Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team

The GCC has made significant investments in payment security and fraud prevention, strengthening authentication and making many traditional card-fraud techniques harder to execute.
Group-IB has uncovered a complex, multi-stage fraud scheme designed to operate across those defenses. Fraudsters combine phishing, eSIM compromise, account takeover, authenticated 3D Secure payments, underground marketplaces, and cryptocurrency to cash out stolen cards by settling genuine government bills at a discount.
The research shows why these schemes cannot be understood through transaction monitoring alone. Group-IB’s Cyber Fraud Fusion approach connects fraud, threat intelligence, digital risk, and investigation signals to reveal the full attack and monetization chain.
Discover how fraudsters connect multiple stages of cybercrime and financial fraud into a single cash-out chain — from the first phishing interaction to the final movement of funds.
The scheme begins with paid search advertising and cloned government or insurance services designed to harvest identity information, card details, PINs and authentication data. Compromised access is then used to enable authenticated payments through legitimate government portals, while underground channels recruit customers seeking discounted settlement of genuine bills.
Each individual stage can appear legitimate or unrelated when viewed in isolation.
A bank may see an authenticated 3DS transaction. A threat-intelligence team may see malicious infrastructure. A digital-risk team may identify a phishing page. Investigators may see Telegram activity or cryptocurrency flows.
The fraud becomes clearer when these signals are connected.
This cross-domain nature is central to the research: Group-IB identified how the phishing layer, account-compromise activity, payment stage, underground marketplace, and monetization infrastructure combine into a single operational chain.
Modern fraud increasingly spans cybersecurity, financial fraud, digital risk, telecommunications, and underground ecosystems. Defending against it therefore requires visibility across the entire chain rather than isolated controls.
Group-IB’s Cyber Fraud Fusion approach brings together Digital Risk Protection, Threat Intelligence, Fraud Protection, the Cyber Fraud Intelligence Platform, and Investigation capabilities to connect signals across domains and support earlier detection, investigation, and disruption.