Bangladeshi mobile users are being targeted in a global SMS phishing campaign, with fraudsters impersonating the Bangladesh Road Transport Authority (BRTA) to trick victims into sharing sensitive personal and financial information.
Users have reported receiving text messages claiming, “Toll alert: your ETC charge is still due,” followed by links designed to mimic official BRTA service portals.
However, the links use suspicious “.top” domains instead of the official “.gov.bd” government domain, raising clear red flags about their authenticity.
Abul Maruf, who does not own a vehicle, said he received such a message on Tuesday. “I was surprised to see the text and clicked on the link. I closed it as I did not know what to do,” he told TIMES.
Since then, many users have shared screenshots of similar messages on social media, suggesting the campaign is being carried out at scale.
ETC, or electronic toll collection, is a contactless toll payment system used on several bridges and highways across Bangladesh. As many commuters rely on the system, such messages can appear credible and trigger panic among recipients.
Some variations of the scam also mention overspeeding fines or offer discounts, further attempting to lure users into clicking malicious links. Initial analysis shows the domain used in the campaign was registered on 13 April. Its nameservers point to
Cloudflare, while ownership details remain concealed. In an advisory issued on Monday, the Bangladesh e-Government Computer Incident Response Team (CIRT) said it had identified intelligence on a large-scale global smishing campaign, dubbed “Error524”, targeting sectors including financial services, telecommunications, logistics, retail and government platforms.
According to CIRT, the campaign relies on phishing-as-a-service (PhaaS) infrastructure to distribute SMS messages embedded with malicious links.
Once clicked, these links redirect users to fake websites designed to closely resemble legitimate service portals, using official-looking branding to gain trust.
Victims are then prompted to enter login credentials, personal identification information and payment details.
The attackers collect sensitive data, including account credentials, card information and one-time authentication codes, which are transmitted to attacker-controlled servers through encrypted channels and centralised phishing systems.
CIRT Project Director Md Nazmul Haque Khandaker urged users to remain cautious. “To stay digitally safe, users must verify links before clicking,” he told TIMES, warning that such messages should be treated as phishing attempts.
According to CIRT, the campaign follows a multi-stage attack process, beginning with SMS messages that appear to originate from trusted services. These messages may reference delivery updates, unpaid tolls or fines, account verification requests, or reward offers.
Each message typically contains a shortened or disguised link, increasing the likelihood of user engagement.
Officials have advised the public to avoid clicking on suspicious links, verify sources through official channels, and report such incidents to relevant authorities.






