On the morning of August 18, Mr. Nguyen Huy (Hanoi) received an iMessage message from a phone number with the prefix +212, displaying the sender's name as "[TTDLQG - Ministry of Public Security]". The message warned that his vehicle was recorded running a red light on August 9, 2026 and had not completed the fine payment obligation.
Notably, the message creates a psychological urge when notifying the recipient that there are only 48 hours left to process. After this deadline, the warned fine will increase by 50% and vehicle documents may be temporarily seized.
Attached to the notification is a link introduced to view information and pay. Receivers are also instructed to answer "1" or "Y" to receive a new link if they cannot access the original link.
However, the link leading to the domain name 0984811. cc is not the official domain name of the state agency. This is a sign that the message is likely a scam scenario to lure users to access a fake website.
Mr. Ngo Minh Hieu (Hieu PC) - Member of the Vietnam National Cyber Security Association said that, according to statistics from chongluadao.vn, in the past two days, many similar cases have been recorded in the form of iMessage. Besides the content impersonating the Ministry of Public Security, the subjects also impersonate Vietnam Post (VNPost).
The message informs the user that a parcel is about to be delivered but the recipient address does not have a specific house number. The recipient is required to update information so that the postman can deliver the goods.
The common point of the two scenarios is that both put users in a familiar but urging situation. One side is the risk of being fined for traffic violations, the other side is the risk of not receiving the parcel.
Accordingly, the subjects often create short deadlines for recipients to have the psychology of having to handle it immediately. At that time, users easily skip basic checks such as the phone number to send the message, website address or source of notification.
If accessing the link, users may be redirected to a fake website and continue to be asked to enter personal information, accounts or payment data.
This is the main goal of the scam scenario: taking users from a message that seems to be an administrative notification or delivery to a website controlled by the subject.
Impersonating large units to spread messages is not a new trick. Previously, subjects used fake BTS stations to mass-display SMS in an area.
With the messages recorded this time, the subject used a foreign phone number, including the prefix +212, and approached users through iMessage.
Mr. Ngo Minh Hieu recommends that users do not reply to these messages, do not click on the link and do not provide information according to instructions.
If you have clicked on the link but have not entered the data, you need to close the page and stop interacting. If account information or payment data has been provided, you need to contact the bank and related units to control the account.
In particular, with notifications about remote fines, users should not pay through links sent from strange messages. Information verification needs to be carried out on official channels of functional agencies.
