Skip to main content

Grand Egyptian Museum Ticket Scam Network

18 min read

Grand Egyptian Museum ticket scam cover: a fake ticket-checkout site linked outward to clusters for the Louvre, Colosseum, Dubai parks and Istanbul, with stat tiles reading 188 domains, 40 attractions, 10-plus countries.

TL;DR — A traveler searching for Grand Egyptian Museum tickets can land on a near-perfect lookalike, pay, and never receive a ticket. We started from one such fake domain and pulled the thread: it belongs to an industrial fake-ticket network of 188 domains that impersonates roughly 40 real attractions across 10+ countries — the Louvre, the Colosseum, Versailles, the Uffizi, Dubai theme parks, Istanbul palaces, UK stadium tours, and more. The whole thing runs on a handful of origin servers (GoDaddy, IONOS, a Moldovan VPS) behind Cloudflare and AWS, with the Egyptian core registered through NiceNIC and CNOBIN from RU/CN. This is our map of the operation and how to avoid it.

About this investigation. This is first-hand PhishEye threat research built primarily from passive OSINT — whois, DNS, Certificate Transparency, urlscan.io, reverse-IP, and abuse.ch — plus one deliberate, controlled walkthrough of a single lookalike's checkout flow using a non-functional test card, purely to document the user-facing experience end to end. No real transaction was completed, no real payment or personal data was submitted, and screenshots below have card and invoice fields redacted regardless. All indicators are defanged with [.], captured 19–23 July 2026. We reported the infrastructure for takedown. Official ticketing is only at gem.eg / tickets.gem.eg and, for other venues, each attraction's own site.

The lure: a real museum, huge demand, and a fake checkout

The Grand Egyptian Museum (GEM) is one of the most anticipated cultural openings in the world, which makes it perfect bait. Search interest is enormous, official capacity is constrained, and most visitors have never seen the real ticketing site. That gap is exactly what a fake-ticket operator wants.

The scam is not a credential-phishing page in the usual sense. It is a fake e-commerce checkout: a polished site that looks like an official or "authorized" ticket seller, lists real opening hours and prices, pulls in the attraction's genuine photos and logo, and asks for your card to "book" timed-entry tickets. The card is charged (or the details are harvested for later fraud), and either no ticket arrives or a worthless PDF does. Because the victim wanted to buy a ticket, every step feels normal — the only tell is the domain.

We were handed a batch of GEM lookalikes and asked a simple question: how big is this, really? The answer turned out to be much bigger than Egypt.

Starting point: the Grand Egyptian Museum cluster

The seed domains were textbook brand abuse of GEM and its official gem.eg domain — a mix of typo-lookalikes and keyword mashups:

  • Brand mashups: egyptian-museum-tickets[.]com, grandegyptianmuseumticket[.]com, tickets-grandegyptianmuseum[.]com, grand-egyptian-museum[.]org.
  • Abbreviation play on "GEM": gem-tours[.]com, gemvisiteg[.]com, ticketsgem[.]com, gemsticket[.]com, gem-museum[.]xyz.
  • Deliberate misspellings to dodge exact-match filters: egtcktsmuseum[.]com (egtickets-museum), gizatcktsmuseum[.]com, egtoorstickt[.]com, gem-rnuseum[.]cfd (the "rn" reads as "m"), grand-egyptlan-museum[.]org ("egyptlan").
  • Fake official subdomains: gem.tickets-eg[.]com, gem.eg-tickets[.]world, gem.eg-visit[.]com — the gem. prefix mimics an official subdomain while the real registrable domain is attacker-owned.

Hosting split two ways. Many sit behind Cloudflare, which hides the origin. But a few resolved straight to origin servers, and that is where the investigation opened up: egtcktsmuseum[.]com pointed to a bare VPS at 62.60.226[.]43.

The pivot: one origin server unrolls the network

An exposed origin IP is a gift. A reverse-IP lookup on 62.60.226[.]43 immediately returned a sibling we had not been given — gizatcktsmuseum[.]com — confirming the host was running more than one GEM scam. From there we widened the aperture with two techniques:

  1. Brand-fingerprint search. Querying urlscan.io for pages titled "Grand Egyptian Museum" and "Egyptian Museum" on non-official domains returned hundreds of scans and dozens of new lookalikes.
  2. Per-IP host mining. For every scam domain that exposed an origin, we pulled the full list of other domains ever seen on that IP.

That second step is what turned a domain list into a map. Two origin servers lit up with far more than Egyptian museums.

Investigation flow: one GEM lookalike resolved to an origin VPS; reverse-IP and per-IP mining on that and two anchor hosts unrolled a 188-domain network across eight attraction clusters. From one fake museum ticket to a global network Each exposed origin server revealed the operator's other brands egtcktsmuseum[.]com one GEM lookalike 62.60.226[.]43 exposed origin VPS reverse-IP + per-IP host mining + brand-title search across urlscan 188 domains · ~15 origin IPs · ~40 attractions · 10+ countries Egypt / GEM · European museums · UK attractions Dubai / UAE · Istanbul / Turkey · Gulf states · Europe Louvre · Colosseum · Versailles · Uffizi · Legoland Dubai · Hagia Sophia · Tower of London …
Figure 1. The investigation flow. A single GEM lookalike that exposed its origin server was enough to unroll an operation spanning dozens of unrelated tourist attractions.

What the network actually covers

Mapped end to end, the operation is 188 domains impersonating around 40 attractions in more than ten countries. The Grand Egyptian Museum is the largest single cluster, but it is one of eight.

Domains by cluster: Egypt and Grand Egyptian Museum 85, United Kingdom attractions 37, Dubai and UAE 21, Istanbul and Turkey 13, European museums 11, Gulf states 10, other Europe 5, unclassified 6. 188 scam domains, by attraction cluster One operation, one kit, dozens of impersonated brands Egypt / GEM 85 UK attractions 37 Dubai / UAE 21 Istanbul / Turkey 13 European museums 11 Gulf (Saudi/Qatar/Oman) 10 Europe (other) 5 Unclassified 6 Source: PhishEye passive OSINT mapping, July 2026. Counts include per-venue subdomains.
Figure 2. The Egyptian cluster is the biggest, but UK, Dubai, Istanbul, and European-museum clusters together outnumber it. Same operator, same kit, different brands.

The impersonated brands read like a world tour: the Louvre, Château de Versailles, the Colosseum, Milan Duomo, Musée d'Orsay, St Mark's Basilica, and the Uffizi in Europe; Legoland and Motiongate and the Dubai Frame in the UAE; Hagia Sophia, Topkapi Palace, the Blue Mosque, and Dolmabahçe in Istanbul; the Tower of London, Stonehenge, The Shard, Edinburgh Castle, and Premier League stadium tours in the UK; plus Saudi, Qatari, and Omani attractions in the Gulf.

The kit fingerprint

What makes this one operation rather than a coincidence is the consistent tradecraft across every cluster.

  • Naming grammar: one parent domain per destination, one subdomain per venue. legoland.dubai-parks-and-resorts-tickets[.]com, hagia-sophia.istanbul-ticket[.]co, and pyramids.egypt-tickets[.]co are three regions of the same machine. Parents follow tidy templates: <place>-tickets.<tld>, <attraction>ticket.com, and for French targets lelouvre**billet**.com.
  • A shared subdomain marker. An sge. subdomain appears across the museum hosts — sge.ticketsgem[.]com, sge.uffizigalleries[.]com, sge.egypt-monuments[.]com — a small operational fingerprint that ties otherwise unrelated brands to one builder.
  • Cheap, abused TLDs: the operation sprawls across .com, .co, .uk, .co.uk, .me, .nl, .to, .top, .shop, .live, .sbs, .cfd, .xyz, .site, .online, .world, and .mom.
The kit's naming grammar: a per-destination parent domain with a subdomain for each venue, illustrated for Egypt, Dubai, and Istanbul parents. One parent per destination, one subdomain per venue The template that scales the scam to any attraction egypt-tickets[.]co pyramids.egypt-tickets[.]co grand-museum.egypt-tickets[.]co ski.egypt-tickets[.]co dubai-parks-and-resorts-tickets[.]com legoland.dubai-parks…[.]com motiongate.dubai-parks…[.]com real-madrid-world.dubai-parks… istanbul-ticket[.]co hagia-sophia.istanbul-ticket[.]co skyview.istanbul-ticket[.]co vialand.istanbul-ticket[.]co Add a new attraction by adding a subdomain. Add a new country by registering one more parent. Representative examples, defanged. Full indicator list withheld from the article; available to responders.
Figure 3. The scam scales like software. Each destination is a parent domain; each venue is a subdomain, cloned from one checkout template with the target's branding swapped in.

Inside the checkout: what the scam actually shows you

To document the victim's experience end to end, we walked one lookalike's checkout flow with a non-functional test card — no real transaction, no real payment or personal data submitted. Four screenshots below (card and invoice fields redacted regardless) show why the flow is convincing at every step.

Fake Grand Egyptian Museum ticketing homepage using the museum's real logo and photography, labelled 'OFFICIAL TICKETING WEBSITE', with a Book Tickets call to action.
Step 1 — the homepage. The site reuses the museum's real logo and imagery and explicitly labels itself the "OFFICIAL TICKETING WEBSITE," even warning visitors that tickets bought "through other platforms" aren't the museum's responsibility. The irony is that this page is the unofficial one.
Fake museum ticket booking flow showing a Date, Time and Ticket Types step with Admission Ticket and Guided Tour Ticket options and a working July 2026 calendar, styled to match a real e-commerce booking flow.
Step 2 — ticket and date selection. A fully functional booking UI — ticket type, a live calendar, a running cart total — builds trust before payment is ever mentioned. Nothing here looks like a scam; it looks like normal e-commerce.
Fake payment gateway page for Grand Egyptian Museum tickets, total EGP 100, with a card-details form requesting cardholder name, card number, expiry and CVV.
Step 3 — the card-capture form. A third-party-branded "payment gateway" lists the museum by name, an invoice ID (redacted here), and the total, then asks for a full card number, expiry, and CVV — everything needed to clone or resell the card.
Fake Mastercard ID Check screen asking for the 6-digit SMS one-time password, with merchant, amount, a redacted card number, and a countdown timer pressuring the visitor.
Step 4 — the fake OTP relay (the dangerous part). After the card, a spoofed Mastercard "ID Check" screen asks for the SMS one-time password banks use for 3-D Secure. This is not simple card skimming: a card number alone is often useless without this code, so the page is built to capture it too, in real time, while the countdown timer pressures the visitor to act before their actual bank session expires. Card digits redacted in this image; nothing was submitted.

This is the same technique underlying the AiTM (adversary-in-the-middle) session-theft patterns we've covered before: a stolen card and a live-captured OTP together can defeat standard payment verification, the same way a stolen password and a live-captured MFA code defeat standard login verification.

The infrastructure behind it

For all its brand sprawl, the operation rests on a small, findable set of servers — which is exactly why coordinated takedown is realistic.

  • Three anchor origins. A GoDaddy VPS at 92.205.28[.]211 hosted the bulk of the global-attractions domains (roughly 95). An IONOS server at 217.154.177[.]158 and a second host at 165.245.219[.]4 ran the European-museum brands (Louvre, Colosseum, Versailles, Uffizi, Musée d'Orsay, St Mark's) alongside Egyptian ones. A Moldovan VPS at 178.17.62[.]108 held a dedicated GEM cluster.
  • Edge fronting. Many domains hide behind Cloudflare (104.21.x / 172.67.x / 188.114.x), and the mega-host's parents were later moved behind AWS anycast (15.197.148[.]33, 3.33.130[.]190) — a reminder that the visible IP is often not the origin, and that exposed origins are the exception worth chasing.
  • Registration cluster. The Egyptian core concentrates on two registrars — NiceNIC International (8 domains) and CNOBIN (3) — with registrant countries recorded as Russia, China, and the United States. Others are scattered across MatBao, Name.com, Realtime Register, Metaregistrar, Eranet, and PDR, a common pattern for an operator spreading risk.

Why fake-ticket scams keep working

These sites succeed for reasons that have nothing to do with technical sophistication:

  • High-intent search. People actively want tickets to a famous, hard-to-book attraction, so a convincing result — organic or paid — gets the click. A brand-new museum with pent-up demand is ideal.
  • Real branding. The pages reuse the venue's genuine photos, logo, and pricing, so nothing on the page looks off.
  • A transaction the victim initiated. Unlike a cold phishing email, the visitor came to buy. The request for a card is expected, which disarms the usual suspicion.
  • Domain camouflage. grandegyptianmuseumticket[.]com or egypt-tickets[.]co reads as plausibly official to someone who has never seen gem.eg.

The one signal that never lies is the domain in the address bar and where the money goes.

How travelers avoid it

  • Start at the official site, typed yourself. For GEM that is gem.eg. For any attraction, find the official domain via its verified social account or a search you scrutinize, not the first ad.
  • Distrust "authorized reseller" domains. <attraction>-tickets[.]com and tickets-<attraction>[.]co are the exact shape this operation uses. Real venues sell on their own domain or a small number of well-known platforms.
  • Be wary of paid search results and social ads for tickets to popular attractions; scam operators buy these aggressively.
  • Check the destination before paying. If the checkout domain does not match the venue's real website, stop.
  • Pay by card, not bank transfer, so you retain chargeback rights if a "ticket" never materializes.

What platforms, hosts, and registrars can do

Because the network concentrates on a few anchors, the defensive leverage is unusually good. Suspending the three anchor origins and the NiceNIC/CNOBIN registrations would collapse most of it at once, rather than playing whack-a-mole with 188 domains one at a time. Search engines and ad networks can deprioritize <attraction>-tickets lookalikes on high-intent queries, and the impersonated venues can push registrar and host abuse reports backed by the shared sge. fingerprint and hosting clusters. This is the routine, unglamorous work of brand protection: detect the lookalikes early, cluster them by shared infrastructure, and take down the infrastructure, not just the domain — the same approach we take in our IronToll and reservation-hijack investigations.

Indicators (defanged, representative)

Copy-paste blocks for detection engineering. We are not publishing all 188 domains here, but the origin IPs and the Egyptian core below are the useful starting points for blocklists and abuse reports. Captured 19–23 July 2026; the operation adds and drops domains continuously, so treat the origin IPs as the more durable indicator.

Origin / edge IPs — where the domains actually resolve, hidden behind Cloudflare/AWS for many of the brands above:

# Anchor origins (multi-domain hosts)
92.205.28.211    # GoDaddy — global attractions mega-host (~95 domains: UK, Dubai, Istanbul, Gulf)
217.154.177.158  # IONOS — European museums + GEM (Louvre, Colosseum, Duomo, Orsay, St Mark's)
165.245.219.4    # European museums + Egypt (Louvre, Versailles, Uffizi, egypt-monuments)
178.17.62.108    # Moldova — dedicated GEM cluster (7+ domains)
62.60.226.43     # Stark — egtcktsmuseum, gizatcktsmuseum

# AWS anycast fronting the mega-host's parent domains
15.197.148.33
3.33.130.190

# Smaller single/few-domain Egypt-GEM origins
103.57.249.244
95.85.239.39
196.251.107.112
185.177.239.52
188.93.233.239
165.22.192.213
91.92.34.209
85.192.40.144
217.76.52.0
195.35.60.30
13.32.99.56

# Cloudflare fronting (origin hidden) — ranges seen across many GEM domains
104.21.0.0/16
172.67.0.0/16
188.114.0.0/16

Grand Egyptian Museum domains (defanged, sample of 85 mapped):

egtcktsmuseum[.]com
gizatcktsmuseum[.]com
grandegyptianmuseumticket[.]com
tickets-grandegyptianmuseum[.]com
ticketsgem[.]com
ticketseg[.]com
egypt-tickets[.]co
grand-egyptian-museum[.]org
gem-museum[.]xyz
gemvisiteg[.]com
egyptian-museum-tickets[.]com
egyptian-museum-booking[.]com
egyptian-museum-ticket[.]com
egypt-monuments[.]com
egmuseum[.]com
egmuseum[.]org
egtoorstickt[.]com
eg-tickets[.]com
eg-visits[.]com
eg-order[.]online
egvisits[.]com
booking-gem[.]com
cairo-tickets[.]com
cairo-treasures[.]live
cairo-heritage[.]live
cairolayover[.]org
grandmuseum-egypt[.]com
grandmuseumegypt[.]com
grandmuseumeg[.]com
turquoisepyramidsgrandegyptianmuseum[.]com
museumofegypt[.]mom
egyptianmuseum[.]me

Other-brand parent domains (defanged, one per impersonated destination):

# European museums
lelouvreticket[.]com
lelouvrebillet[.]com
ilcolosseoticket[.]com
chateauversaillesticket[.]com
duomomilanoticket[.]com
museeorsay-billetterie[.]com
basilicadisanmarcoticket[.]com
uffizigalleries[.]com

# United Kingdom
london-tickets[.]uk
edinburgh-tickets[.]uk
birmingham-tickets[.]uk
stadium-tours-tickets[.]co.uk

# Dubai / UAE
dubai-parks-and-resorts-tickets[.]com
dubai-ticket[.]me
dubaii-tickets[.]com

# Istanbul / Turkey
istanbul-ticket[.]co

# Gulf
saudi-tickets[.]co
tickets-doha[.]co
oman-tickets[.]co

A note on precision: we deliberately excluded a genuine institution — the Rosicrucian Egyptian Museum in San Jose (egyptianmuseum.org) — that surfaced in the same brand searches but is unrelated, and we flagged a small number of ambiguous domains for manual review rather than publishing them as confirmed. Getting the false positives out matters as much as finding the true ones.

Sources

  • First-hand PhishEye passive-OSINT mapping, 19–23 July 2026 (whois, DNS, Certificate Transparency, urlscan.io, reverse-IP, abuse.ch).
  • Official reference: Grand Egyptian Museum, gem.eg.

FAQ

How can I buy Grand Egyptian Museum tickets safely? Only through the official site at gem.eg (tickets at tickets.gem.eg), typed into your browser yourself rather than reached through an ad or search result. Any other domain selling "GEM tickets" — especially names like grandegyptianmuseumticket or egypt-tickets — should be treated as unofficial until you have verified it against the museum's own channels.

What is the "Grand Egyptian Museum ticket scam"? A fake e-commerce site that impersonates the museum's official ticketing, reuses its real branding and prices, and takes your card for tickets that are never issued. We traced these lookalikes to a larger network that runs the same scheme against roughly 40 attractions worldwide.

Is this only about the Grand Egyptian Museum? No. GEM is the largest cluster we mapped, but the same operator impersonates the Louvre, the Colosseum, Versailles, the Uffizi, Dubai theme parks, Istanbul palaces, UK attractions and stadium tours, and Gulf venues — 188 domains across 10+ countries in total.

How do you know these domains are one operation? Shared infrastructure and tradecraft: many run on the same origin servers, they follow one naming template (a parent domain per destination with a subdomain per venue), and a common sge. subdomain marker appears across otherwise unrelated brands.

What should I do if I already paid one of these sites? Contact your bank or card issuer immediately to dispute the charge and, if possible, freeze or reissue the card. Keep the confirmation email and URL as evidence. Report the domain to the impersonated attraction and to your national fraud reporting service.

Does PhishEye interact with these scam sites? No. This investigation used passive OSINT only — public DNS, whois, Certificate Transparency, and scan databases. We did not submit data to, purchase from, or otherwise interact with any scam page, and all indicators are defanged.


About the authors

PhishEye Threat Research is the anti-phishing and digital-risk-protection team behind PhishEye. We hunt brand-impersonation infrastructure daily across passive DNS, Certificate Transparency, and newly-registered-domain feeds, cluster it by shared hosting and registration, and file the takedowns that follow. This investigation began with a handful of Grand Egyptian Museum lookalikes and expanded, through passive pivots alone, into a full map of a multi-country fake-ticket operation. Related first-hand work includes IronToll and our hotel reservation-hijack mapping.

Every indicator here was derived from public data and is defanged. We report confirmed infrastructure to the relevant hosts and registrars, exclude legitimate institutions that surface in the same searches, and do not publish victim data.

Impersonated by one of these domains, or want a lookalike monitored? Contact the team at [email protected].