
News Desk
The News Desk provides timely and factual coverage of national and international events, with an emphasis on accuracy and clarity.

A person holding a credit card and a cell phone
A stolen credit card scam across the GCC allows fraudsters to pay genuine government bills and fines, then offer residents the same services at steep discounts, Khaleej Times reported.
Group-IB detected about 300 related incidents involving major retail banks between October 2025 and August 2026. Criminals use stolen cards to settle legitimate bills, then charge residents 50% to 80% less than the actual amount to turn the stolen funds into cash.
How does the stolen credit card scam work?
Fraudsters use stolen card details to pay genuine bills and fines through official government portals.
They then offer to settle bills for residents at a discount, collecting payment through cryptocurrency or local bank transfers. Because the original payment goes to a legitimate government entity, bank monitoring systems may not flag the transaction as suspicious.
How big is the stolen credit card scam in the GCC?
Cybersecurity firm Group-IB said its Fraud Protection team detected about 300 related incidents involving several major retail banks across the Gulf Cooperation Council (GCC).
In a validated sample of 80 compromised cards linked to three government institutions, confirmed losses reached $2.01 million, or about Dh7.4 million.
Residents offered steep discounts on traffic fines, utility bills or legal charges may unknowingly help criminals convert stolen funds into usable money.
How do fraudsters get past bank security?
GCC banks require 3D Secure (3DS), an additional security step that asks customers to confirm online card payments using a one-time passcode or bank app approval. The system has helped block simpler fraud tactics, such as digital wallet top-ups.
Group-IB said the fraudsters are not bypassing these checks but passing them. In every confirmed case, the fraudulent transactions successfully cleared 3DS authentication.
Criminals took control of victims' phone numbers and banking accounts, allowing them to approve security prompts themselves. As a result, banks had no obvious indication that the transactions were fraudulent.
What are the three stages of the operation?
Group-IB said the operation has three stages.
First, more than 400 fake websites imitate government portals and insurance services using 10 different disguise patterns. The sites were promoted through verified Google Search ads targeting users across the GCC.
Victims enter personal information and card details on the fake sites. They may also approve phone prompts that enable fraudulent eSIM swaps.
Second, attackers use the hijacked eSIM numbers to intercept one-time passcodes and conceal their locations through GPS spoofing. They then take over online banking accounts, increase transfer limits and approve 3DS challenges through banking apps.
Group-IB said 90% of these account takeovers were linked to new iOS device fingerprints from a cluster in Ramtha, Jordan.
Third, fraudsters recruit members of the public through specialised Telegram channels. They offer to settle fines, utility bills and legal charges at steep discounts using the stolen cards.
How can you protect yourself from the scam?
Group-IB urged the public to access government and insurance services only through official apps or bookmarked websites, rather than sponsored search results. A paid advertisement does not guarantee that a website is legitimate.
It also advised residents to be wary of third parties offering steep discounts on government bills. Such offers may be linked to fraud or money laundering and could expose participants to financial or legal consequences.
What does Group-IB recommend for banks and governments?
Group-IB recommended that banks treat account-recovery processes relying on card PINs and SMS passcodes as high risk. It also urged banks to reassess high-value 3DS payments to government billers when they follow recent device registrations, eSIM changes or increases in transaction limits.
The cybersecurity firm advised government portal operators to introduce risk checks for rapid repeat or high-value bill settlements. It also called for dedicated channels through which national cyber emergency response teams and banks can report suspected fraudulent bill payments.
What have UAE officials said about online fraud?
The UAE Cyber Security Council has previously warned that online fraud is increasingly exploiting digital services, smart applications and online networks. Such crimes can be difficult to detect until after they have been committed.
Dr Mohamed Hamad Al Kuwaiti, head of cybersecurity for the UAE government, has said that "no single entity or government can achieve cyber security on its own." He stressed the importance of coordination between government bodies, the private sector and other countries in tackling cyber threats.







Comments
See what people are discussing