Technadu New QR Code Phishing Scams Target US Residents with Fake Traffic Violations
Article Content
- •Scammers are using QR codes in text messages to impersonate state courts and demand payments.
- •The phishing scheme targets multiple U.S. states, including New York and California.
- •Victims are led through a CAPTCHA to avoid detection before being redirected to fraudulent sites.
A new phishing campaign is targeting residents across multiple U.S. states with fraudulent 'Notice of Default' traffic violation text messages. These messages impersonate state courts and pressure recipients to scan a QR code that leads to a phishing site, demanding a $6.99 payment while stealing personal and financial information. The campaign has affected states including New York, California, North Carolina, Illinois, Virginia, Texas, Connecticut, and New Jersey. Unlike previous scams that used direct links, this variation incorporates images of fake court notices with embedded QR codes. After scanning the QR code, victims are redirected to an intermediary site that requires CAPTCHA validation to evade automated detection, before being sent to a phishing site impersonating state agencies like the DMV. The stolen data can be used for identity theft, financial fraud, and further phishing attacks. State agencies have reiterated that they do not solicit personal information via text messages.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…