackers take over online banking accounts, raise transfer limits and approve 3DS challenges in the app. Group-IB said 90 per cent of these takeovers were linked to new iOS device fingerprints from a cluster in Ramtha, Jordan.
Lastly, on specialised Telegram channels, fraudsters recruit members of the public by offering to settle fines, utility bills and legal charges at a discount, using the stolen cards.
How to protect yourself
Group-IB urged the public to access government and insurance services only through official apps or bookmarked websites, not sponsored search results. A paid ad is not a sign of trust.
It advised UAE and GCC residents to be wary of any third party offering a steep discount on a government bill. It may be a fraud or money-laundering lure, which can carry financial or legal consequences for those who take part.
The company recommended that banks treat account-recovery flows relying on card PINs and SMS passcodes as high-risk, and re-score high-value 3DS payments to government billers when they follow recent device registrations, eSIM changes or limit increases.
It also advised government portal operators to introduce risk checks for rapid repeat or high-value settlements, and to set up dedicated channels for national cyber emergency response teams and banks to report suspected fraudulent bill clearing.








United Arab Emirates Dirham Exchange Rate

