PHISHCA
Cybercriminals routinely target Canadians with phishing lures -- often via text messages (also known as "smishing") -- impersonating financial institutions, government entities, telecommunications and other companies. Their goal is to steal banking or credit card data as well as other personal identification information in order to perpetrate fraud or sell this data to other fraudsters.

PHISHCA identifies and analyzes phishing threats targeting Canadians.

BLOG
RBC / Apple Pay Phish

Apr 03, 2024

phish sms rbc apple

We recently received an RBC / Apple Pay phish that directed recipients to a spoofed RBC login page. The SMS suggested that Apple Pay had been added to "Andrew's IPhone" and encouraged recipients to click the phishing link if this information was incorrect. The subdomain of the domain data-en[.]fr contains "rbc-online-banking" in an attempt to appear legitimate.

read more

Netflix SMS Phishing Campaign

Mar 04, 2024

phish sms netflix

A recent SMS phishing campaign spoofed Netflix and encouraged recipients to click a fake link and login to a Netflix-themed phishing page. The domain itself contains a misspelling of "netflix". When the link is clicked, the recipient is presented with a Captcha, after solving it a fake Netflix login page is shown.

read more

USPS SMS Phishing Campaign In Canada

Feb 28, 2024

phish sms usps

USPS delivers to Canada, so fraudsters are conducting SMS phishing campaigns against Canadians. We spotted this campaign spoofing USPS which informs the recipient that a package cannot be delivered. It also includes instructions that cause the link in the text to become clickable. Responding with a "Y" causes the link to become hyperlinked, and the user can click the link rather than try and copy 'n paste the link into their browser.

This may also allow the threat actors to know that the receiving phone number is valid, so that they can continue to send messages to that recipient.

 

read more

Phish URL Date Info
https://rbc-online-banking.data-en.fr/ 2024-04-03 Details
https://data-en.fr/ 2024-04-03 Details
https://myaccoun1tnetflfixssl.info/ 2024-02-23 Details
https://post-mersue8.top/LNiPt7/ 2024-02-27 Details