logo

Cybercriminals Exploit Canadians’ Dependence on Digital Services in Widespread Attacks

ID: 0ea59164-a850-51df-b908-e8edbdf12ab8

STIX ID: report--0ea59164-a850-51df-b908-e8edbdf12ab8

Feed Name: GBHackers

Threat Score
68/100

Date Published: 2026-01-28

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

Executive Summary: A large-scale phishing campaign targeting Canadians leverages PayTool phishing-as-a-service to impersonate government services (traffic tickets, CRA), Air Canada, and Canada Post via SMS and malicious ads, using typosquatted domains, shorteners, and fallback infrastructure; researchers observed 70+ domains resolving to IP 198.23.156.130 and payment infrastructure in the 45.156.87.0/24 subnet, while threat actors sell phishing kits and coordinate via Telegram, harvesting PII and banking credentials and advising domain monitoring, DNS/web gateway controls, and public awareness campaigns as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.