Cybersecurity Alert: Fake Traffic Ticket Portals Target Personal, Credit Card Data
A recent phishing campaign has emerged, targeting Canadian drivers by impersonating provincial traffic bureaus. This campaign employs "SEO poisoning" techniques to manipulate search engine rankings, causing fraudulent websites to appear above legitimate…
A recent phishing campaign has emerged, targeting Canadian drivers by impersonating provincial traffic bureaus. This campaign employs "SEO poisoning" techniques to manipulate search engine rankings, causing fraudulent websites to appear above legitimate government portals.
The campaign uses a deceptive "waiting room" feature to harvest sensitive Personally Identifiable Information (PII) and credit card details from victims. Attackers have successfully manipulated search engine results to make these fraudulent sites appear trustworthy.
Search queries such as "traffic ticket search portal government of Canada" reveal malicious domains ranking highly on major search engines. The URLs mimic legitimate provincial codes, such as /on/ for Ontario or /ab/ for Alberta, to deceive users.
Upon clicking a link, victims are redirected from a central landing page to a province-specific sub-page. These pages are designed to match the branding of local agencies in Ontario, Quebec, British Columbia, Alberta, Manitoba, and Saskatchewan.
A recent phishing campaign has emerged, targeting Canadian drivers by impersonating provincial traffic bureaus.
The "Waiting Room" and "Heartbeat" Mechanisms
The campaign employs a sophisticated technical kit that controls the victim’s experience in real-time. A "waiting room" tactic is used, where the victim's browser sends polling requests to the attacker’s server every two seconds. This allows attackers to control the user's experience, redirecting them based on server responses.
A "heartbeat" function pings the attacker’s server every second, confirming the victim's activity on the page. This feedback loop enables a seamless data theft process.
The attack is a multi-stage process. Initially, users are asked to enter a license plate number. All data entered is intercepted via JavaScript and sent to a backend controller. The site then demands additional personal data, including name, address, email, phone number, and date of birth.
To create urgency, the portal displays a fabricated "ticket amount." Finally, victims are led to a payment page where their credit card information is collected.
The campaign uses a cluster of domains registered primarily in late November 2025 through the registrar MAT BAO CORPORATION. All identified domains are hosted on the IP address 198.23.156.130 and consistently use "ticket" in their hostnames.
Based on reporting by GBHackers.
