Fake parking SMS messages – police in Podkarpackie warn of phishing

Criminals are distributing SMS messages with links to fake parking payment pages. Clicking the link risks immediate loss of funds from the account.

Fake parking SMS messages – police in Podkarpackie warn of phishing

Phishing targeting drivers – SMS about unpaid parking used to steal card data

Podkarpacka.policja.gov.pl is warning of a new wave of fraud targeting drivers. The CERT Poland database and police units are receiving reports of fake SMS messages in which criminals impersonate operators of municipal paid parking zones.

The modus operandi is based on time pressure. The recipient receives a message demanding payment of alleged parking arrears. The SMS contains an active link purportedly leading to a quick-payment panel. After clicking, a page appears that is visually almost identical to the official operator website – in reality created entirely by fraudsters.

On the fake website, criminals demand the vehicle registration number, personal data and full payment card details. Obtaining the registration number allows them to personalise subsequent attacks, making them appear credible. Entering card data results in immediate emptying of the victim's bank account.

Bypassing smartphone security – a warning sign

Police draw attention to a characteristic element of the campaign: fraudsters are actively attempting to circumvent the built-in security mechanisms of modern phones. In SMS messages, they ask recipients to send any reply or to manually copy and paste the website address into a browser window, which is intended to prevent automatic detection of the malicious link.

As police emphasise, legitimate parking zone operators never encourage users to disable or circumvent phone system security features.

What to do after receiving a suspicious SMS?

The received message – in its unchanged form – should be forwarded to the free national number 8080, operated by CERT Poland. Reports can also be filed via the form on the incydent.cert.pl website or through the government mObywatel application in the "Safe Online" tab.

If payment card data has already been entered on the suspicious website, police recommend immediate contact with the bank's helpline and blocking the card. The message content, link and screenshots should be preserved – they constitute key evidence when filing a report of a crime at the nearest police unit.

The warning was prepared by the Cybercrime Combat Division of the Regional Police Headquarters in Rzeszów based on alerts from the CERT Poland team.

Source: Google News PL — Crime (pl)

Read this article in the original language