{"id":420302,"date":"2026-09-28T16:14:27","date_gmt":"2026-09-28T16:14:27","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=420302"},"modified":"2026-09-28T16:14:27","modified_gmt":"2026-09-28T16:14:27","slug":"outsider-phishing-kit-fake-pages-steal-cards-codes","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/outsider-phishing-kit-fake-pages-steal-cards-codes\/","title":{"rendered":"Outsider Phishing Kit Built 100,000 Fake Pages to Steal Cards and Codes"},"content":{"rendered":"<p>A short message says a routine account or vehicle record needs attention today. The link looks official enough to tempt a quick check.<\/p><div id=\"mwtad594907933\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>For someone reading on the move, the easiest next step is to tap. That is precisely the moment this campaign is designed around.<\/p>\n<figure><img src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-sms.jpg\" class=\"wp-image-420303 skip-lazy\" width=\"738\" height=\"1600\" decoding=\"async\" loading=\"eager\" fetchpriority=\"high\" alt=\"Authentic screenshot of an LTA-impersonating text used in the Outsider phishing campaign\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-sms.jpg 738w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-sms-138x300.jpg 138w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-sms-472x1024.jpg 472w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-sms-708x1536.jpg 708w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/><\/figure>\n<div id=\"mwtad144035456\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>One message, many possible disguises<\/h3>\n<p>The Outsider phishing kit is a collection of ready-made fraudulent pages used by criminals to impersonate transport authorities, delivery services, banks, and other familiar organizations.<\/p><div id=\"mwtad3306191615\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>It is not a single text with a single web address. Operators can choose a template and send a link that fits the target country or brand.<\/p>\n<p>One documented example copied Singapore&#8217;s Land Transport Authority. It began with a vehicle-record warning and led toward personal details, payment data, and verification challenges.<\/p>\n<h3>What investigators counted<\/h3>\n<p><a href=\"https:\/\/www.group-ib.com\/blog\/chenlun-outsider-phaas-kit\/\" target=\"_blank\" rel=\"noopener\">Group-IB researchers<\/a> identified more than 100,000 related phishing pages from December 2025 through May 2026, using at least 267 templates across more than 54 countries.<\/p><div id=\"mwtad3504234681\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>They also observed more than 700 newly created pages within a month after a June 2026 legal and takedown effort. The kit remained active in their research.<\/p>\n<p>Those are counts of pages and templates, not confirmed victims. The number of people who lost money or submitted details was not established by those figures.<\/p>\n<h3>The verified scam mechanism<\/h3>\n<p>Group-IB captured an SMS lure, a copied authority page, a false fee, a card-entry page, and operator controls that could present different verification requests.<\/p><div id=\"mwtad3210629128\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The real organization named in a message is being impersonated. It is not responsible for the fraudulent page or payment demand.<\/p>\n<p>For readers, the warning signs look like this:<\/p>\n<ul>\n<li>A surprise text presses you to settle a fee or account issue immediately.<\/li>\n<li>The link resembles an official address but ends under a different domain.<\/li>\n<li>The page asks for a card, phone number, or bank verification code.<\/li>\n<li>An error screen or loading loop keeps you engaged.<\/li>\n<li>A real-looking brand does not match the web address.<\/li>\n<\/ul>\n<div id=\"mwtad3968300742\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Same Kit Can Reach So Many Countries<\/h2>\n<div id=\"mwtad678076628\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Outsider was built for reuse. Instead of creating a new scam site by hand each time, an operator can select a prepared page and adjust the impersonated organization.<\/p>\n<p>That turns local-sounding stories into a repeatable business model. A road fee in one country can become a parcel charge or loyalty warning somewhere else.<\/p>\n<p>The exact words and logos vary, so memorizing one version is not enough. The stable features are an unsolicited link, urgency, and a sensitive-data request.<\/p>\n<div id=\"mwtad552964428\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Group-IB found ready-made templates across transport, telecom, logistics, financial, and fine-payment themes. These categories cover situations many people encounter routinely.<\/p>\n<p>A person may not know whether a toll or package fee is outstanding. The message does not need to be certain; it only needs to make checking feel urgent.<\/p>\n<p>The kit&#8217;s scale also explains why takedowns are a moving target. Removing one domain does not prevent an operator from publishing another copy.<\/p>\n<div id=\"mwtad2874454958\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>That is not a reason to give up reporting. It is a reason to verify the claim through the real organization instead of trying to identify one dangerous URL.<\/p>\n<div id=\"mwtad589019478\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Outsider Phishing Scam Works<\/h2>\n<h3>Step 1: The text creates a deadline<\/h3>\n<p>In the captured Singapore example, the message claimed vehicle records needed confirmation by the end of the day. It presented a portal link as the solution.<\/p>\n<p>Some phones had already flagged the conversation as spam. The text told recipients how to copy the address or reply in ways that could defeat a blocked link.<\/p>\n<p>Instructions to bypass a phone&#8217;s warning are a serious red flag. An official agency does not need to teach people how to override spam protections.<\/p>\n<h3>Step 2: A copied page borrows official identity<\/h3>\n<p>The link opened a page styled to resemble Singapore&#8217;s transport authority. It asked for a vehicle registration number and phone number.<\/p>\n<p>That first request felt related to the text. The page did not need to collect a card immediately to establish a false sense of normal procedure.<\/p>\n<p>The authority&#8217;s name, colors, and portal language were props. The page was controlled by the scammers, not by the agency it copied.<\/p>\n<h3>Step 3: The page invents a payment problem<\/h3>\n<p>After the initial details, the victim was shown a supposed outstanding fee. Extra penalties created pressure to pay without checking through a separate channel.<\/p>\n<p>This escalation matters. The original text was about records, but the website moved the visitor into a payment request after gaining attention.<\/p>\n<p>A sudden fee inside an unfamiliar portal is not proof of a real obligation. The agency&#8217;s own site or phone line is the place to confirm it.<\/p>\n<h3>Step 4: The card form gathers financial details<\/h3>\n<p>The next page imitated a quick-payment checkout. It asked for a card number, expiration date, security code, and cardholder name.<\/p>\n<p>Group-IB reported that the page&#8217;s script transmitted entered information to an operator panel in real time, even before a final form submission.<\/p>\n<p>That detail changes the response. Closing the tab after typing a card number may not guarantee that the number stayed on your device.<\/p>\n<figure><img src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-420304 lazyload\" width=\"1999\" height=\"1080\" decoding=\"async\" loading=\"lazy\" alt=\"Authentic screenshot of a fraudulent payment page in the Outsider phishing flow\" title=\"\" sizes=\"auto, (max-width: 1999px) 100vw, 1999px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-payment.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-payment.png 1999w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-payment-300x162.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-payment-1024x553.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/outsider-payment-1536x830.png 1536w\"><\/figure>\n<h3>Step 5: The operator chooses a verification challenge<\/h3>\n<p>After card entry, the page could show a fake payment gateway. The operator had controls to present an SMS code, email code, PIN, or app confirmation.<\/p>\n<p>Those requests were not ordinary security checks. They were ways to capture whatever additional proof a real bank might demand for a payment.<\/p>\n<p>Because the operator could adapt, one victim might see different prompts from another. A single screenshot cannot represent every version of the kit.<\/p>\n<h3>Step 6: The page can ask again<\/h3>\n<p>The research also showed controls that could send a visitor back to the payment screen. That could be used to seek another card if the first failed.<\/p>\n<p>A failure message does not mean the previous details were rejected or erased. It may be a tactic to collect more data before the victim leaves.<\/p>\n<p>Stop at the first unexpected card or code request. Do not keep retrying on the theory that a successful payment will resolve the notice.<\/p>\n<div id=\"mwtad284189348\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Happened After the Takedown Effort<\/h2>\n<p>In June 2026, Google took legal action against the group described in this ecosystem, alongside a coordinated effort with law enforcement and infrastructure partners.<\/p>\n<p>Group-IB&#8217;s later observation of more than 700 new pages is important because it shows the activity did not simply end with that announcement.<\/p>\n<p>It does not mean each new page attracted a victim. It means the infrastructure could still be created after public disruption.<\/p>\n<p>The same distinction applies to the 100,000-page estimate. It is a measure of deployment scale, not a count of people defrauded.<\/p>\n<p>For the public, a legal action is welcome news but not an all-clear. A new text can still arrive under a different name or domain.<\/p>\n<div id=\"mwtad842646328\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Next Screen Can Change While You Wait<\/h2>\n<p>Many scam pages are fixed. You enter information, click a button, and receive the same confirmation as everyone else. Outsider offered a more flexible experience.<\/p>\n<p>Researchers described a live connection between the page and an operator panel. That meant the person running the campaign could watch activity and adjust the challenge.<\/p>\n<p>A payment page might first request card details. Then it could ask for an SMS code because the real bank issued one during an attempted transaction.<\/p>\n<p>Another visitor could see an email code or a request to approve something in a banking app. The exact prompt can depend on the institution&#8217;s rules.<\/p>\n<p>That flexibility is why a victim may feel the page understands their case. The apparent personalization is not evidence that an authority found a real fine.<\/p>\n<p>The operator can also show a loading screen while waiting for a real banking response. A pause that feels like processing may be part of the theft.<\/p>\n<p>Do not assume an error means the attempted charge failed. It might mean the operator needs a fresh code or wants another payment method.<\/p>\n<p>Group-IB found page naming conventions that corresponded to stages such as login, card payment, SMS verification, email, and PIN entry.<\/p>\n<p>Those names were useful to investigators. Readers do not need to memorize them; they need to recognize the movement from surprise notice to sensitive-data collection.<\/p>\n<p>The first request can be small. A registration number or phone number may feel harmless beside a card number, yet it prepares the next screen.<\/p>\n<p>It can also make the page seem responsive. Once you have invested time entering details, abandoning a supposed final payment may feel inconvenient.<\/p>\n<p>That is the point where a short pause helps. Ask whether you began this task yourself through an official channel or followed a stranger&#8217;s text.<\/p>\n<p>If the answer is the text, leave the page. You can always return through the real agency&#8217;s website if the fee genuinely exists.<\/p>\n<p>The real agency should be able to identify an actual case through its normal service channels. A page&#8217;s own case number proves nothing independently.<\/p>\n<p>Likewise, a real bank notification may be triggered by an attacker trying your card. The bank message is genuine, but the surrounding website remains fraudulent.<\/p>\n<p>Never tell the page a code just because it came from your bank. Call the bank and explain that an unexpected transaction or verification may be underway.<\/p>\n<p>This campaign&#8217;s exact templates may change. The step that matters is consistent: a message you did not request steers you away from a known channel.<\/p>\n<p>Keeping that distinction in mind is more durable than saving a list of bad domains, which can be replaced quickly.<\/p>\n<div id=\"mwtad3728341990\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check a Fee or Account Warning<\/h2>\n<p>Ignore the link inside the message. Search for the authority&#8217;s official website yourself or use a saved app you already know is genuine.<\/p>\n<p>For a road, parking, or toll claim, check whether the agency actually handles payments by text. Its published guidance may identify authorized channels.<\/p>\n<p>Do not trust the first search advertisement blindly. Criminals can buy ads, and a sponsored result is not an official government seal.<\/p>\n<p>Read the whole domain. A name containing an agency abbreviation may still end under a different, attacker-controlled address.<\/p>\n<p>If a phone flags a message as spam, do not follow instructions to copy the link or reply to unlock it. That bypasses a protective warning.<\/p>\n<p>If the page asks for a real bank code, stop. A fee notice should never need you to hand a fresh authentication code to an unfamiliar site.<\/p>\n<p>Ask the agency through a verified channel whether any debt exists. A case number printed on the suspicious page is not independent evidence.<\/p>\n<p>Talk to someone you trust if the threat feels urgent. A brief pause is useful when a text is designed to make you act before thinking.<\/p>\n<div id=\"mwtad4274560366\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Close the fraudulent page.<\/strong> Do not try another card or code. Save the text and address without opening the link again.<\/li>\n<li><strong>Contact your card issuer.<\/strong> Say you entered details on a fake payment page. Ask about blocking the card, replacement, and disputed transactions.<\/li>\n<li><strong>Tell the bank about any code or app approval.<\/strong> A submitted authentication code may have enabled a payment or account action even if no fee appeared.<\/li>\n<li><strong>Review account activity now.<\/strong> Look for pending and completed charges, new payees, or changes to your profile and contact information.<\/li>\n<li><strong>Secure exposed accounts.<\/strong> Change passwords if you entered them and revoke sessions or devices that you do not recognize.<\/li>\n<li><strong>Keep proof of the sequence.<\/strong> Preserve the message, sender, domain, screenshots, and bank alerts. This can help an issuer or agency investigate.<\/li>\n<li><strong>Report the impersonation.<\/strong> Notify the real agency named in the text and your mobile provider&#8217;s spam channel. Report financial fraud to local authorities.<\/li>\n<li><strong>Check for other exposure.<\/strong> If the page asked you to download anything, scan the device with a reputable product such as Malwarebytes.<\/li>\n<li><strong>Use link filtering as another layer.<\/strong> AdGuard may block some known malicious destinations, but it cannot make every unfamiliar text safe.<\/li>\n<\/ol>\n<p>Even if the card has not been charged, tell the issuer that the details were entered. The page may have captured them before you pressed a button.<\/p>\n<p>Recovery scammers sometimes contact victims after a report. Ignore anyone asking for a fee to unlock a refund or trace a card payment.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Does 100,000 phishing pages mean 100,000 people were scammed?<\/h3>\n<p>No. Group-IB counted related pages over a defined period. The figure is not a verified count of victims, successful payments, or losses.<\/p>\n<h3>Was the Singapore Land Transport Authority behind the message?<\/h3>\n<p>No. The documented text and website impersonated the authority. Verify any real vehicle or fee issue through the agency&#8217;s own channels.<\/p>\n<h3>Why did the message tell me to copy the link?<\/h3>\n<p>In the captured example, it gave ways around a phone&#8217;s spam protections. Treat instructions to bypass a blocked link as a warning.<\/p>\n<h3>Can the page take a card number before I press Pay?<\/h3>\n<p>Group-IB found real-time transmission of entered card data in the analyzed page. If you typed details there, contact the issuer even without submitting.<\/p>\n<h3>Did the June 2026 action shut down Outsider completely?<\/h3>\n<p>No complete shutdown was established. Group-IB observed hundreds of new related pages in the month after the coordinated action.<\/p>\n<h3>Do all Outsider texts mention vehicles or tolls?<\/h3>\n<p>No. The kit included templates for several industries and countries. The Singapore vehicle example demonstrates one flow, not every campaign variation.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>Outsider is a reusable phishing system, not one suspicious text. Its messages change names and countries, but the push toward a fake page remains familiar.<\/p>\n<p>When a surprise notice asks you to pay through a link, step out of that conversation. Check the claim independently and act quickly if you entered card details.<\/p>\n<div id=\"mwtad634663743\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A short message says a routine account or vehicle record needs attention today. The link looks official enough to tempt a quick check. For someone reading on the move, the easiest next step is to &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Outsider Phishing Kit Built 100,000 Fake Pages to Steal Cards and Codes\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/outsider-phishing-kit-fake-pages-steal-cards-codes\/#more-420302\" aria-label=\"Read more about Outsider Phishing Kit Built 100,000 Fake Pages to Steal Cards and Codes\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":420303,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-420302","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=420302"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420302\/revisions"}],"predecessor-version":[{"id":420460,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420302\/revisions\/420460"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/420303"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=420302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=420302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=420302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}