Fake Serbian Traffic-Fine Texts Lead to a Cloned Road-Authority Checkout

A text says a traffic fine is unpaid. The amount is specific, the deadline is close, and the link appears to belong to a road authority.

If you have driven recently, the easiest reaction is to check before the fee rises. That small moment of uncertainty is what the message exploits.

Authentic screenshots of Serbian-language fake traffic-fine texts used in a road-authority phishing campaign

Overview

The message that starts it

People in Serbia received SMS messages claiming they owed a traffic fine. Some versions warned that a penalty or added charge would follow if they delayed payment.

The messages used Serbian text and link names designed to look connected to the country’s road system. A precise amount made the notice feel like a recorded case.

Neither an amount nor a deadline proves a violation exists. The text was an unsolicited route to a fraudulent payment page.

The page behind the link

Group-IB’s investigation captured websites impersonating Putevi Srbije, Serbia’s state road authority. They used familiar colors, logos, and payment language.

Some screens displayed made-up case references and timestamps. The flow asked for personal details and then card number, expiration date, and security code.

The road authority’s identity was being abused. The authority was not operating the fake websites or asking people to pay through those links.

What the evidence does not establish

The investigators did not publish a verified recipient total or a confirmed loss figure for this campaign. A person receiving a text should not infer that everyone nearby got one.

Some technical features matched patterns associated with Darcula and Phoenix phishing services. That is not a definitive attribution of every domain to either service.

The central facts are clear without overstating those connections:

  • The SMS claimed a traffic payment was due.
  • The supplied link led to an impersonation site.
  • The site requested personal and card information.
  • The real road authority was the borrowed identity.
  • The number of successful card thefts was not publicly established.

Why a Small Fine Is a Strong Hook

A message demanding an enormous transfer may be easy to dismiss. A small traffic fine feels more plausible and less worth a long investigation.

The example texts showed a specific amount in dinars. That detail made the demand resemble an administrative record rather than a generic scam blast.

The threatening part came next. The message suggested that delay would bring higher charges or another consequence, turning a modest amount into a time-sensitive decision.

People may also feel unsure whether a camera, parking system, or road authority can issue a notice without speaking to them first.

The scam does not need to answer that question accurately. It needs the recipient to settle the anxiety by visiting the link.

A convincing notice usually combines a familiar institution with an unfamiliar payment route. The borrowed logo and local language do the work before the card form appears.

Visitors who stop to check the exact domain may notice that it is not the agency’s published address. That is why the message creates a deadline.

How the Serbian Traffic-Fine SMS Scam Works

Step 1: A text claims a recorded violation

The recipient sees a short Serbian-language notification about an unpaid fine. Some versions appear to come from a police or road-related service.

The message gives an amount and may warn of extra cost if payment is not made quickly. Those details are designed to make a spontaneous click feel sensible.

The link is the decisive element. It directs the recipient away from any official channel they might otherwise open independently.

Step 2: The link opens a cloned authority page

The destination looks like a public service website. It uses colors, navigation, and labels resembling the real road authority’s online presence.

In one captured page, a form requested a phone number. The page also displayed road and toll-service sections to make the screen feel normal.

A visitor can mistake familiar layout for official ownership. Copying a public-facing website is easier than creating a legitimate government payment record.

Step 3: The case becomes more specific

Later screens can display a case reference, a time, and a supposed violation record. These details appear to answer the question the recipient had.

Yet the numbers come from the same suspicious site that made the allegation. They have not been checked against the authority’s own records.

Some pages stress that payment must happen before a deadline. This shortens the window in which a cautious visitor might call the authority.

Step 4: The site requests card information

The fake checkout asks for a card number, expiration date, and security code. That is the point where the invented fine becomes a financial-data theft attempt.

Group-IB identified the payment page as a phishing destination. Entered details can be sent to the operators rather than paying a genuine penalty.

Even if the amount on the screen is tiny, the card details can be useful for other unauthorized payments. The demanded fee is not the only risk.

Authentic screenshot of a cloned Serbian road-authority page reached from a fake fine text

Step 5: The site makes inspection harder

Researchers found that some pages stored visible text in encoded form and displayed it using JavaScript after the page loaded.

That matters because a simple scanner reading the raw HTML might not see the same text a person sees in a browser.

It can slow automated detection and takedown, especially when operators rotate domains. It does not make the demand legitimate.

The victim still sees an urgent fine and a payment form. The technical concealment is aimed at defenders, not at making a real case file.

What the Darcula and Phoenix Links Really Mean

Group-IB compared parts of the Serbian infrastructure with characteristics previously documented for Darcula, a phishing-as-a-service ecosystem with many ready-made templates.

It also found a subset of domains consistent with Phoenix, another platform connected to international smishing operations. Those are technical similarities, not a court finding.

For a reader, the names are less important than the implication: fake fine pages can be assembled and replaced quickly with shared tools.

A takedown of one address might only create a brief pause. New messages can lead to new domains while keeping the same fine-payment story.

It would be wrong to say every Serbian traffic text came from one named kit. It would also be wrong to treat the cloned page as a harmless mistake.

The request for card data under a false government identity is the confirmed scam mechanism.

The Detail That Turns a Notice Into a Trap

A real payment reminder should be traceable to an actual authority record. This campaign instead asked the recipient to accept the linked website as both the accuser and the collector.

That is a bad position for the reader. The page can invent the violation, choose the deadline, and show a checkout without proving any debt exists.

A convincing case reference does not solve the problem. If the reference appears only on the suspect site, you have no independent reason to trust it.

The first image shows how several text versions differ. One warns about an added charge; another mentions a driver’s license consequence.

The wording changes, but the pressure is consistent. Each version urges the recipient to resolve uncertainty by visiting a link chosen by the sender.

The second image shows why the page may feel credible after the click. It is structured like an ordinary portal, with familiar navigation and service sections.

Neither image is a payment instruction. They are captures of the fraudulent path documented by the researchers, included so readers recognize the shape of the lure.

The false portal asked for a phone number before later payment stages. That may seem like a harmless verification step, but it also ties information to the visit.

If a page already knows your alleged case, ask why it needs to build the story as you proceed. A real authority can confirm its record independently.

The campaign’s use of encoded page text is another clue about intent. Legitimate public-service portals do not need to hide the words “fine” and “payment” from scanners.

Encoding by itself is not proof of fraud. Here it sits alongside cloned branding, unsolicited SMS delivery, and a card-collection page.

Those pieces reinforce one another. The conclusion does not rest on a single awkward sentence or a suspicious-looking domain alone.

Be careful with screenshots shared in group chats. A friend may send the same text while asking whether it is real, accidentally spreading the link further.

Reply with the authority’s verified contact page instead. Avoid copying the scam URL into advice that others might tap by mistake.

If you are helping an older relative, ask whether they entered card details rather than only whether they “paid.” The page may collect data before a charge appears.

If you are helping someone who does not read Serbian, translate the warning but do not translate it into certainty. Language comprehension and sender verification are separate tasks.

A person can be careful and still click under pressure. The useful next question is what was entered, not why the link looked convincing.

That answer guides the response: close the page for a simple visit, contact the bank for card data, and escalate immediately for a banking code.

How to Check Whether a Fine Is Real

Do not start with the SMS link. Open the authority’s published website through a bookmark or type its known address after checking an independent source.

If you have a paper notice, use the payment instructions on that notice rather than the unsolicited text. A legitimate case should be traceable through normal channels.

Ask the relevant authority or your local police service how traffic penalties are notified and paid in your area. Procedures may differ by type of violation.

Do not trust a case number that appears only on the linked page. A fabricated number can be as convincing as a genuine one until checked separately.

Read the full web address, not just a word inside it. A domain containing a road agency’s name can still belong to a criminal.

Look for sudden changes from “notice” to “pay now.” The demand may reveal that the page’s real purpose is to collect a card.

If you are traveling, do not assume a text can identify a rental-car or foreign-driver fine accurately. Verify through the rental company and relevant authority independently.

When a text is in a language you only partly understand, take extra time. Automatic translation can help read it but cannot authenticate the sender.

Do not provide a bank code or app approval to finish a fine payment from a message link. Contact the bank if such a request appears.

A genuine authority should not object to you verifying a claim through its public contact details before paying.

What to Do if You Have Fallen Victim to This Scam

  1. Stop using the linked site. Do not retry a card after an error or enter a code sent by your bank.
  2. Call your card issuer. Explain that you entered card details on a fake road-authority page. Ask about blocking, replacement, and unauthorized charges.
  3. Mention any bank code. If you entered an SMS code or approved a transaction, the issuer needs that detail to investigate immediately.
  4. Check pending transactions. A small test charge can appear before a larger one. Dispute anything you did not authorize.
  5. Protect other information. If the page collected a phone number, ID detail, or password, ask the relevant provider what additional safeguards are appropriate.
  6. Save the evidence. Keep the SMS, sender, URL, screenshots, and bank notifications. Do not reopen the malicious site just to gather more.
  7. Report the fake notice. Tell Putevi Srbije or the authority being copied through official channels and report the SMS through your mobile provider.
  8. Scan after unexpected downloads. The documented flow centers on phishing. If you installed an app or file from it, run a reputable security scan such as Malwarebytes.
  9. Add link filtering. AdGuard can block some known phishing pages, but it should support, not replace, independent verification of official payments.

If a real fine also exists, handle it through the authority’s verified system. Paying a scam page does not settle an official obligation.

Anyone who contacts you later offering to recover the stolen payment for an advance fee should be treated with suspicion.

Frequently Asked Questions

Were the messages really from Putevi Srbije?

No. The documented campaign impersonated Serbia’s road authority. Verify any actual notice through its official website or contact channel.

Does the exact dinar amount prove a recorded fine?

No. A specific amount can be placed in a fraudulent SMS. The linked page’s own case details are not independent confirmation.

Can my card be at risk if the fake fine was small?

Yes. The site sought complete card details, not just the stated amount. Contact the issuer if you entered them.

Did researchers prove Darcula or Phoenix operated every page?

No. Group-IB reported infrastructure consistent with those platforms. Similar technical features do not establish a single operator for every domain.

Why might a security scanner miss the page?

Some analyzed pages encoded visible text and rendered it with JavaScript. A basic inspection of raw page code could miss what a person sees.

What if I only opened the text link?

Opening alone is different from submitting card data. Close the page, avoid downloads, and contact your bank if you supplied any information.

The Bottom Line

The fine exists inside the text and cloned page, not necessarily in any official record. The verified campaign used that claim to reach a card-collection form.

Do not pay from an unsolicited traffic message. Check the supposed violation through the authority’s real channels, and contact your bank quickly if you entered card details.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

M.whimsyard.com EXPOSED – Fake Store or Real? Read First

Next

Fake Software Download Pages Install Malware Behind Familiar Brand Names