Traffic violation scams switch to QR codes in new phishing texts
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要快速浏览一下文章内容。看起来是关于骗子发送虚假的交通违规通知短信,伪装成美国各州法院。他们让收件人扫描一个二维码,链接到钓鱼网站,要求支付6.99美元,同时窃取个人信息。 接下来,文章提到这是2025年广泛发送的通行费违规和未付停车票诈骗的新变种。这次的新骗局是通过包含法院通知图片和嵌入二维码的短信进行的。扫描二维码后会跳转到一个需要解决验证码的中介网站,然后进入伪装成州DMV或其他机构的钓鱼网站,声称有未付的通行费或停车票。 最后,文章提醒用户不要理会来自未知号码或邮箱的支付请求,并指出州机构不会用短信索取个人信息或付款。 现在我要把这些信息浓缩到100字以内。重点包括:骗子发送假交通违规通知短信,伪装成法院;包含二维码链接到钓鱼网站;要求支付6.99美元并窃取信息;这是2025年诈骗的新变种;提醒用户不要理会此类信息。 可能还需要提到钓鱼网站如何运作,比如中介网站和验证码部分,但为了简洁可能需要省略。确保涵盖骗子的行为、钓鱼手法、金额、以及提醒部分。 最终总结应该是:骗子发送假交通违规通知短信,伪装成法院;包含二维码链接到钓鱼网站;要求支付6.99美元并窃取信息;这是2025年诈骗的新变种;提醒用户不要理会此类信息。 </think> 骗子发送伪装成美国各州法院的虚假“违约通知”短信,声称涉及交通违规,并要求受害者扫描二维码支付$6.99以解决所谓的未付费用。扫描二维码后会跳转至钓鱼网站,窃取个人信息和财务数据。这种骗局是2025年广泛传播的通行费违规和停车票诈骗的新变种。 2026-4-5 19:45:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:7 收藏

QR Code phishing

Scammers are sending fake "Notice of Default" traffic violation text messages impersonating state courts across the U.S., pressuring recipients to scan a QR code that leads to a phishing site demanding a $6.99 payment while stealing personal and financial information.

This is a new variation of the widely sent toll violation and unpaid parking ticket scams that users received in 2025, which claimed to be from state toll agencies.

This new campaign started a few weeks ago, with someone sharing a text targeting New York residents with BleepingComputer, and many other people reporting similar texts online for other states, including California, North Carolina, Illinois, Virginia, Texas, Connecticut, and New Jersey.

Unlike the previous campaign, which included a text message and links to phishing sites, this new variation instead includes an image of an alleged court notice with an embedded QR code.

"This notice constitutes a final and urgent warning regarding an outstanding traffic violation involving your registered vehicle within the State of New York," reads the fake court notice.

"This matter has now entered the formal enforcement stage."

Fake court notice about traffic violations
Fake court notice about traffic violations
Source: BleepingComputer

The text message shared with BleepingComputer claims to be from the "Criminal Court of the City of New York", stating that there is an unpaid parking or toll violation that must be paid immediately or the person must appear in court. Included are instructions to scan a QR code to settle the unpaid balances.

Scanning the QR code brings the targeted person to an intermediary site that first prompts you to solve a captcha to prove you are human. The QR codes and CAPTCHA are used to make it harder for automated security software and researchers to analyze the phishing campaign.

Solving the CAPTCHA redirects you to another phishing site that impersonates the state's DMV or another agency, claiming there is an unpaid toll or parking ticket. In all examples seen by BleepingComputer, this outstanding balance is $6.99.

For example, phishing sites that impersonate the New York DMV use the hostname "ny.gov-skd[.]org" or "ny.ofkhv[.]life".

Fake NY Department of Motor Vehicles phishing site
Fake NY Department of Motor Vehicles phishing site
Source: BleepingComputer

Clicking continue will take you to a page where you can enter your personal and credit card information to pay the alleged charge.

This form is used to steal your data, including your name, address, phone number, email address, and, eventually, your credit card information.

This information can then be used for a wide variety of malicious activities, including follow-on phishing attacks, financial fraud, identity theft, and the sale of your data to other threat actors.

As a general rule, if you receive a text from an unknown phone number or email address requesting payment of a bill, ignore it.

State agencies have repeatedly stated in response to these scams that they do not use text messages requesting personal information or payment information.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/traffic-violation-scams-switch-to-qr-codes-in-new-phishing-texts/
如有侵权请联系:admin#unsafe.sh