Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cybercriminals Exploit Canadians’ Dependence on Digital Services in Widespread Attacks

Canadian citizens are experiencing a coordinated phishing campaign that exploits government impersonation and brand spoofing to collect personal and financial data extensively.

Canadian citizens are experiencing a coordinated phishing campaign that exploits government impersonation and brand spoofing to collect personal and financial data extensively.

The campaign is associated with PayTool, a phishing-as-a-service ecosystem known for its traffic violation scams targeting Canadians via SMS.

In addition to traffic fines, fraudulent entities are impersonating the Canada Revenue Agency (CRA), Air Canada, and Canada Post, suggesting a broader operation utilizing shared design templates and infrastructure.

Victims receive SMS messages and malicious advertisements using urgent tactics related to unpaid fines, failed deliveries, or booking errors. URLs use shorteners and typosquatted domains to appear legitimate.

Upon clicking, users are led through a "fake validation" phase, which requests ticket numbers or booking references that accept any input without actual verification.

Security researchers at CloudSEK have identified multiple fraud clusters exploiting traffic enforcement, tax refunds, airline bookings, and parcel delivery services—areas where Canadians commonly exchange sensitive information online.

This step is followed by a fraudulent payment gateway designed to gather personally identifiable information (PII), banking credentials, and payment data.

Over 70 websites resolved to IP address 198.23.156.130, impersonating canada.ca as a "Traffic Ticket Search Portal – Government of Canada."

This federal-level portrayal reduces victim suspicion while allowing rapid scalability across provinces. Domain patterns exhibit systematic naming conventions (ticket, traffic, portal, search, violation, infraction), indicating bulk automation rather than organic creation.

Province Observed Domains

The campaign is associated with PayTool, a phishing-as-a-service ecosystem known for its traffic violation scams targeting Canadians via SMS.
Benjamin Scott · Thehackingpost

British Columbia paytool-bc-2025[.]com, bc-infraction[.]com

Ontario ontarioticketpay[.]live, ontario-paytool-2025[.]com

Quebec ville-montreal-pay[.]com, amende-enligne-qc[.]com

The 45.156.87.0/24 subnet hosts payment phishing infrastructure, with key nodes at 45.156.87.145, 45.156.87.131, and 45.156.87.143.

When specific provincial domains are blacklisted, threat actors reroute traffic to generic fallback domains (parking-portal[.]live, overdueticketinfraction[.]info) to maintain campaign continuity.

Air Canada impersonation utilizes typosquatting and SEO poisoning through character omission (aircanda-booking[.]com), duplication, and substitution.

These sites replicate favicon hashes and page titles from legitimate Air Canada infrastructure, intercepting users who mistype domains or click malicious ads.

Advertisement

Threat actor 'theghostorder01' actively sells phishing kits on dark web forums, offering the capability to collect names, addresses, banking credentials, and Interac e-Transfer logins.

During interactions, the seller was unable to demonstrate any server-side data handling or hosted infrastructure.

The actor facilitates sales via Telegram channels, accepting USDT (TRC-20) and Bitcoin payments.

When questioned about data capture infrastructure, the seller provided vague responses about email delivery.

This implies minimal technical sophistication on the seller’s part, with buyers using generative AI tools to script backend logic and real-time data exfiltration via APIs—a capability requiring minimal technical skill.

Organizations should enforce proactive domain monitoring for keyword-based typosquatting and initiate rapid takedowns.

DNS and web gateways should block suspicious TLDs (.live, .info) and known PayTool IP ranges. Public awareness campaigns should emphasize that government agencies and airlines do not request sensitive data via SMS links.

Users are advised to access services only through official bookmarked portals rather than links in messages or advertisements.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories