securityonline.info 18 Sept 2026, 07:11 UTC

Chinese Cybercrime Syndicate Uses Dubai Payment Gateways to Test Stolen Cards

Chinese Cybercrime Syndicate Uses Dubai Payment Gateways to Test Stolen Cards
CyberSIXT Evidence Panel
Threat Actor
Tajin Group

RECORDED Future’s Insikt Group has identified Tajin Group, a suspected Chinese-speaking cybercriminal syndicate, as a vendor operating on Chinese-language “guarantee” marketplaces. The group is linked to phishing, payment-card theft and money laundering, with activity targeting mainland Chinese citizens, Chinese banks, global financial institutions and cryptocurrency exchanges. Researchers say Tajin moved from the Dabai Guarantee marketplace to Xinbi Guarantee around May 2026 and promoted its services through Telegram.

According to the report, Tajin buys stolen bank-identification data and processes fraudulent transactions through payment gateways including CCAvenue UAE and Geidea. It creates payment links while impersonating Dubai-based businesses, tests cards from multiple countries and avoids some Middle Eastern, US and Japanese cards because stronger 3D Secure controls make them more difficult to use. The group also converts proceeds into electronic gift cards, airline tickets, luxury goods and cash.

It reportedly claimed a 208,848 USDT deposit on Xinbi Guarantee and advertised transactions of up to 50,000 RMB—about US$7,382—although these figures are claims attributed to the group, not independently confirmed losses.

The US Treasury recently sanctioned Xinbi Guarantee, and authorities seized US$52.8 million from wallets linked to the platform, according to the article. Recorded Future says vendors have since adapted by moving to rival forums and using decentralised services, cryptocurrency and anonymous phone numbers or Telegram accounts.

The report recommends that financial institutions monitor card-testing patterns and transactions involving Middle Eastern payment gateways, while retailers should apply stronger checks to electronic gift-card purchases.

View full article

Article by CyberSIXT