Back to advisories
CriticalAdvisory
3 min read

Threat Alert: Financially Motivated Phishing & Impersonation Campaign Targeting Motorists in Nigeria

Threat actors are actively impersonating official traffic management and registration authorities—specifically the Federal Road Safety Corps (FRSC) and the Directorate of Road Traffic Services (DRTS)—to fraudulently harvest personal credentials and sensitive financial data from citizens under the pretext of settling traffic violation fines .

Critical Severity

This vulnerability requires immediate attention. Affected systems should be patched or mitigated as soon as possible.

1. Executive Summary

WhiteHat.NG, operating as Nigeria's dedicated cybersecurity response team, ISAC, and People CERT, is issuing this security advisory regarding an active, financially motivated threat campaign targeting motorists across Nigeria.

Threat actors are actively impersonating official traffic management and registration authorities—specifically the Federal Road Safety Corps (FRSC) and the Directorate of Road Traffic Services (DRTS)—to fraudulently harvest personal credentials and sensitive financial data from citizens under the pretext of settling traffic violation fines .


2. Key Observations & Incident Response Analysis

Based on incident tracking and threat intelligence coordination by WhiteHat.NG :

  • Potential Bulk SMS Gateway Compromise: Informal incident notifications indicate that a system containing citizen contact records and equipped with bulk SMS dispatch capabilities may have been compromised, enabling widespread targeting.
  • Impersonation of DRTS Infrastructure: Threat actors are spoofing the DRTS Automated Online Vehicle Registration System. It remains unconfirmed whether recipient phone numbers originated directly from DRTS databases or were compiled from secondary data sources.
  • Social Engineering Tactics: Deceptive text messages notify recipients of alleged road traffic offences, creating artificial urgency to compel recipients to open malicious web links .
  • Official Public Warning: WhiteHat.NG acknowledges and supports the public alert issued by the FRSC via Corps Public Education Officer Osondu Ohaeri, advising citizens against engaging with fake traffic offence notices.

3. Threat Characteristics & Data at Risk

Threat Dimension Observed Characteristics
Delivery Vector Unsolicited SMS and social media messaging channels .
Social Engineering Cue Urgent claims of newly recorded traffic violations and pending penalties.
Spoofed Entities Brand identity and portals of the FRSC and the DRTS Automated Online Vehicle Registration System.
Data Targeted Credit/debit card numbers, PINs, CVV codes, banking credentials, driver's licence details, and vehicle registration records .

4. Recommended Mitigations for Motorists

WhiteHat.NG advises members of the public to observe the following safeguards:

  1. Avoid Suspicious Links: Do not click on links embedded in unsolicited SMS messages alleging traffic violations or demanding immediate payment .
  2. Verify via Official Channels: Confirm any traffic citation directly through legitimate, verified FRSC channels (such as national toll-free number 122 or official agency website) or DRTS portals .
  3. Protect Sensitive Credentials: Never disclose banking passwords, card PINs, CVV numbers, or driver's licence details in response to text messages or unverified links .
  4. Preserve Evidence & Report Incidents: Retain screenshots of phishing messages, refrain from communicating with sender numbers, and submit incident reports to law enforcement or CERT response platforms .

5. Guidance for Authorities & Infrastructure Providers

WhiteHat.NG recommends that technical stakeholders and government IT administrators implement the following actions:

  • Comprehensive Incident Response: Initiate an independent incident response audit across bulk SMS dispatch systems and vehicle registration infrastructure to determine root causes and verify platform integrity.
  • Inter-Agency CERT Collaboration: Deepen operational collaboration between national security response teams, regulatory bodies, and law enforcement to block and neutralize active phishing networks.

6. Technical Indicators of Compromise (IoCs)

Security Operations Centers (SOCs), network administrators, and digital service providers should block traffic to and monitor networks for the following identified malicious infrastructure:

Malicious Phishing URLs & Domains

  • https://www.frscgov[.]top/ng
  • https://fcoseig[.]cc/ (Mobile devices only)
  • https://www.asasjargol[.]cc
  • https://canjeasrpts[.]cc/ (Mobile devices only — redirects to https://www.frscgov.top)
  • https://www.frsc-gev[.]cc/
  • https://sz.swka.eu[.]cc//
  • Other domain ending with .CC

Associated IP Addresses

  • 104.21.39[.]103
  • 172.67.144[.]52
  • 192.25.102[.]213