Looking for Gasoline? Hand Over Your Account: Scammers Launch Fake Gas Station Card Phishing Sites Targeting Fuel Shortages
Cybercriminals are exploiting ongoing fuel shortages and long queues at gas stations by deploying sophisticated phishing campaigns that trick users into surrendering access to their messenger accounts. Security researchers at F6 have discovered more than 60 fraudulent websites designed to look like official gas station locator services, game platforms, marketplaces, and video hosting sites.
How the Scam Operates
The attackers promise victims practical help such as real-time maps showing where gasoline is available, electronic fuel coupons, or bonus rewards in popular games. To “activate” these offers, users are asked to enter their phone number and then confirm it by inputting a one-time code sent via SMS. This simple step hands the attackers control over the victim’s messenger account.
Once inside, the criminals can read private conversations, download photos, videos, and documents, browse contact lists, and send messages while impersonating the account owner. In many cases, the legitimate user retains partial access and may not immediately notice the intrusion, allowing the attackers to operate undetected for extended periods.
Convincing Fake Interfaces
The phishing pages are built to appear authentic. Visitors are invited to choose fuel type and region; the site then claims to have located several stations. Instead of displaying the list, however, a “phone confirmation” form appears. In another variant, the criminals clone the design of legitimate services and require messenger authorization to receive a nonexistent electronic coupon.
Targeting Children and Additional Disguises
The same network also targets younger users. Under the guise of the popular game Brawl Stars, children are offered free loot boxes and in-game currency after logging in through their messenger. More than half of the identified sites impersonate marketplace brands, while 19 percent pose as social platforms. The remaining pages mimic gas station maps, video services, games, and classified advertisement boards.
Domain Patterns and Response
Most of these malicious pages are hosted on the domain zones .site, .click, .shop, .lol, and .xyz. F6 has already submitted the discovered domains for blocking, yet new addresses continue to appear as the campaign evolves.
Related articles
Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints
Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.
Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics
The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.
OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery
OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.
Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels
Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.