Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cybersecurity Alert: Fake Traffic Ticket Portals Target Personal, Credit Card Data

A recent phishing campaign has emerged, targeting Canadian drivers by impersonating provincial traffic bureaus. This campaign employs "SEO poisoning" techniques to manipulate search engine rankings, causing fraudulent websites to appear above legitimate…

A recent phishing campaign has emerged, targeting Canadian drivers by impersonating provincial traffic bureaus. This campaign employs "SEO poisoning" techniques to manipulate search engine rankings, causing fraudulent websites to appear above legitimate government portals.

The campaign uses a deceptive "waiting room" feature to harvest sensitive Personally Identifiable Information (PII) and credit card details from victims. Attackers have successfully manipulated search engine results to make these fraudulent sites appear trustworthy.

Search queries such as "traffic ticket search portal government of Canada" reveal malicious domains ranking highly on major search engines. The URLs mimic legitimate provincial codes, such as /on/ for Ontario or /ab/ for Alberta, to deceive users.

Upon clicking a link, victims are redirected from a central landing page to a province-specific sub-page. These pages are designed to match the branding of local agencies in Ontario, Quebec, British Columbia, Alberta, Manitoba, and Saskatchewan.

A recent phishing campaign has emerged, targeting Canadian drivers by impersonating provincial traffic bureaus.
Leo Underwood · Thehackingpost

The "Waiting Room" and "Heartbeat" Mechanisms

The campaign employs a sophisticated technical kit that controls the victim’s experience in real-time. A "waiting room" tactic is used, where the victim's browser sends polling requests to the attacker’s server every two seconds. This allows attackers to control the user's experience, redirecting them based on server responses.

A "heartbeat" function pings the attacker’s server every second, confirming the victim's activity on the page. This feedback loop enables a seamless data theft process.

The attack is a multi-stage process. Initially, users are asked to enter a license plate number. All data entered is intercepted via JavaScript and sent to a backend controller. The site then demands additional personal data, including name, address, email, phone number, and date of birth.

Advertisement

To create urgency, the portal displays a fabricated "ticket amount." Finally, victims are led to a payment page where their credit card information is collected.

The campaign uses a cluster of domains registered primarily in late November 2025 through the registrar MAT BAO CORPORATION. All identified domains are hosted on the IP address 198.23.156.130 and consistently use "ticket" in their hostnames.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories