A $2 million cyber fraud scheme exploiting official government portals in GCC countries has been uncovered by cybersecurity firm Group-IB. Between October 2025 and August 2026, the firm’s fraud protection team detected approximately 300 related incidents across several retail banks in the region. In a validated subset of 80 compromised cards associated with three government institutions, confirmed financial losses reached 2.01 million dollars.

Details of the Cyber Fraud Scheme

The operation involved using stolen credit cards to settle real traffic fines, utility bills, and legal fees on public portals at a discount. Fraudsters offered these bill settlements to individuals on Telegram channels at discounts ranging between 50% and 80%. Consequently, the criminals paid the full amounts on official portals using stolen details and collected clean funds via cryptocurrency or local bank transfers.

Strict banking regulations across the GCC require 3D Secure verification steps for card transactions. However, this specific cyber fraud scheme succeeded because attackers passed these verification steps rather than breaking them. By obtaining control over victim phone numbers and online banking credentials, fraudsters approved verification prompts directly.

Three Operational Layers of the Campaign

Group-IB identified three distinct layers in the operation. First, the acquisition layer used Google Search advertisements targeted at the GCC to direct victims to over 400 phishing resources cloning government and insurance websites. Victims entered personal information, card numbers, and approved prompts authorizing fraudulent eSIM swaps on their mobile accounts.

Second, an account takeover group named Jordan Checker used the intercepted one-time passcodes and location spoofing to access accounts. Telemetry linked 90% of these takeovers to new iOS device fingerprints originating from a geohash cluster in Ramtha, Jordan. Third, the cash-out market labeled CIVIC DRAIN converted stolen balances into clean funds through discounted settlements.

Detection Challenges and Single-Channel Monitoring

Single-channel bank monitoring rarely flagged these transactions because payments went directly to legitimate public entities on behalf of actual citizens. Group-IB detected the campaign using its Cyber Fraud Fusion approach, which connects insights from web telemetry, telecommunications data, and financial systems. Combining digital risk protection with threat intelligence allowed investigators to trace mobile risks, including eSIM changes and GPS spoofing.

Security Recommendations for Institutions and the Public

The investigation outlines key mitigation steps for financial institutions and government entities in the cybersecurity sector. Banks should treat account recovery flows relying on card PINs and SMS passcodes as high risk. Furthermore, portal operators should implement risk checks for rapid repeat or high-value settlements.

Members of the public are advised to access official services exclusively through bookmarked links or dedicated applications rather than sponsored search results. Group-IB noted that steep discounts offered by unauthorized third parties for official fee payments often indicate fraudulent activity.