Escudodigital Global Smishing Campaign Targets Drivers with Fake Traffic Fines
Article Content
- •Over 79,000 fraudulent SMS messages detected in a global smishing campaign.
- •Attackers impersonate transport authorities to create urgency and extract sensitive data.
- •No specific threat actor has been identified, but the campaign is highly coordinated.
Bitdefender Labs has identified a widespread smishing campaign affecting drivers in at least 12 countries, including the United States, Canada, Australia, and the United Kingdom. Between December 2025 and April 2026, over 79,000 fraudulent SMS messages and 31,900 malicious URLs were detected, with up to 40 distinct active campaigns. The messages impersonate transport authorities and toll operators, claiming unpaid fines or tolls, and create a sense of urgency with threats of legal action or additional fees. Victims are directed to fraudulent websites where they may be prompted to enter sensitive personal and banking information or download malware. The campaign is characterized by its use of multiple languages and sophisticated techniques to evade detection. Despite the scale and coordination of these attacks, no specific threat actor has been identified. Bitdefender recommends vigilance and caution when receiving such messages.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…