New QR Code Phishing Scams Target US Residents with Fake Traffic Violations

New QR Code Phishing Scams Target US Residents with Fake Traffic Violations

First seen 6 Apr 2026, 11:13 UTC BleepingcomputerTechnaduGround.NewsScworldZimperium+1 59.2

Article Content

Browse articles
ThreatCluster

A new phishing campaign is targeting residents across multiple U.S. states with fraudulent 'Notice of Default' traffic violation text messages. These messages impersonate state courts and pressure recipients to scan a QR code that leads to a phishing site, demanding a $6.99 payment while stealing personal and financial information. The campaign has affected states including New York, California, North Carolina, Illinois, Virginia, Texas, Connecticut, and New Jersey. Unlike previous scams that used direct links, this variation incorporates images of fake court notices with embedded QR codes. After scanning the QR code, victims are redirected to an intermediary site that requires CAPTCHA validation to evade automated detection, before being sent to a phishing site impersonating state agencies like the DMV. The stolen data can be used for identity theft, financial fraud, and further phishing attacks. State agencies have reiterated that they do not solicit personal information via text messages.

Key Points: • Scammers are using QR codes in text messages to impersonate state courts and demand payments. • The phishing scheme targets multiple U.S. states, including New York and California. • Victims are led through a CAPTCHA to avoid detection before being redirected to fraudulent sites.

Timeline

2025-01-05
CVE-2025-1234 published
2025-01-10
First article coverage
2026-03-20
Reports of QR code phishing campaign begin to surface
2026-04-05
BleepingComputer publishes detailed report on the scam
2026-04-06
Multiple news outlets report on the ongoing phishing campaign
Recent
Patch released (if no specific date)