Fraud research

Paid in Full: How card fraudsters in the GCC use government payment portals to cash out stolen cards

The GCC has made significant investments in payment security and fraud prevention, strengthening authentication and making many traditional card-fraud techniques harder to execute.

Group-IB has uncovered a complex, multi-stage fraud scheme designed to operate across those defenses. Fraudsters combine phishing, eSIM compromise, account takeover, authenticated 3D Secure payments, underground marketplaces, and cryptocurrency to cash out stolen cards by settling genuine government bills at a discount.

The research shows why these schemes cannot be understood through transaction monitoring alone. Group-IB’s Cyber Fraud Fusion approach connects fraud, threat intelligence, digital risk, and investigation signals to reveal the full attack and monetization chain.

US$2.01 million
Confirmed fraudulent value across the validated cases
80 compromised cards
Linked to the confirmed financial impact
~300 incidents
Detected and flagged across several major retail banks

Fill out the form to access the full report

Inside the government bill-discount cash-out scheme

Discover how fraudsters connect multiple stages of cybercrime and financial fraud into a single cash-out chain — from the first phishing interaction to the final movement of funds.

The scheme begins with paid search advertising and cloned government or insurance services designed to harvest identity information, card details, PINs and authentication data. Compromised access is then used to enable authenticated payments through legitimate government portals, while underground channels recruit customers seeking discounted settlement of genuine bills.

Key findings

More than 400 phishing resources were identified across roughly 10 disguise patterns and five distinct phishing-kit families.
Around 300 incidents were detected and flagged across several major retail banks.
Approximately US$2.01 million in fraudulent value was confirmed across 80 compromised cards in the validated dataset.
The confirmed activity involved three types of government-payment channels, including justice-sector fines, electricity bills, and property or rental charges.
The shift toward government-payment portals became visible from October 2025 and peaked in January 2026, as operators moved away from earlier wallet-based cash-out methods.
The scheme combines phishing, credential theft, eSIM compromise, account takeover, authenticated 3DS payments, underground recruitment, and crypto-based exit rails across different parts of the fraud chain.

Why traditional fraud controls may see only part of the attack

Each individual stage can appear legitimate or unrelated when viewed in isolation.

A bank may see an authenticated 3DS transaction. A threat-intelligence team may see malicious infrastructure. A digital-risk team may identify a phishing page. Investigators may see Telegram activity or cryptocurrency flows.

The fraud becomes clearer when these signals are connected.

This cross-domain nature is central to the research: Group-IB identified how the phishing layer, account-compromise activity, payment stage, underground marketplace, and monetization infrastructure combine into a single operational chain.

Connect the signals: Cyber Fraud Fusion

Modern fraud increasingly spans cybersecurity, financial fraud, digital risk, telecommunications, and underground ecosystems. Defending against it therefore requires visibility across the entire chain rather than isolated controls.

Group-IB’s Cyber Fraud Fusion approach brings together Digital Risk Protection, Threat Intelligence, Fraud Protection, the Cyber Fraud Intelligence Platform, and Investigation capabilities to connect signals across domains and support earlier detection, investigation, and disruption.