The Bill Is Real. The Payment Is Stolen. Inside a New GCC Government-Bill Scam
Fraudsters are using stolen cards to pay genuine government bills and fines, then selling the payment to customers at a discount. The official portal can be real while…

This scam breaks a common safety shortcut because criminals use genuine government payment portals as part of the cash-out chain.
UAE and GCC residents paying fines, utility bills, legal charges or property-related payments, especially anyone offered a steep third-party discount.
Group-IB’s confirmed loss figures cover a wider GCC dataset and should not be treated as UAE-only losses.
Banks, telecom providers, government portals and investigators will need to connect authentication, phishing, eSIM and payment signals across the full fraud chain.
Pay government obligations directly through official channels. Never use an unknown intermediary offering a large discount, even if the bill is settled on a real portal.
A traffic fine can be real.
The government payment portal can be real.
The bill can genuinely disappear from your account.
And you can still be inside a fraud scheme.
Group-IB has documented a GCC cash-out operation in which criminals use stolen payment cards to settle genuine government bills, fines, electricity charges and property-related payments. They then recruit customers who want those bills paid at a steep discount and collect the “clean” money through bank transfers or cryptocurrency.
The scam works because the final payment looks legitimate
Most scam advice tells users to look for a fake website or suspicious payment link.
This scheme is harder to recognise because the government portal itself may be legitimate.
The fraud happens behind the payment.
A criminal obtains compromised card or account access, then uses it to pay a real obligation belonging to someone else. The customer sees their fine or bill marked as paid and sends the fraudster a smaller amount in return.
The discount is the bait.
The numbers show this is not a theoretical pattern
Group-IB says its investigation confirmed approximately US$2.01 million in fraudulent value across 80 compromised cards.
About 300 incidents were detected and flagged across several major retail banks.
The company identified more than 400 phishing resources spread across roughly 10 disguise patterns and five phishing-kit families.
The confirmed activity included justice-sector fines, electricity bills and property or rental charges.
The fraud chain starts much earlier than the discounted bill
The customer buying the discount is only one part of the operation.
Group-IB describes a longer chain:
- Victims are targeted through phishing resources that imitate government or insurance services.
- Attackers collect identity details, card information, PINs and authentication data.
- Some cases involve eSIM compromise and account takeover.
- Compromised cards are used for authenticated payments through legitimate government portals.
- Underground channels recruit people who want bills or fines settled at a discount.
- The customer pays the fraudster using a bank transfer or cryptocurrency.
Each step can look unrelated when a bank, telecom provider, government portal and victim see only their own part of the chain.
Why 3D Secure does not automatically mean the payment is safe
One of the most important findings is that some transactions were authenticated through 3D Secure.
That matters because consumers often treat an authenticated card transaction as proof that the real cardholder approved it.
But if the attacker has already compromised the victim’s phone number, account or authentication channel, the payment can pass through legitimate security controls while still being fraudulent.
The lesson is not that 3D Secure is useless. It is that payment authentication is only one layer.
The scam flips the usual UAE fraud pattern
Robius has tracked repeated UAE scam mechanics where a criminal sends a fake authority message and pushes the victim toward a fake payment page. Our 2026 scam-pattern roundup showed how often authority impersonation and fake payment links recur.
This scheme is different at the final stage.
The customer may be interacting with a criminal, but the bill itself is settled on a real government system.
That makes “check the domain” insufficient advice for the person buying the discount.
The 50 to 80 percent discount is the warning
Khaleej Times reports that fraudsters have been advertising bill settlements at discounts of 50% to 80%.
There is no legitimate reason an unknown person should be able to settle a government fine, utility charge or legal payment for half its value while still making money.
If the economics only work because someone else’s card is funding the payment, the customer becomes part of the cash-out process even if they did not steal the card.
A payment that clears can still come back
The immediate attraction is obvious. The obligation appears paid.
But a fraudulent card transaction can later be disputed or investigated. Depending on the payment channel and case, the original payment may be reversed, frozen or linked to a fraud investigation.
The customer can also be left explaining why they transferred money to the person who arranged the payment.
That is why “it worked” is not evidence that the service was legitimate.
If someone offers to pay your government bill for less, do not test it
The safe route is boring:
- pay the authority directly;
- use the official app, website or authorised payment channel;
- do not transfer money to an intermediary promising a hidden discount;
- do not give anyone your login, OTP or account access;
- keep receipts and transaction references for payments you make yourself.
If you already used one of these services
Preserve the conversation, payment proof, bank transfer details, usernames, phone numbers and any cryptocurrency addresses.
If your own accounts or identity details were exposed, contact the relevant bank or telecom provider quickly.
Robius has a separate UAE scam-reporting guide that explains when to contact your bank, police, cybercrime channels and Sanadak.
If you are worried that a fraudster may have taken control of a SIM or opened mobile services using your identity, TDRA’s Hesabati service can help you check the numbers registered under your Emirates ID. Our Hesabati guide explains where to look.
Verdict: SCAM
A person offering to pay a government bill, fine or utility charge at a huge discount is not providing a clever payment service.
The bill may be real. The government portal may be real. The payment may initially clear.
That does not make the funding source legitimate.
The Robius Read
This scheme is useful because it breaks a common scam-detection shortcut.
We often tell users to verify the website and pay only through official channels. That advice still matters, but it does not solve every fraud model.
Here, criminals are using the official channel as part of the cash-out process.
The better rule is broader: if someone inserts themselves between you and a government payment and offers an impossible discount, the question is not whether the bill gets paid. The question is whose money is actually paying it.
Sources
- Group-IB: Paid in Full, GCC government-payment portal fraud research
- Khaleej Times: GCC bill-discount scam report, 8 October 2026
Checked 9 October 2026. Group-IB’s confirmed dataset covers a wider GCC fraud operation and should not be read as a UAE-only loss figure.
Robius.news | Dubai, UAE | 2026 | Built to be first. Built to be trusted.
UAE, UNFILTERED
