SMS fraud with fake traffic fine spreading across Croatia and the region
Fraudulent SMS messages about unpaid traffic fines, sent from Philippine numbers, are circulating in Croatia. The National CERT recorded more than 1,100 cyber incidents in 2024, of which 58% were phishing attacks.

SMS fraud with fake "Croatian Traffic Authority" spreading to the region
A Reddit user posted a screenshot of an SMS message requesting payment of an allegedly unpaid traffic fine — and immediately warned that it was a scam. Večernji list reported that the message came from a telephone number with the +63 area code, which belongs to the Philippines, and the sender presented themselves as the "Croatian Traffic Authority" — an institution that does not exist.
The author of the post identified several red flags: a non-existent institution, a foreign area code, and a suspicious link leading to a server in Singapore. The case has been reported to the police.
Threats of late fees and account freezing
The message was written in a threatening tone. It invoked the Road Traffic Act and announced serious consequences in case of non-payment: collection of late fees, court enforcement including freezing of bank accounts, and entry into the National Credit Information Database.
This is a so-called "smishing" attack — a combination of SMS and phishing. The goal is to trigger panic in the recipient and persuade them to click on a fraudulent link and enter personal and banking information.
A regional campaign, not just Croatia
Users in the comments quickly recognised the fraud. One pointed out that elderly citizens are often the most vulnerable group. Another confirmed that identical messages are arriving in Montenegro, suggesting a wider regional campaign using different international numbers.
More than 1,100 incidents in 2024, damage of €7.9 million
According to data from the National CERT, more than 1,100 cyber incidents were handled in 2024, of which 58 per cent related to phishing. Financial damage from online fraud in the first half of 2023 amounted to €7.9 million. Fraudsters regularly impersonate the Croatian Post Office, delivery services, banks, or the Tax Authority.
Police: institutions never request information in this manner
The police have repeatedly warned that official institutions do not communicate in this way and do not request bank card details through suspicious links. Citizens are advised not to open links from unknown messages and to report suspicious cases to the police. Those who have already entered their information are recommended to contact their bank immediately to prevent further financial damage.
Source: Večernji list