Skip to main content
← All threats
HIGH Published May 28, 2026

Exposing a Global Smishing Operation Across 19 Countries: Governments, Postal Services,…

A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications.

A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications.

MITRE ATT&CK

Tactics, Techniques & Procedures

TA0006 Credential Access tactic
TA0001 Initial Access tactic

Defensive mapping

Mapped controls

The audit will verify each of these controls is in place and effective.

Control Confidence Why it matters
Email security gateway (DMARC, SPF, DKIM) suggested 75% Recommended control for phishing
MFA for all user accounts suggested 75% Recommended control for phishing
Security awareness training suggested 75% Recommended control for phishing
Phishing-resistant authentication suggested 75% Recommended control for phishing
URL filtering suggested 75% Recommended control for phishing