
Global GovTrap campaign exposes 11,000 portals
Threat intelligence firm CTM360 has identified GovTrap, a massive operation using over 11,000 fraudulent government portals to exploit citizens globally.
Identification of the GovTrap operation
In a report published within the last 24 hours, threat intelligence firm CTM360 detailed the discovery of GovTrap - a massive, globally distributed network of fraudulent websites. The operation comprises more than 11,000 malicious domains specifically engineered to impersonate government entities across multiple countries.
Unlike isolated phishing attempts, GovTrap functions as a scalable fraud ecosystem, enabling threat actors to simultaneously deploy convincing replicas of official state portals across multiple jurisdictions. The sheer scale of the campaign points to a highly organized effort designed to harvest sensitive citizen data and facilitate direct financial theft on an industrial scale.
How GovTrap works: technical execution and replication
GovTrap attackers don't just copy the look of government websites - they replicate entire service environments to make fraudulent platforms visually and functionally indistinguishable from legitimate government assets.
According to CTM360's research, these portals meticulously reproduce:
- Official government branding and visual identity
- Language, workflows, and navigation structures of real service portals
- References to local policies, deadlines, and compliance requirements
- Country-specific messaging tailored to each target region
This level of technical fidelity is deliberate. It is designed to bypass the skepticism users might naturally apply to poorly built phishing sites. When a portal looks, reads, and behaves exactly like the real thing, even cautious users can be deceived.
Targeted services and victim profile
The campaign focuses specifically on government services where financial transactions are routine. Primary targets include:
- Tax reporting and payment portals
- Traffic fine payment systems
- Vehicle registration platforms
- Social benefit and welfare services
By positioning fraudulent portals at the point of payment or data submission, attackers are able to intercept credit card details and personal identification information in real time.
Victims are typically directed to these fake sites via coordinated SMS campaigns, email phishing, and social media platforms. The messaging is deliberately engineered to create urgency - think notifications about an "overdue fine", an "expired licence", or a "pending tax obligation." The geographic reach of GovTrap is extensive, with citizens affected across North America, Oceania, Europe, and Asia.
Infrastructure and why GovTrap is so hard to shut down
The infrastructure supporting GovTrap is built for resilience and rapid recovery. CTM360 found that the network relies on low-cost, easily accessible hosting, and that new domains are registered and deployed daily to stay ahead of security software blacklists.
Rather than using country-code top-level domains (ccTLDs) that might draw scrutiny, the campaign leverages a broad mix of TLDs - including .me, .com, .cc, .vip, and .icu - chosen for their low cost and ease of registration.
Further compounding the problem is the use of localized language translation, ensuring that the fraudulent experience remains seamless for non-English speaking victims. Harvested data is exfiltrated in real time through automated scripts or transmitted via messaging platforms such as Telegram bots, enabling the immediate exploitation of compromised information before victims even realize what has happened.
What GovTrap means for digital government trust
The emergence of GovTrap signals a meaningful evolution in the threat landscape. Criminals are no longer simply targeting commercial brands - they are systematically undermining the digital interface between the state and its citizens.
As more public services move exclusively online, the existence of 11,000 fake government portals creates a troubling dynamic: the burden of verification is shifted onto the individual citizen, who typically lacks the technical tools to distinguish a legitimate government server from a GovTrap node. This erosion of trust has consequences that extend well beyond individual victims, potentially discouraging legitimate use of e-government services and weakening public confidence in digital infrastructure.
How to protect yourself from GovTrap-style scams
For citizens, protective habits remain the most reliable line of defence:
- Always type government URLs directly into your browser rather than clicking links in SMS messages or emails
- Check the full URL carefully before entering any personal or payment data - look for subtle misspellings or unusual domain extensions
- Be sceptical of urgency - legitimate government agencies rarely demand immediate payment via unsolicited messages
- Use official government app stores or verified portals bookmarked directly from official
.govor national government domains - Enable two-factor authentication on any accounts linked to government or financial services
- If you receive an unexpected message about a fine, licence, or tax obligation, contact the relevant agency directly through a number or website you already know to be legitimate
How governments and organisations should respond
CTM360 advocates for a proactive, intelligence-driven approach that goes well beyond reactive takedowns of individual fraudulent sites.
Recommended actions for governments and cybersecurity teams include:
- Continuous monitoring of domain registration activity and impersonation patterns across the full fraud lifecycle - from resource development and distribution through to monetisation
- Investment in threat intelligence platforms capable of identifying GovTrap-style infrastructure before domains go live
- Coordinated cross-border response frameworks, given the campaign's simultaneous targeting of multiple jurisdictions
- Public awareness campaigns to help citizens recognise and report fraudulent government impersonation attempts
The scale of GovTrap makes it clear that responding to individual sites as they are discovered is not enough. Systemic problems require systemic solutions.
Key takeaways
- CTM360 identified more than 11,000 distinct fraudulent government portals operating as part of a coordinated global campaign named GovTrap
- The operation deploys high-fidelity replicas of official government portals, localized by country in language, branding, and service structure, to facilitate financial theft and data harvesting
- Attackers primarily target high-traffic services including tax filings, traffic fine payments, vehicle registration, and social benefit platforms - services where citizens routinely submit payment and personal data
- GovTrap campaigns are distributed via SMS, email phishing, and social media, using urgency-driven messaging such as overdue fines, expired licences, or pending tax obligations
- The infrastructure relies on a mix of low-cost TLDs (
.me,.com,.cc,.vip,.icu), with new domains registered daily to evade security blacklisting - making the ecosystem highly scalable and difficult to contain - Harvested data is exfiltrated in real time through automated scripts and messaging platforms such as Telegram bots, enabling immediate exploitation before victims detect the breach
- The campaign has extensive geographic reach across North America, Oceania, Europe, and Asia
- GovTrap represents a systematic shift toward industrial-scale impersonation of state-level digital infrastructure, posing a direct threat to public trust in online government services
Sources
- The Hacker News - CTM360 GovTrap report https://thehackernews.com/expert-insights/2026/04/ctm360-exposes-global-govtrap-campaign.html
- CTM360 - GovTrap full threat report https://www.ctm360.com/reports/government-impersonation-phishing-govtrap-scams
- CTM360 - Cybersecurity reports overview https://www.ctm360.com/cybersecurity-reports
- Published 2026-04-27 22:42
- Modified 2026-05-22 21:59


