US cities warn of wave of unpaid parking phishing texts

While parking scams have been around for years, a massive wave of phishing text messages has caused numerous cities throughout the US to issue warnings, including from Annapolis, Boston, Greenwich, Denver, Detroit, Houston, Milwaukee, Salt Lake City, Charlotte, San Diego, San Francisco, and many others. In the New York City phishing campaign, clicking on the link brings you to a website pretending to be "NYC Department of Finance: Parking and Camera Violations," which will prompt you to enter your name and zip code. US cities are warning of an ongoing mobile phishing campaign pretending to be texts from the city's parking violation departments about unpaid parking invoices, that if unpaid, will incur an additional $35 fine per day. The text message received by BleepingComputer claims to be from the City of New York about an unpaid parking invoice, which would incur a daily $35 fine if not paid. At this point, you can enter any name and zip code and will be brought to a page stating, "Your vehicle has an unpaid parking invoice in City of New York. This same phishing template is used in texts about unpaid parking invoices from other cities seen by BleepingComputer. Clicking on the "Proceed Now" button brings you to the screen where the threat actors attempt to steal your data, including your name, address, phone number, email address, and, eventually, your credit card information. As a general rule, if you receive a text from an unknown phone number or email address that is an out-of-the-blue greeting or asks you to click a link, pay a bill, or respond in some manner, you should report and block the number instead. As Google.com is a trusted domain, Apple iMessage does not disable the link, so using the company's open redirect makes it easier to trick unsuspecting users into clicking on the link by mistake. This information can then be used for a wide variety of malicous activity, including further phishing attacks, identity theft, financial fraud, and the sale of your data to other threat actors. The current wave of texts started last December and has continued since, with BleepingComputer receiving a text targeting New York residents earlier this week. "This is a final reminder from the City of New York regarding the unpaid parking invoice. To circumvent this, the scammers use an open redirect on Google.com to redirect users to a phishing site named after the city it is impersonating.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Sun, 09 Mar 2025 17:20:11 +0000


Cyber News related to US cities warn of wave of unpaid parking phishing texts

US cities warn of wave of unpaid parking phishing texts - While parking scams have been around for years, a massive wave of phishing text messages has caused numerous cities throughout the US to issue warnings, including from Annapolis, Boston, Greenwich, Denver, Detroit, ...
10 hours ago Bleepingcomputer.com
Spear Phishing vs Phishing: What Are The Main Differences? - Almost half of them used phishing to obtain the passwords of users. Highly targeted phishing campaigns against specific individuals or types of individuals are known as spear phishing. It's important to be able to spot phishing in general. For ...
1 year ago Techrepublic.com
Flipping the BEC funnel: Phishing in the age of GenAI - For years, phishing was just a numbers game: A malicious actor would slap together an extremely generic email and fire it out to thousands of recipients in the hope that a few might take the bait. Common among these new techniques was a shift towards ...
1 year ago Helpnetsecurity.com
What SOCs Need to Know About Water Dybbuk - According to the Federal Bureau of Investigation, BEC costs victims more money than ransomware, with an estimated US$2.4 billion being lost to BEC in the US in 2021. Recently, BEC scammers have been using stolen accounts from legitimate Simple Mail ...
2 years ago Trendmicro.com
Hackers steal customer data from Europe's largest parking app operator - Europe's largest parking app operator has reported itself to information regulators in the EU and UK after hackers stole customer data. EasyPark Group, the owner of brands including RingGo and ParkMobile, said customer names, phone numbers, ...
1 year ago Packetstormsecurity.com
Europe's Largest Parking App Provider Informs Customers of Data Breach - EasyPark Group, Europe's largest parking application operator, has disclosed a data breach impacting customer information. Data stolen by hackers includes name, phone number, physical address, email address and partial IBAN or credit/debit card ...
1 year ago Securityweek.com
Combat Phishing Attacks With AI-Powered Threat Protection - According to statistics, 81% of organizations have seen an increase in phishing emails since 2020, with an estimated 3.4 billion emails sent every day. AI-generated phishing emails are a sophisticated and evolving cybersecurity threat. ...
1 year ago Gbhackers.com
The Future of Phishing Email Training for Employees in Cybersecurity - One common method they use is through phishing emails. To counter this changing threat, companies must give importance to providing phishing email training for employees on identifying and responding properly to phishing attempts. Standard training ...
10 months ago Hackread.com
Hackers Steals Customer Data Car Parking Giant - Owner of parking apps RingGo and ParkMobile has been hacked, and customer data including credit card info has been stolen. Cybersecurity issues have not lessened during the Christmas holiday period, after Europe's largest parking app organisation ...
1 year ago Silicon.co.uk
Phishing Campaign Exploits Open Redirection Vulnerability In 'Indeed.com' - Phishing remains one of the most prevalent challenges facing organisations, with more than three billion malicious emails estimated to be sent around the world every day. Owing to the prevalence of the problem, Verizon's 2023 Data Breach ...
11 months ago Cyberdefensemagazine.com
T-Mobile, Verizon workers get texts offering $300 for SIM swaps - Criminals are now texting T-Mobile and Verizon employees on their personal and work phones, trying to tempt them with cash to perform SIM swaps. The targeted employees have shared screenshots of messages offering $300 to those willing to aid the ...
10 months ago Bleepingcomputer.com
Vade Releases 2023 Phishers' Favorites Report - PRESS RELEASE. SAN FRANCISCO, Feb. 15, 2024 /PRNewswire/ - Vade, a global leader in threat detection and response with more than 1.4 billion mailboxes protected, today announced its annual Phishers' Favorites report for 2023. Phishers' Favorites ...
1 year ago Darkreading.com
One Phish, Two Phish, Red Phish, Blue Phish - I sat down for a chat with George Skouroupathis, our phishing expert at Resonance Security. Phishing is often the first step taken by hackers in a larger scam. There are lots of different kinds of phishing attacks, but one of the most prevalent is ...
9 months ago Hackread.com
Watch out for "I can't believe he is gone" Facebook phishing posts - This phishing attack is ongoing and widely spread on Facebook through friend's hacked accounts, as the threat actors build a massive army of stolen accounts for use in further scams on the social media platform. As the posts come from your friends' ...
1 year ago Bleepingcomputer.com
"Quishing" you a Happy Holiday Season - QR Code phishing scams - What they are and how to avoid them. Originally invented to keep track of car parts in the early 90s, QR codes have been around for decades. Quishing, or QR Code phishing, exploits smartphone users scanning the 2D barcode, ...
1 year ago Netcraft.com
Dynamic Malware Analysis using GPT-4 With 100% Recall Rate - A new prompt engineering-assisted Dynamic Malware Analysis model has been introduced, which can overcome the drawbacks faced in the quality API call sequences deployed for dynamic malware analysis. This new method has been reported to perform ...
1 year ago Cybersecuritynews.com
Yodobashi Camera Users Under Attack from a New Wave of Phishing Attack - Cybersecurity firm Symantec reported the campaign, which uses emails titled “Yodobashi.com: ‘Customer Information’ Change Request Notification” to trick recipients into visiting fake login pages. A new wave of phishing attacks impersonating ...
1 week ago Cybersecuritynews.com Qilin
Smishing: SMS Phishing Attacks And How to Thwart Them - Smishing is a fast growing version of one of the most established and lucrative scams on the internet. Smishing, like other forms of phishing, aims to trick you into revealing sensitive data and information; however, instead of email, cybercriminals ...
1 year ago Cysecurity.news
USPS Delivery Phishing Scam Exploits SaaS Providers to Steal Data - A new USPS Delivery Phishing Scam has surfaced, in which scammers are exploiting Freemium Dynamic DNS and SaaS Providers to steal victims' login credentials and other data. Cybersecurity researchers at Bloster AI have uncovered a new USPS Delivery ...
1 year ago Hackread.com
Telegram is a Wide-Open Marketplace for Phishing Tools - The encrypted messaging app Telegram has become a veritable marketplace for bad actors who want to launch effective phishing campaigns on the cheap, essentially democratizing the cyberthreat, according to researchers at cybersecurity firm Guardio. ...
1 year ago Securityboulevard.com
EasyPark discloses data breach that may impact millions of users - Parking app developer EasyPark has published a notice on its website warning of a data breach it discovered on December 10, 2023, which impacts an unknown number of its millions of users. EasyPark is a Swedish company that creates mobile and web apps ...
1 year ago Bleepingcomputer.com
RingGo: Phone Parking Service Suffers Data Breach, Customer Data Stolen - UK-based pay-by-phone parking service - RingGo - has suffered a data breach, where information including partial credit card numbers of several of its customers has been leaked. The EasyPark-owned company informed that the data of at least 950 ...
1 year ago Cysecurity.news
Police takes down BulletProftLink large-scale phishing provider - The notorious BulletProftLink phishing-as-a-service platform that provided more than 300 phishing templates has been seized, the Royal Malaysian Police announced. The operation started in 2015 but came to researchers' radar later and became more ...
1 year ago Bleepingcomputer.com
Splunk: AI isn't making spear phishing more effective - Despite increased concerns, AI tools won't give adversaries an advantage when it comes to sending effective phishing emails, according to new research by Splunk's Surge security research team. In a blog post Thursday, Tamara Chacon, security ...
1 year ago Techtarget.com
5 Common Phishing Vectors and Examples - Phishing attacks can be executed through various means, such as SMS and phone calls, but the most prevalent method involves sending victims emails containing malicious attachments. Let's take a closer look at these types and examine examples of ...
9 months ago Cybersecuritynews.com CVE-2017-11882 Equation

Cyber Trends (last 7 days)