National cyber authorities in Croatia and Slovenia warned of an active SMS and iMessage phishing campaign that falsely tells recipients they owe traffic fines and must pay immediately through linked websites. In Croatia, CERT.hr said the messages direct users to fake pages mimicking the official ePrekršaji dispute-resolution portal, while police stressed that traffic fine notifications and payment requests are not sent by SMS. In Slovenia, SI-CERT reported that attackers impersonated the police and the Ministry of the Interior, claiming victims owed a €39 road-traffic penalty and pushing them to newly registered phishing domains.
The Slovenian campaign rapidly scaled, with roughly 100 different URLs observed across unique newly registered domains, and victims who entered payment-card details saw them abused almost immediately for high-value online purchases. SI-CERT said the operation later expanded to additional lures involving unpaid income-tax prepayments and undelivered packages, with matching indicators suggesting the same actors were behind all variants. Both agencies urged citizens not to click links, reply to the messages, or submit personal or financial information to the fraudulent sites.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
VJ CSIRT warned of a phishing and smishing campaign targeting Slovak citizens with SMS messages impersonating services under Slovakia’s Ministry of Interior and claiming a traffic fine must be paid. The fraudulent sites collected a vehicle registration number, displayed a fake speeding offense, and attempted to steal payment card data; the identified domains shared registrar and infrastructure characteristics suggesting a unified operation.
The phishing operation expanded beyond traffic fines to impersonate the Financial Administration of the Republic of Slovenia over unpaid income tax prepayment and a delivery service over an undelivered package. SI-CERT assessed from matching indicators of compromise that the same attackers were behind all variants.
By this date, the attackers had used about 100 different URLs in the Slovenian traffic-fine phishing campaign, with each URL hosted on a unique newly registered domain. Victims who submitted card details had them immediately abused for high-value online purchases.
A large-scale phishing campaign in Slovenia began using fake iMessage messages from foreign phone numbers that impersonated the police or Ministry of the Interior. The messages pushed recipients to pay a supposed €39 traffic fine through newly registered phishing domains that harvested payment card data.
Croatia's National CERT warned of an ongoing SMS phishing campaign that falsely claimed recipients had committed traffic violations and needed to pay fines. CERT said it had received multiple citizen reports and identified two fraudulent website variants mimicking the official ePrekršaji portal to steal personal and financial data.
VJ CSIRT warned of a phishing and smishing campaign in Slovakia that used stickers or flyers placed on parked vehicles, claiming a traffic offense and directing victims via QR codes to fraudulent sites. The campaign impersonated Slovak government services, prompted victims for personal data and SMS verification, and then demanded payment of a fake fine; CSIRT identified platbymvsr[.]sk, platby-mvsr[.]sk, and sk-slovensko[.]web[.]app as related sites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecert.si
Open sourcecert.hr
Open sourcecsirt.sk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.