Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Cyber Crime

California Tax Refund Mobile Phish

Cyberinchief by Cyberinchief
October 25, 2025
Reading Time: 2 mins read
0
California Tax Refund Mobile Phish


RELATED POSTS

Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London

AI Expert: We Have 2 Years Before Everything Changes! We Need To Start Protesting! — Tristan Harris – Lifeboat News: The Blog

Russian police bust bank-account hacking gang that used NFCGate-based malware

A new round of mobile phish is imitating the State of California’s “Franchise Tax Board” in a round of phishing sites that are gaining prominence in the past few days. I visited ftb.ca-gov-sg[.]top/notice from a burner phone to see how the scheme works (the page doesn’t load from the Windows browsers I tested.)

After harvesting all of my private information, the site informs me that I had a $1050 refund available. The phish claims that “Bank Routing” is unavailable due to “system maintenance” and offers the option to send my refund via my Credit Card if I just provide the card number, expiration date, and CVV.


urlscan.io shows at least 300 domains have been observed, all using a hostname pattern that starts with “ftb.cagov” or “ftb.ca-gov” following by some random characters and using TLDs “.cfd” or “.cc”

Most of the observed domains were registered at Dominet (HK) Limited, and likely all are hosted at TENCENT, though most are having their location protected by the reverse proxy service at CloudFlare. (All of the non-CloudFlare ones are on TenCent).

Some recent example hostnames are:

Buy JNews
ADVERTISEMENT
  • ftb.cagov-ac[.]cfd
  • ftb.cagov-bd[.]cfd
  • ftb.cagov-ch[.]cfd
  • ftb.ca-gov-ci[.]cfd
  • ftb.cagov-ckt[.]cc
  • ftb.cagov-ga[.]cc
  • ftb.ca-gov-gd[.]cfd
  • ftb.cagov-gi[.]cc
  • ftb.cagov-go[.]cc
  • ftb.cagov-idr[.]cc
  • ftb.cagov-nb[.]cfd
  • ftb.cagov-ork[.]cc
  • ftb.ca-gov-pf[.]cfd
  • ftb.cagov-rld[.]cc
  • ftb.cagov-tes[.]cc
  • ftb.cagov-tuf[.]cc
  • ftb.cagov-tug[.]cc
  • ftb.cagov-tum[.]cc
  • ftb.cagov-vkd[.]cc
  • ftb.cagov-whe[.]cc
  • ftb.cagov-wht[.]cc
  • ftb.cagov-whu[.]cc
  • ftb.cagov-why[.]cc
  • ftb.ca-gov-yg[.]cfd
  • ftb.cagov-ytk[.]cc

There have been 190 domains observed by URLScan that included the pattern “*.cagov-xx.cc” with the first round imitating California’s DMV from June 23rd to June 25th. The “FTB” pattern began August 19th with ftb.cagov-ge[.]cc/notice and continuing with 143 more reported domains, including 32 domains reported today. The “cagov-XX.cfd” pattern began on August 31st and has been seen using 31 domains. “ca-gov-XX.cfd” also began August 31st and has used 58 domains so far, all hosted at TENCENT.

Searching by IP address using ZETAlytics ZoneCruncher, we find at least 105 domains hosted on four TenCent IP addresses:

 
41 domains hosted on 170.106.140[.]181
38 domains hosted on 43.153.19[.]10
14 domains hosted on 49.51.188[.]94
12 domains hosted on 43.130.56[.]94



Source link

Tags: CaliforniaMobilePhishRefundTax
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
Cyber Crime

Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London

December 27, 2025
AI Expert: We Have 2 Years Before Everything Changes! We Need To Start Protesting! — Tristan Harris – Lifeboat News: The Blog
Cyber Crime

AI Expert: We Have 2 Years Before Everything Changes! We Need To Start Protesting! — Tristan Harris – Lifeboat News: The Blog

December 9, 2025
Russian police bust bank-account hacking gang that used NFCGate-based malware
Cyber Crime

Russian police bust bank-account hacking gang that used NFCGate-based malware

December 8, 2025
How To Reframe Cybersecurity Budget Requests And Get Them Approved
Cyber Crime

How To Reframe Cybersecurity Budget Requests And Get Them Approved

December 8, 2025
Contractors with hacking records accused of wiping 96 govt databases – Lifeboat News: The Blog
Cyber Crime

Contractors with hacking records accused of wiping 96 govt databases – Lifeboat News: The Blog

December 7, 2025
Maryland man sentenced for N. Korea IT worker scheme involving US government contracts
Cyber Crime

Maryland man sentenced for N. Korea IT worker scheme involving US government contracts

December 7, 2025
Next Post
Analyzing bare metal firmware binaries in Ghidra

Analyzing bare metal firmware binaries in Ghidra

The Most Secret US Hacking Operation: Eligible Receiver 97

The Most Secret US Hacking Operation: Eligible Receiver 97

Recommended Stories

Cyber Security Salary in 2025 | How Much Does a Cyber Security Engineer Earn? | Intellipaat #shorts

Cyber Security Salary in 2025 | How Much Does a Cyber Security Engineer Earn? | Intellipaat #shorts

November 29, 2025
A Complete Guide to ASPM (Application Security Posture Management)

A Complete Guide to ASPM (Application Security Posture Management)

November 9, 2025
Cyber Security – Navigating the Digital World Safely | Protect Your Money, Data & Identity!

Cyber Security – Navigating the Digital World Safely | Protect Your Money, Data & Identity!

November 18, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested