Cybercriminals Exploit Canadians’ Dependence on Digital Services in Widespread Attacks
Canadian citizens are experiencing a coordinated phishing campaign that exploits government impersonation and brand spoofing to collect personal and financial data extensively.
Canadian citizens are experiencing a coordinated phishing campaign that exploits government impersonation and brand spoofing to collect personal and financial data extensively.
The campaign is associated with PayTool, a phishing-as-a-service ecosystem known for its traffic violation scams targeting Canadians via SMS.
In addition to traffic fines, fraudulent entities are impersonating the Canada Revenue Agency (CRA), Air Canada, and Canada Post, suggesting a broader operation utilizing shared design templates and infrastructure.
Victims receive SMS messages and malicious advertisements using urgent tactics related to unpaid fines, failed deliveries, or booking errors. URLs use shorteners and typosquatted domains to appear legitimate.
Upon clicking, users are led through a "fake validation" phase, which requests ticket numbers or booking references that accept any input without actual verification.
Security researchers at CloudSEK have identified multiple fraud clusters exploiting traffic enforcement, tax refunds, airline bookings, and parcel delivery services—areas where Canadians commonly exchange sensitive information online.
This step is followed by a fraudulent payment gateway designed to gather personally identifiable information (PII), banking credentials, and payment data.
Over 70 websites resolved to IP address 198.23.156.130, impersonating canada.ca as a "Traffic Ticket Search Portal – Government of Canada."
This federal-level portrayal reduces victim suspicion while allowing rapid scalability across provinces. Domain patterns exhibit systematic naming conventions (ticket, traffic, portal, search, violation, infraction), indicating bulk automation rather than organic creation.
Province Observed Domains
The campaign is associated with PayTool, a phishing-as-a-service ecosystem known for its traffic violation scams targeting Canadians via SMS.
British Columbia paytool-bc-2025[.]com, bc-infraction[.]com
Ontario ontarioticketpay[.]live, ontario-paytool-2025[.]com
Quebec ville-montreal-pay[.]com, amende-enligne-qc[.]com
The 45.156.87.0/24 subnet hosts payment phishing infrastructure, with key nodes at 45.156.87.145, 45.156.87.131, and 45.156.87.143.
When specific provincial domains are blacklisted, threat actors reroute traffic to generic fallback domains (parking-portal[.]live, overdueticketinfraction[.]info) to maintain campaign continuity.
Air Canada impersonation utilizes typosquatting and SEO poisoning through character omission (aircanda-booking[.]com), duplication, and substitution.
These sites replicate favicon hashes and page titles from legitimate Air Canada infrastructure, intercepting users who mistype domains or click malicious ads.
Threat actor 'theghostorder01' actively sells phishing kits on dark web forums, offering the capability to collect names, addresses, banking credentials, and Interac e-Transfer logins.
During interactions, the seller was unable to demonstrate any server-side data handling or hosted infrastructure.
The actor facilitates sales via Telegram channels, accepting USDT (TRC-20) and Bitcoin payments.
When questioned about data capture infrastructure, the seller provided vague responses about email delivery.
This implies minimal technical sophistication on the seller’s part, with buyers using generative AI tools to script backend logic and real-time data exfiltration via APIs—a capability requiring minimal technical skill.
Organizations should enforce proactive domain monitoring for keyword-based typosquatting and initiate rapid takedowns.
DNS and web gateways should block suspicious TLDs (.live, .info) and known PayTool IP ranges. Public awareness campaigns should emphasize that government agencies and airlines do not request sensitive data via SMS links.
Users are advised to access services only through official bookmarked portals rather than links in messages or advertisements.
Based on reporting by GBHackers.
