
A significant cyber fraud scheme is currently taking advantage of the trust placed in India's traffic enforcement systems. Cybercriminals are deploying counterfeit e-Challan websites to extract sensitive financial details from unsuspecting vehicle owners. Recent insights from Cyble Research and Intelligence Labs (CRIL) highlight a transition from traditional malware attacks to highly convincing phishing tactics conducted through web browsers. This extensive scam has been linked to over 36 fraudulent websites that are actively deceiving users throughout India. Victims are receiving SMS notifications claiming they owe unpaid traffic fines, often accompanied by alarming warnings about potential license suspensions or legal repercussions, which pressure recipients to act immediately. Within the messages, a shortened link directs users to a fake website that closely mimics official portals of the Regional Transport Office (RTO) or e-Challan systems. Once there, victims are presented with fabricated violation details, usually featuring minor penalty amounts like ₹590 and imposing urgent deadlines. These details are generated in real-time, with no actual connection to any government database. The fraudulent websites deliberately limit payment methods to credit and debit cards, deliberately excluding UPI or net banking options that could be more easily traced. This design forces victims to input their complete card information, including CVV codes and expiration dates. To further deceive users, these sites falsely assert that transactions are processed through recognized Indian banks, enhancing their credibility. Even in instances of failed payments, the system remains functional, allowing multiple submissions from the same user, which enables attackers to collect several sets of card data. Investigators have discovered that the SMS messages originate from mobile numbers registered with Indian telecom providers, with some accounts tied to the State Bank of India. This localization strategy effectively increases the perceived legitimacy of the scam. CRIL emphasizes that this campaign is notably more advanced than previous efforts, relying on established trust in familiar institutions rather than purely technical exploits. An analysis of the backend infrastructure indicates that the same systems are utilized across various fraud campaigns, suggesting a well-coordinated and professional cybercrime network rather than isolated incidents. Additionally, researchers have identified advanced evasion techniques being employed, with many of the malicious domains still active, indicating that the scam is ongoing. Cybersecurity professionals are urging users to remain vigilant and exercise caution.
Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...
TechCrunch | Jul 25, 2026, 19:50
In a recent discussion surrounding the use of AI in software development, Linus Torvalds, the founder of Linux, voiced h...
Business Insider | Jul 26, 2026, 13:10As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...
Business Insider | Jul 26, 2026, 10:10In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...
Business Insider | Jul 25, 2026, 20:30Monday.com, the innovative work management platform based in Tel Aviv, has recently announced significant layoffs, attri...
TechCrunch | Jul 26, 2026, 01:45