Good Carder
Professional
- Messages
- 1,014
- Reaction score
- 691
- Points
- 113
From carder to carders. Classic carding is a war against 3DS, BIN filtering, and AI anti-fraud. But there's a quiet corner where protection is virtually nonexistent. Paying fines, taxes, and government fees. Why? Because government portals are required to accept payments from citizens without unnecessary obstacles. Who will complain if someone's parking fine is suddenly paid by a stranger? No one. The victim won't notice the charge, and even if they do, they're unlikely to investigate who paid their debts. In this article, I'll explore why government services are an ideal target, schemes involving refunds from "grateful" payers, phishing through fake receipts and QR codes, and the risks of card blocking.
Critical Alert: Starting in January 2026, the IRS may automatically send fraudulent payment alerts to credit reporting agencies for amounts exceeding $1,000.
Solution: Don't exceed $500 per payment. Use disposable cards.
The main risks are card blocking due to frequency or automatic notification of fraudulent payments to tax authorities. Remain completely remote, do not exceed limits (2-3 payments per day from one card, $300-500 per payment), and use disposable cards.
A quick one-line reminder:
"Fines, taxes, PagoPa, EWA — no 3DS." Pay someone else's debt with a stolen card and get 70% from the "grateful" payer. Phishing receipts and QR codes collect CVVs by the thousands. Don't exceed $500 — otherwise, the tax authorities might get interested. Split the amounts and burn the cards."
Part 1: Why Government Portals Are the Ideal Target
Government portals (tax authorities, fine payment portals, court fees) have a fundamental feature: they are obligated to accept payments from citizens. They have no choice — they cannot refuse to pay taxes or fines. This makes them an ideal target.1.1 No 3DS or CVV verification
Government portals process millions of transactions daily. If every payment required 3DS, the system would simply collapse. Therefore, most government payment gateways either disable 3DS completely or have a low-value exemption for amounts up to a certain threshold. In the US, the Internal Revenue Service (IRS) accepts payments through third-party processing partners, which often disable 3DS. In Europe, government portals (PagoPa in Italy, GovPay in the UK) also have simplified verification.1.2. Victim Psychology
If a cardholder sees a $50 charge labeled "traffic fine" or "property tax," they rarely dispute it. First, they might not remember paying the fine. Second, even if they notice, they'll assume it's their own transaction. Third, the amount is often small ($20-$200). The risk of a chargeback is minimal. Even if the victim initiates a chargeback, the bank will handle the matter with the government agency, not you.1.3. No Trademark
Unlike card theft for electronics, paying a fine doesn't create a product trail. You don't order delivery or leave a drop-off address. The transaction occurs between you and the government agency, making it nearly impossible to trace back to you.1.4. Possibility of refund from the payer
The most intriguing scheme: you pay someone else's fine or tax with a stolen card, then contact the owner and offer to return the money "with a fee." The owner, upon learning that their debt has been repaid, willingly transfers 50-70% of the amount to a drop account. You receive the cleared money, and the victim is left with a loss.Part 2. International Government Payment Portals
2.1. USA: IRS, fines, court fees
In the United States, federal and state agencies use a variety of payment providers:- IRS (Internal Revenue Service): Accepts payments through third-party processing partners. 3DS is not required for amounts under $2,500. The IRS also partners with Equifax and Experian to send notices of outstanding balances.
- Payments to Courts: Many court systems accept online payments through platforms with poor security.
- Traffic Fines: Many states accept online payments through portals with minimal verification.
Critical Alert: Starting in January 2026, the IRS may automatically send fraudulent payment alerts to credit reporting agencies for amounts exceeding $1,000.
2.2. Europe: PagoPa (Italy)
PagoPa is an Italian platform for paying government services (taxes, fines, court fees). It processes millions of transactions annually. In 2026, fraudsters used PagoPa to pay their own tax debts using stolen cards. The loss amounted to €3,500 in just one case. PagoPa does not require 3DS for amounts under €500.2.3. Bahrain: EWA (Electricity and Water Authority)
In 2026, fraudsters in Bahrain used stolen cards to pay electricity and water bills through EWA. Two men made 12 fraudulent transactions totaling 1,854 Bahraini dinars ($4,900). The payment processor flagged the transactions as suspicious.2.4. India: e-Challan (traffic fines)
e-Challan is an online payment system for traffic fines. Fraudsters actively use it to collect CVVs through fake SMS fine notifications. The portal accepts any vehicle license plate number and generates a realistic fine, which is then used for phishing.Part 3. The "Payment of Someone Else's Debt + Repayment from the Payer" Scheme
This is the most effective method of cashing out through government portals.3.1. Search for debtors
Look for people with overdue taxes, fines, or court fees. Sources:- Public registers of debtors (available online in some countries).
- Forums and self-help groups where people ask for help paying off debts.
- Random selection. You can simply find the receipt in your mailbox or online.
3.2. Paying off a debt with a stolen card
Use a stolen non-3DS card with a balance corresponding to the debt amount. It's important that the card is from the same country as the payment portal. A US card is suitable for paying a fine in the US, an EU card for PagoPa, etc.3.3. Communication with the debtor
Contact the debtor (by phone, email, or social media). Let them know you've paid their debt. Legends:- "I entered the wrong receipt number, I want a refund."
- "A charity helps people with debt."
- "Return of erroneous translation."
3.4. Receiving money
The debtor, having received the "gift," willingly transfers 50-70% of the debt to a drop account or in cryptocurrency. The owner of the stolen card disputes the transaction, but the bank deals with the government agency, not you.Part 4. Phishing through fake receipts and QR codes
This method allows you to collect CVVs in the thousands without having direct contact with the victim.4.1. Fake utility and tax receipts
In Russia and some CIS countries, fraudsters are massively distributing fake utility and tax bills. The number of such schemes increased sharply in 2026. In some regions, fraudsters are adding QR codes to fake bills. When scanned, victims are redirected to a phishing page where they enter their card details. Funds are debited to controlled accounts, but no actual payment for services occurs. Experts from the Higher School of Economics warn that scammers are using ready-made website cloning tools to quickly create phishing sites.4.2. e-Challan Scheme in India
In India, scammers are using SMS messages threatening legal consequences to pay fictitious e-Challan fines. The portal accepts any vehicle license plate number and generates a realistic fine (approximately 590 rupees) to create the illusion of legitimacy, then steals card details. More than 36 phishing domains are linked to the same IP addresses, indicating a centralized infrastructure.4.3. Canada and Greece: Phishing for traffic fines
In Canada, scammers are using SEO poisoning to ensure their fake fine payment portals appear at the top of search results. They have deployed over 70 malicious domains on a single IP address, imitating government websites. In Greece, scammers are sending SMS messages demanding payment of a non-existent fine of €6.99. The link leads to a fake portal that mimics the official government website with an official design. The victim enters their card details, and they are sent to the carders.Part 5. Risks and how to minimize them
5.1. Card blocking based on transaction frequency
The bank may block your card if it detects unusual activity (for example, 10 payments per day to different government agencies). Use different cards for each payer — no more than 2–3 payments per card per day.5.2. Requesting documents from the payment gateway
For large amounts ($1,000+), the gateway may request identification. Keep the amount per payment within $300–$500.5.3. A government agency may cancel a payment
If a government agency discovers that a payment was made with a stolen card, it can reverse the transaction and report the information to the police. In the US, the Internal Revenue Service can automatically send fraudulent payment alerts to credit bureaus if the amount exceeds $1,000.Solution: Don't exceed $500 per payment. Use disposable cards.
5.4 The victim disputes the payment
The cardholder may notice the charge and initiate a chargeback. The money will be returned to them, and you will still owe the government agency. However, the agency won't be able to locate you. The only risk is that if you used a phishing receipt and the victim contacts the police, they might find your IP address and the drop account.Part 6. Comprehensive Checklist
- Select country and portal: USA (IRS, fines), Europe (PagoPa), Bahrain (EWA), India (e-Challan), Russia (tax portals).
- Obtain a stolen non-3DS card with a balance equal to the debt amount. The card's country must match the portal's country.
- Pay your debt through the online portal.
- Contact the debtor (if you are working under the repayment scheme) and receive cash or cryptocurrency to the drop account.
- For phishing receipts: create a fake payment order or copy an official form, replacing the details with your own.
- Distribute receipts through mailboxes, QR codes in entryways, and SMS messaging.
- Collect money from victims who pay a fake invoice.
- Cover your tracks: destroy receipt templates, change proxies, close VCC.
Summary
Paying fines and taxes is one of the most underestimated niches in carding. 3DS is almost never required. Chargebacks are rare. Victim psychology plays into this: people don't trust anyone to pay their debts and don't check their statements. A case from Bahrain shows that even when directly using stolen cards, the scheme works. A case from Italy demonstrates how paying someone else's taxes can serve as a direct method of cashing out. Phishing receipts and fake QR codes make it possible to collect CVVs by the thousands.The main risks are card blocking due to frequency or automatic notification of fraudulent payments to tax authorities. Remain completely remote, do not exceed limits (2-3 payments per day from one card, $300-500 per payment), and use disposable cards.
A quick one-line reminder:
"Fines, taxes, PagoPa, EWA — no 3DS." Pay someone else's debt with a stolen card and get 70% from the "grateful" payer. Phishing receipts and QR codes collect CVVs by the thousands. Don't exceed $500 — otherwise, the tax authorities might get interested. Split the amounts and burn the cards."