E-Commerce Scams Drive 85% of Financial Phishing in Oman as Infostealers Compromise Over One Million Banking Accounts
E-commerce scams now account for 85% of financial phishing in Oman, while infostealers compromised over one million banking accounts in 2025 as mobile malware attacks grow 1.5x year-on-year, per Kaspersky.

Kaspersky report reveals e-commerce scams account for 85% of financial phishing in Oman as mobile malware and infostealer attacks surge across the GCC in 2026
A new report from Kaspersky has put hard numbers on a threat pattern that enterprise security teams across the GCC have been tracking with growing concern: financial cybercrime is shifting decisively away from traditional banking malware and toward credential theft, social engineering, and dark web data markets with e-commerce infrastructure emerging as the primary attack surface.
The findings carry direct implications for security leaders at GCC financial institutions, retail enterprises, and any organisation operating consumer-facing digital payment infrastructure.
The Numbers Enterprise Security Teams Need to Know
Up to 80% of cyberattacks by online fraudsters in the region were e-commerce scams in 2025. More critically for enterprise risk teams: over one million online banking accounts were compromised by infostealers during the same period.
The phishing breakdown reveals a clear attacker preference shift. Pages impersonating e-commerce platforms accounted for 48.5% of financial phishing attempts, followed by bank impersonation at 26.1% and payment system spoofing at 25.5%. The relative decline in bank-specific phishing is not a positive signal Kaspersky analysts note it reflects the increasing difficulty of successfully impersonating well-protected banking interfaces, pushing attackers toward softer targets in the e-commerce layer where controls are typically weaker.
Why Oman And Why It Matters Regionally
Oman presents an instructive case study for the broader GCC. The country's e-commerce market, valued at approximately $2.2 billion in early 2024, is projected to reach $3.26 billion by end of 2026 and $4.62 billion by 2031 a trajectory driven by smartphone penetration exceeding 150% and government digitisation initiatives under Oman Vision 2040. Mobile payment volumes have grown eightfold in two years alone.
That growth velocity creates precisely the conditions attackers exploit: a rapidly expanding digital payment surface, a user base still developing security hygiene, and an e-commerce environment that has formalised quickly with the Ministry of Commerce issuing over 3,300 e-commerce licences by 2024 but where security standards across merchants remain uneven.
This pattern mirrors trajectories already visible in Saudi Arabia and the UAE, where similar e-commerce growth curves have been accompanied by escalating phishing and credential theft activity. As we highlighted in our earlier analysis of GCC cloud security risks, the speed of digital adoption across the region is consistently outpacing security posture maturity.
The Infostealer and Dark Web Dimension
For enterprise security teams, the most operationally significant finding in the Kaspersky data is not the phishing volume it is the role of infostealers and dark web marketplaces in the broader attack chain.
Kaspersky's Digital Footprint Intelligence analysts highlight that stolen credentials and bank card data are being systematically aggregated, repackaged, and sold through dark web markets, with phishing kits targeting financial product users readily available for purchase. This represents a professionalisation of financial cybercrime that lowers the skill floor for attackers while dramatically increasing the scale and persistence of credential-based threats.
For GCC enterprises particularly in financial services, retail, and hospitality a phishing incident affecting a customer or employee is no longer a contained event. Compromised credentials entering the dark web ecosystem can resurface in credential stuffing attacks, account takeover campaigns, and business email compromise attempts weeks or months after initial theft. The UAE Cyber Security Council has separately flagged that data exposure risks across cloud-stored files remain critically underestimated a vulnerability that compounds the infostealer threat.
Mobile Malware: The Accelerating Vector
The Kaspersky report flags mobile financial malware as a rapidly growing vector. Mobile banker attacks grew 1.5 times in 2025 compared to the previous year, driven by the continued migration of financial activity from desktop to mobile a shift accelerating sharply across the GCC.
For enterprise security architects, this has a direct infrastructure implication. Mobile device management policies, app vetting frameworks, and mobile threat defence capabilities need to be treated as front-line financial security controls not peripheral IT hygiene measures. Organisations that have not reviewed their mobile security posture against the current infostealer and mobile banker threat landscape are carrying material unaddressed risk.
Three Immediate Priorities for GCC Enterprise Security Teams
Review credential exposure. Dark web monitoring for compromised employee and customer credentials should be an operational baseline. The volume of infostealer-compromised accounts reported in 2025 makes passive posture untenable.
Harden e-commerce and payment interfaces. Organisations operating digital storefronts or payment infrastructure should audit their anti-phishing controls, domain monitoring coverage, and customer authentication requirements against current attack patterns.
Treat mobile as a primary threat surface. The 1.5x growth in mobile banker malware demands that mobile security controls receive equivalent investment and scrutiny to endpoint and network defences. For organisations evaluating 24/7 threat monitoring capabilities, our analysis of Managed Detection and Response in the GCC outlines what an effective monitoring framework looks like for the region.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.