logo

The “PayTool” Trap: Massive Fraud Cluster Impersonates Canada Gov & Air Canada

ID: e51c0f02-56d0-584c-8667-58ca07582098

STIX ID: report--e51c0f02-56d0-584c-8667-58ca07582098

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** CloudSEK uncovered a large, coordinated PayTool-linked fraud campaign targeting Canadian citizens with high-fidelity impersonations of federal services and commercial brands (e.g., Air Canada), leveraging smishing, SEO poisoning, typosquatting, province-specific phishing portals, and rotating fallback domains; the operation is being commoditized via Phishing-as-a-Service and active sellers advertising kits that harvest banking credentials and other high-value data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.