GCC Fraud Warning: Scammers Use Stolen Credit Cards to Offer Bill Payments at 50–80% Discounts

Date:

Cybersecurity Firm Exposes Scam Where Fraudsters Use Stolen Cards to Settle Genuine Government Bills, Then Collect Payments From Customers Lured by Discounted Offers.

Residents across the Gulf Cooperation Council (GCC) are being warned about a sophisticated financial scam in which fraudsters offer substantial discounts on traffic fines, utility bills and legal payments while secretly using stolen credit card information to complete the transactions.

According to a recent investigation by cybersecurity company Group-IB, individuals who accept these seemingly attractive offers may unknowingly become involved in a scheme designed to convert stolen funds into legitimate-looking payments.

The fraud operates by using compromised credit card details to settle genuine government bills and penalties through official payment platforms.

Scammers approach customers with offers to clear their outstanding payments at discounts ranging from 50% to 80%. After completing the transaction using stolen card information, they collect the reduced payment directly from the customer through cryptocurrency or transfers to local bank accounts.

Group-IB explained that these transactions can be difficult for financial institutions to identify as fraudulent because the payments are made to legitimate government authorities and are linked to genuine bills belonging to real individuals.

As a result, conventional banking monitoring systems may fail to recognise the suspicious activity.

Between October 2025 and August 2026, Group-IB’s Fraud Protection team identified approximately 300 incidents associated with this fraudulent practice across several leading retail banks in the GCC region.

The findings highlight how criminals are exploiting trusted government payment systems and attractive discount offers to disguise the movement of funds obtained through stolen credit card details.

A detailed examination of 80 compromised credit cards associated with three government institutions revealed confirmed financial losses of $2.01 million (approximately Dh7.4 million), highlighting the scale of the fraudulent activity.

The UAE Cyber Security Council has previously cautioned residents that cybercriminals are increasingly exploiting digital platforms, smart applications and online services to deceive unsuspecting users. Such scams can be particularly difficult to identify, with victims often discovering the fraud only after it has occurred.

Dr Mohamed Hamad Al Kuwaiti, Head of Cybersecurity for the UAE Government, has emphasised that effective cybersecurity requires collective action rather than efforts by individual organisations alone.

He highlighted the importance of cooperation among government authorities, private businesses and international partners in strengthening digital security and combating emerging cyber threats.

How Fraudsters Bypass Banking Security Measures

Banks across the GCC use 3D Secure (3DS) authentication, an additional security measure that requires customers to verify online card transactions through a one-time password (OTP) or approval within their banking application.

Although this system has helped prevent simpler fraudulent activities, including unauthorised digital wallet top-ups, Group-IB found that criminals involved in the latest scheme were successfully completing these authentication procedures rather than technically bypassing them.

According to the cybersecurity firm, every confirmed fraudulent transaction passed valid 3DS verification.

The attackers achieved this by gaining control of victims’ mobile phone numbers and online banking accounts, allowing them to approve transaction verification requests without the account holders’ knowledge.

Consequently, the transactions appeared legitimate to banking systems, making fraudulent activity significantly harder to detect.

How the Three-Stage Fraud Operation Works

Group-IB identified three interconnected stages used by cybercriminals to obtain stolen financial information and convert it into payments.

Stage 1: Fake Websites and Online Advertisements

The operation begins with fraudulent websites designed to resemble legitimate government service portals and insurance platforms.

Investigators identified more than 400 fake websites using 10 different impersonation patterns.

These websites were reportedly promoted through verified Google Search advertisements targeting internet users across GCC countries.

Victims visiting the fraudulent platforms were tricked into providing personal information and credit card details.

They were also persuaded to approve mobile verification requests that enabled unauthorised eSIM transfers, giving criminals control over their phone numbers.

Stage 2: Mobile Number Hijacking and Banking Account Takeovers

After gaining control of a victim’s mobile number through an eSIM swap, attackers could intercept one-time passwords and other security notifications.

The criminals also used GPS spoofing techniques to disguise their actual locations while attempting to access victims’ online banking accounts.

Once access was obtained, they could increase transaction limits and approve 3DS verification requests through banking applications.

Group-IB reported that 90% of these account takeovers were associated with newly registered iOS device fingerprints linked to a cluster in Ramtha, Jordan.

Stage 3: Discounted Bill Payments Using Stolen Cards

In the final stage, fraudsters used specialised Telegram channels to attract customers interested in paying government-related charges at reduced rates.

They advertised substantial discounts on traffic fines, utility bills and legal payments, offering to settle these obligations using compromised credit cards.

Customers paid the fraudsters a discounted amount, while the actual bills were cleared using stolen financial information.

This allowed criminals to receive payments from customers while making the underlying transactions appear to involve legitimate government services.

How UAE and GCC Residents Can Protect Themselves

Group-IB has urged residents to remain cautious when accessing government services, making online payments or responding to offers promising unusually large discounts.

The cybersecurity company recommends using official government and insurance applications or previously bookmarked websites rather than relying on sponsored search engine advertisements.

It warned that the presence of a paid advertisement does not necessarily mean that a website is legitimate or trustworthy.

Residents should also be suspicious of individuals or third-party services offering to settle government fines, utility charges or other official payments at significantly reduced prices.

Such arrangements could be connected to financial fraud or money laundering, potentially exposing participants to financial losses or legal consequences.

Recommendations for Banks and Government Authorities

Beyond public awareness, Group-IB has recommended additional safeguards for financial institutions and government payment platforms.

The company advised banks to classify account recovery procedures involving card PINs and SMS-based verification codes as higher-risk activities.

It also recommended reassessing the risk associated with high-value 3DS transactions involving government payments, particularly when they occur shortly after suspicious account changes.

These warning signs may include newly registered devices, recent eSIM replacements or sudden increases in transaction limits.

For government payment platforms, Group-IB suggested introducing stronger monitoring systems to identify unusually frequent transactions or large-value settlements.

The firm also recommended establishing dedicated reporting channels connecting government portal operators, banks and national cyber emergency response teams.

Such coordination would help authorities identify suspicious bill payments more quickly and strengthen efforts to prevent the misuse of legitimate government services for financial fraud.

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

Philippine Airlines Suspends Riyadh Flights Following Houthi Attacks on Saudi Airport

Philippine Airlines Temporarily Halts Manila-Riyadh Flights Amid Growing Safety...

US-Iran Tensions: Key Updates UAE Residents Should Know Today (October 8, 2026)

Rising Saudi-Houthi Tensions, Tanker Attack and Strait of Hormuz...

Lisa’s ‘SaWaDiKa’ Becomes First K-Pop Music Video of 2026 to Reach 200 Million Views

BLACKPINK’s Lisa Makes History as Her Bangkok-Filmed Music Video...

Dubai Set to Play Decisive Role in SailGP’s US$2 Million Grand Final

Dubai to Stage SailGP’s Penultimate Event as Teams Compete...