FF News — The Fintech News Network

Group-IB Uncovers $2M GCC Fraud Scheme Exploiting Government Payment Portals

By Lauren Towner · 9 October 2026

Press Release: Group-IB Uncovers $2M GCC Fraud Scheme Exploiting Government Payment Portals | Featured Image by FF News

Cybersecurity firm Group-IB has uncovered a sophisticated fraud scheme in the Gulf Cooperation Council (GCC) region where criminals use stolen credit cards to pay legitimate government bills at a discount. By bypassing 3D Secure protocols through eSIM swaps and account takeovers, attackers are laundering stolen funds through official payment gateways, posing a significant challenge to traditional bank monitoring systems.

What was announced

Group-IB’s Fraud Protection team identified a high-impact campaign active between October 2025 and August 2026, detecting approximately 300 related incidents across several major retail banks. In a validated subset of 80 compromised cards used at three government institutions, confirmed losses reached USD 2.01 million. The investigation revealed that despite strict banking rules in the GCC requiring 3D Secure (3DS) verification, cybercriminals have developed a multi-step process to pass these security checks rather than breaking them.

The operation, which Group-IB categorizes into three layers, begins with an acquisition phase involving over 400 phishing resources. These sites, promoted via verified Google Search ads, clone government portals to steal personal data and authorize fraudulent eSIM swaps. The second layer, attributed to the "Jordan Checker Group," involves hijacking the victim's phone number to intercept one-time passcodes (OTPs) and take over online banking accounts. Telemetry linked 90% of these takeovers to a geohash cluster in Ramtha, Jordan, using GPS spoofing to mask the attackers' locations.

The final "CIVIC DRAIN" layer operates via Telegram channels, where fraudsters offer to settle traffic fines and utility bills for the public at discounts of 50% to 80%. The criminals pay the full bill on official government portals using stolen card details and collect "clean" discounted funds from the customer via cryptocurrency or local bank transfers. Because the payments are made to trusted government entities, they rarely trigger traditional fraud alerts.

"Because the payment goes directly to a trusted government entity on behalf of a real citizen, single-channel bank monitoring rarely flags the transaction as suspicious."

Group-IB.

The companies involved

Group-IB is a leading creator of predictive cybersecurity technologies designed to investigate, prevent, and fight digital crime. The company specializes in mapping threat actor activity and providing high-fidelity threat intelligence to financial institutions and government bodies. Its product suite includes Digital Risk Protection (DRP) for phishing takedowns and Fraud Protection systems that cross-reference 3DS prompts against live mobile risks, such as eSIM changes and GPS spoofing.

In the GCC market, Group-IB has established itself as a primary investigator of localized cyber threats, particularly those targeting the region's advanced digital payment infrastructure. The company’s Cyber Fraud Fusion (CFF) approach aims to unite insights across web, mobile, and financial systems to expose threat activity that siloed defenses often miss. By tracing financial flows and mapping Telegram-based cash-out markets, the firm provides a broader view of the organized criminal groups operating across international borders, such as the Jordan-based clusters identified in this latest investigation.

What FF News has reported before

In August 2026, FF News reported on another significant threat identified by the firm in the region: Group-IB Warns Gulf Investors of Deepfake Stock Scams and Fake Crypto Platforms on WhatsApp. That investigation highlighted how scammers were utilizing deepfake technology and social messaging platforms to promote fraudulent investment schemes. The recurring nature of these reports suggests a persistent and evolving threat landscape in the Gulf, where attackers are increasingly moving away from simple technical exploits toward complex social engineering and identity-based attacks that exploit the high trust placed in digital government services and verified communication channels.

What this means

This announcement moves the needle by demonstrating that 3D Secure, long considered the gold standard for online payment security, is no longer an absolute barrier against organized crime. When attackers transition from bypassing security to "passing" it through identity theft and eSIM hijacking, the industry’s reliance on single-channel authentication becomes a liability. Government payment portals are now being weaponized as laundering tools, putting public sector infrastructure under unexpected pressure. This shift forces a question for the sector: if a transaction is authenticated by the correct device and sent to a legitimate biller, but the underlying intent is criminal, can traditional banking systems ever hope to catch it without cross-industry data sharing?

Companies in this story: GROUP IB

More from News