#smishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #smishing, aggregated by home.social.
-
What communities / forums discuss #PhoneSpam?
I'm looking for serious discussion on telemarketing, robocalls, AI calls, and unsolicited voice or text comms generally. Here on the Fediverse or elsewhere.
I'm aware that the #FCC has / has had several recent rulemaking requests for comment. I'm afraid I've missed most such windows.
I'd like to know what's being tried, successfully or otherwise, throughout the world. The problem seems severe in the US presently, but I suspect it's growing elsewhere. AI will all but certainly open new avenues for abuse.
What hashtags are being used for discussion? Are there any Fediverse groups formed on the topic?
Reboosts greatly appreciated.
DM if you prefer, though I'd generally appreciate an open thread.
-
What communities / forums discuss #PhoneSpam?
I'm looking for serious discussion on telemarketing, robocalls, AI calls, and unsolicited voice or text comms generally. Here on the Fediverse or elsewhere.
I'm aware that the #FCC has / has had several recent rulemaking requests for comment. I'm afraid I've missed most such windows.
I'd like to know what's being tried, successfully or otherwise, throughout the world. The problem seems severe in the US presently, but I suspect it's growing elsewhere. AI will all but certainly open new avenues for abuse.
What hashtags are being used for discussion? Are there any Fediverse groups formed on the topic?
Reboosts greatly appreciated.
DM if you prefer, though I'd generally appreciate an open thread.
-
Even scam SMS are now using UK phone numbers.
This fake “parcel delivery” text came from a +44 number with a fake Evri link. Scammers clearly don’t care which country you’re in anymore—they’re targeting everyone.
Never click the link. Always verify through the courier’s official website or app.
#ScamAlert #Smishing #SMSScam #Phishing #CyberSecurity #OnlineSafety #Evri #Fraud #StaySafe #Scam
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
Don’t Troll the Scam Texts. You’re Only Helping the Scammers.
https://www.msn.com/en-us/money/general/don-t-troll-the-scam-texts-you-re-only-helping-the-scammers/ar-AA24i1NW #cybersecurity #scams #scambaiters #smishing #ignore #block #report -
⚠️ Právě teď se šíří vlna podvodných SMS zpráv, kde se útočníci vydávají za Policii ČR a požadují uhrazení pokuty přes odkaz. Jde o smishing. Neklikejte, nic nezadávejte a pamatujte: policie platby přes SMS nevymáhá.
-
⚠️ Právě teď se šíří vlna podvodných SMS zpráv, kde se útočníci vydávají za Policii ČR a požadují uhrazení pokuty přes odkaz. Jde o smishing. Neklikejte, nic nezadávejte a pamatujte: policie platby přes SMS nevymáhá.
-
Supuestos “mensajes urgentes” disparan casos de fraudes digitales, alerta UNED
La casa de enseñanza señala que las estafas a través de smishing se han convertido en “una de las principales amenazas digitales” en 2026.
La entrada Supuestos “mensajes urgentes” disparan casos de fraudes digitales, alerta UNED aparece primero en Semanario Universidad.#Ciberfraudes #Estafas #Fraudes #País #RolandoRojas #Smishing #Tecnología #Uned #UniversidadEstatalADistancia #ÚltimaHora
-
Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
Smishing campaigns targeting device owners
Pay‑as‑you‑go “unlocking” tools sold on Telegram
By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. https://www.infoblox.com/blog/threat-intelligence/lookalike-domains-expose-the-iphone-theft-economy/
#ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel
-
Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
Smishing campaigns targeting device owners
Pay‑as‑you‑go “unlocking” tools sold on Telegram
By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. https://www.infoblox.com/blog/threat-intelligence/lookalike-domains-expose-the-iphone-theft-economy/
#ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel
-
Mi è arrivato un sms truffa molto pericoloso, segnato come Nexi diceva hai chiesto autorizzazione a pagamento di 2500€ se non sei tu contatta questo numero...Ho visto i veri sms nexi erano diversi poi controllando online ho letto di questo tipo di truffa che fa presa sull'immediato bisogno di evitare una truffa contattando questo numero
#smishing -
Mi è arrivato un sms truffa molto pericoloso, segnato come Nexi diceva hai chiesto autorizzazione a pagamento di 2500€ se non sei tu contatta questo numero...Ho visto i veri sms nexi erano diversi poi controllando online ho letto di questo tipo di truffa che fa presa sull'immediato bisogno di evitare una truffa contattando questo numero
#smishing -
“the message appears to come from institutions, victims are more likely to trust it and tap the link sent to their phones… the targets are then routed to a website designed to steal their credentials or make them pay fraudulent charges. This is called #smishing, and the SMS blaster enables attackers to reach tens of thousands of potential victims directly, without going through official networks… bypass protections put in place by #telecom providers”
-
“the message appears to come from institutions, victims are more likely to trust it and tap the link sent to their phones… the targets are then routed to a website designed to steal their credentials or make them pay fraudulent charges. This is called #smishing, and the SMS blaster enables attackers to reach tens of thousands of potential victims directly, without going through official networks… bypass protections put in place by #telecom providers”
-
Show 4: The Digital Con Artist. Phishing today isn’t about hacking your computer it’s about hacking you. In this episode of The Geek and The Detective, Amy Lynn and Detective Derrick Stevens break down how scammers use fake profiles, urgent messages... #TheGeekAndTheDetective #Vishing #Smishing #MFA #CyberCrime #StaySafeOnline #TechSecurity #DigitalPrivacy #CyberAwareness https://www.amylynn.org/thegeekandthedetective
-
That "failed delivery" text isn't a mistake—it's a precision-engineered strike on your bank account. Stop playing guessing games with your mobile security and learn how the $5,000 package scam actually works. 📦🛡️
-
That "failed delivery" text isn't a mistake—it's a precision-engineered strike on your bank account. Stop playing guessing games with your mobile security and learn how the $5,000 package scam actually works. 📦🛡️
-
Gefälschte Paket-SMS: Wie ein Betrugs-Netzwerk in China Schutz findet
Hunderttausende Opfer gefälschter Paket-SMS gibt es weltweit. Der Schaden geht womöglich in die Milliarden. Recherchen des BR und internationaler Medien belegen: Die Betrüger agieren aus China - und die Volksrepublik lässt sie offenbar gewähren.
-
Gefälschte Paket-SMS: Wie ein Betrugs-Netzwerk in China Schutz findet
Hunderttausende Opfer gefälschter Paket-SMS gibt es weltweit. Der Schaden geht womöglich in die Milliarden. Recherchen des BR und internationaler Medien belegen: Die Betrüger agieren aus China - und die Volksrepublik lässt sie offenbar gewähren.
-
📱Smishing Slows, Quishing Quickens 🎣
Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨
North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑⚖️
We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!
Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.
For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣
We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.
Recent examples:
⛔ ahfgx[.]icu
⛔ euoyq[.]icu
⛔ htpze[.]icu
⛔ mwlaj[.]icuFriendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃♂️➡️
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing
-
📱Smishing Slows, Quishing Quickens 🎣
Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨
North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑⚖️
We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!
Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.
For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣
We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.
Recent examples:
⛔ ahfgx[.]icu
⛔ euoyq[.]icu
⛔ htpze[.]icu
⛔ mwlaj[.]icuFriendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃♂️➡️
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing
-
Smishing: O que é e como proteger a sua empresa de SMS fraudulentos
Saiba como identificar mensagens falsas e evitar que cibercriminosos acedam aos dados da s
https://pme.pt/smishing-o-que-e-e-como-proteger-a-sua-empresa-de-sms-fraudulentos/
#PME #Smishing -
#Smishing ➡️ El SMS con el que no te quieres encontrar ➡️ Los #Ciberataques empiezan con un clic en el lugar equivocado. ¿Qué debemos hacer para protegernos?
-
Fate attenzione!
È in corso una #truffa via SMS #smishing che sfrutta il nome Nexi (ma anche altre agenzie) per esfiltrare dati bancari.Messaggi allarmanti segnalano falsi pagamenti, invitando a cliccare su link o richiamare numeri per bloccare i (finti) pagamenti notificati. Nella interazione si finisce su pagine di #phishing o a parlare con truffatori che chiedono codici OTP e credenziali.
Non cliccate su niente, non richiamate nessuno, cancellate e bloccate!
-
Fate attenzione!
È in corso una #truffa via SMS #smishing che sfrutta il nome Nexi (ma anche altre agenzie) per esfiltrare dati bancari.Messaggi allarmanti segnalano falsi pagamenti, invitando a cliccare su link o richiamare numeri per bloccare i (finti) pagamenti notificati. Nella interazione si finisce su pagine di #phishing o a parlare con truffatori che chiedono codici OTP e credenziali.
Non cliccate su niente, non richiamate nessuno, cancellate e bloccate!
-
⚠️ Smishing alert for Greek citizens. 💳 🚨
Scammers are pushing fake AADE (Independent Authority for Public Revenue) “unpaid taxes” SMS that lead to cloned payment pages designed to steal credit‑card info. If a text suddenly demands urgent payment, treat it like a pop‑up from nowhere—don’t click, don’t trust, don’t pay. Share to protect others.mycargr[.]com
aadcar[.]com
aadgee[.]com
aadgre[.]com#CyberThreatIntel #Infoblox #DNS #ThreatResearch #phishing #smishing #Cybercrime #AADE #Greece
-
⚠️ Smishing alert for Greek citizens. 💳 🚨
Scammers are pushing fake AADE (Independent Authority for Public Revenue) “unpaid taxes” SMS that lead to cloned payment pages designed to steal credit‑card info. If a text suddenly demands urgent payment, treat it like a pop‑up from nowhere—don’t click, don’t trust, don’t pay. Share to protect others.mycargr[.]com
aadcar[.]com
aadgee[.]com
aadgre[.]com#CyberThreatIntel #Infoblox #DNS #ThreatResearch #phishing #smishing #Cybercrime #AADE #Greece
-
Greek police arrested scammers using a fake cell tower for SMS phishing.
Phones were forced onto insecure 2G networks to harvest data and send bank-themed smishing.
Thoughts?
-
Greek police arrested scammers using a fake cell tower for SMS phishing.
Phones were forced onto insecure 2G networks to harvest data and send bank-themed smishing.
Thoughts?
-
Smishing Triad campaign observed via SMS phishing with typical toll payment-themed lure.
Smishing URL: illinois.gov-xiv[.]cc/diot/
Domain Name: gov-xiv.cc
Registrar WHOIS Server: grs-whois.aliyun.com
Registrar URL: alibabacloud[.]com
Updated Date: 2026-01-15T12:52:19Z
Creation Date: 2026-01-15T12:52:19Z
Registrar Registration Expiration Date: 2027-01-15T12:52:19Z
Registrar: Dominet (HK) Limited
Registrar IANA ID: 3775
Registrant State/Province: MA
Registrant Country: UShttps://urlscan.io/result/019bc36c-44b6-72a6-8b52-af8935ec1893/#summary
URLScan submission requires a mobile user-agent string to return the actual phishing page. In this instance, the page loads an IDOT-themed outstanding toll payment due of $6.99. Phishing ends with payment card theft.
Examining HTTP image requests, the page illinois.gov-xiv[.]cc/diot/ requests BHcjXi3x.gif which appears to be unique. The threat group appears to be reusing BHcjXi3x.gif across its phishing campaigns based on URLScan.io analysis of the resource hash 7515437df23c4af47700948c1650f0f9460da07e86a9447d33cfda1f36c91052. Sub-domain/SLD naming patterns include not just US/Canada toll payment, but US state comptroller refund status updates, USPS failed delivery notifications, and UK government fuel payment notifications. Majority of domains are hosted via US - AS132203 (TENCENT-NET-AP-CN Tencent Building, Kejizhongyi Avenue, CN).
illinois.gov-xiv[.]cc/diot/static/BHcjXi3x.gif
Requested by
Host: illinois.gov-xiv.cc
URL: illinois.gov-xiv[.]cc/diot/
Main IP: 43.153.98.107
Resource Hash: 7515437df23c4af47700948c1650f0f9460da07e86a9447d33cfda1f36c91052
Location: Santa Clara, United States
Owner: TENCENT-NET-AP-CN Tencent Building, Kejizhongyi Avenue, CN.
TLS certificate: Issued by R13 January 15th 2026
Valid for: 3 months.Regular expression pattern to identify smishing triad domains:
.+\.((gov|mobile)-?[a-z]{2,}|pay.+|re(f|v)[a-z]{2,}|revenue-.+|t(e|a)?x.+|mdot-.+|.+safedriving((gov)?.+)?|com-(pay)?.+|(.+-)?gov-?[a-z]{2,}|dmv.+|uk-.+|gui-.+|packages-.+)\.(cc|city|men|bid|mom|icu|digital|vip|shop|life|xyz|cfd|cyou|xin|top|help|bond|win|info|my|works?|live|loan|wang|fyi|pro|date|email)(\/(rmv|diot|pay|mvc|us|tax|notice|refund|uk|portal))?Google brought claims under the Racketeer Influenced and Corrupt Organizations, or RICO, Act, the Lanham Act, and the Computer Fraud and Abuse Act, or CFAA, and is seeking to dismantle Smishing Triad and the Lighthouse platform.
https://www.cnbc.com/2025/11/12/google-e-zpass-usps-text-scam-phishing-suit.html
https://www.resecurity.com/blog/article/smishing-triad-targeted-usps-and-us-citizens-for-data-theft
-
Smishy New Year: Fake Rewards, Real Scams!
Redeemed those "expiring" cell network reward points and awaiting your shiny new iPad or cash rebate?
⚠️📵 Think again. There's a catch - and your payment card details are on the hook! 🎣 💳
Cell phone users in North America are getting hit with yet another wave of smishing campaigns, likely orchestrated by Chinese-speaking threat actors. This campaign builds on previous toll scams, evolving tactics and expanding targets. Over the holidays and well into the New Year, a barrage of SMS messages have posed as banks and cell phone networks, dangling phishing links to bait customers with fake points and high value rewards about to expire.
Talk about FOMO! 💰🤑
But you already know how this one plays out. Victims are prompted to enter payment details for “verification” or “shipping” and the only ones being rewarded are those taking the payments.
We uncovered thousands of these nefarious domains through their use of Registered Domain Generation Algorithms (RDGAs) and brand impersonation, hosted across a diverse range of hosting providers to evade takedown.
Recent examples:
⛔ anzrewardsprogram2026d[.]cc
⛔ <brand>.dvqlp[.]icu
⛔ <brand>.outdz[.]icu
⛔ <brand>.xqufa[.]cc
⛔ <brand>rewards.734726[.]comWe suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving the tradecraft used in smishing delivery. As for us, we'll keep tracking til we get that iPad... 🙈
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #telecom #china
-
Smishy New Year: Fake Rewards, Real Scams!
Redeemed those "expiring" cell network reward points and awaiting your shiny new iPad or cash rebate?
⚠️📵 Think again. There's a catch - and your payment card details are on the hook! 🎣 💳
Cell phone users in North America are getting hit with yet another wave of smishing campaigns, likely orchestrated by Chinese-speaking threat actors. This campaign builds on previous toll scams, evolving tactics and expanding targets. Over the holidays and well into the New Year, a barrage of SMS messages have posed as banks and cell phone networks, dangling phishing links to bait customers with fake points and high value rewards about to expire.
Talk about FOMO! 💰🤑
But you already know how this one plays out. Victims are prompted to enter payment details for “verification” or “shipping” and the only ones being rewarded are those taking the payments.
We uncovered thousands of these nefarious domains through their use of Registered Domain Generation Algorithms (RDGAs) and brand impersonation, hosted across a diverse range of hosting providers to evade takedown.
Recent examples:
⛔ anzrewardsprogram2026d[.]cc
⛔ <brand>.dvqlp[.]icu
⛔ <brand>.outdz[.]icu
⛔ <brand>.xqufa[.]cc
⛔ <brand>rewards.734726[.]comWe suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving the tradecraft used in smishing delivery. As for us, we'll keep tracking til we get that iPad... 🙈
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #telecom #china
-
Olha um novo esquema fraudulento sobre supostos desalfandegamentos de encomendas #CTT, por SMS.
Mais alguém recebeu?
-
Olha um novo esquema fraudulento sobre supostos desalfandegamentos de encomendas #CTT, por SMS.
Mais alguém recebeu?
-
-
Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users https://thecyberexpress.com/coupang-ceo-resigns-amid-data-leak/ #SouthKoreaCybersecurity #TheCyberExpressNews #CoupangCEOResigns #Coupangdatabreach #TheCyberExpress #FirewallDaily #BusinessNews #CoupangInc #CyberNews #Features #Phishing #smishing