Khairul Alam ; Dhaka – A sophisticated cyber-scam has emerged in the capital, capitalizing on the Dhaka Metropolitan Police’s (DMP) recently launched AI-based traffic surveillance and automated traffic fine system.
Scammers are sending fraudulent traffic violation alerts to vehicle owners, directing them to a fake Bangladesh Road Transport Authority (BRTA) website designed to steal bank card details.
According to an investigation report by DismissLab published on Sunday, the entire scam triggers through a deceptive SMS. The messages do not bear the name of any official government agency or the BRTA.
Instead, they originate from an international number with the country code +63 (+63 948 331 8282), which belongs to the Philippines.
On May 7 this year, the DMP Traffic Division experimentally deployed AI-based CCTV cameras at various intersections in Dhaka to automatically detect traffic violations. Exploiting this technological shift, cyber criminals are manufacturing fear and credibility to dupe citizens.
Recently, several victims took to social media to share their encounters with these scam messages. A motorcycle rider and content creator posted a video on Facebook, revealing he received a fine notification for a date when both his bike and personal car were physically in Chattogram.
He questioned how a fine could be issued in Dhaka without the vehicles being present, and why a government notice would come from a foreign number.
Professor Sumon Rahman, Founder Editor of FactWatch and Head of the Media Studies and Journalism Department at the University of Liberal Arts Bangladesh (ULAB), also shared a similar experience online.
He noted that receiving overspeeding fine alerts from a foreign number with a link pointing to a .icu domain is highly suspicious, as no government entity would use international numbers or non-government domains for official notices.
DismissLab’s investigation revealed that entering any vehicle registration number on the phishing site automatically generates a fake traffic case.
In almost all instances, the offense is listed as “speed limit violation,” with a penalty of BDT 3,000. To lure victims into quick action, the site promises a 50% discount—reducing the fine to BDT 1,500—if paid within three days.
The report highlights that the scammers rely on a combination of fear and greed. On one hand, they create psychological pressure by threatening that failure to pay will hurt the violator’s national driver database and credit record. On the other hand, they tempt the user with a massive discount.
The phishing website closely mimics the layout, logos, colors, and interface of the official BRTA Service Portal (BSP), creating a high risk of deception for ordinary users.
However, it holds no connection to the legitimate government domain. Once a user proceeds to the payment stage, the site prompts them to enter sensitive financial data, including the cardholder’s name, card number, expiration date, and CVV code.
Cybersecurity expert Ashraful Haque warned, “Once this data falls into the hands of fraudsters, unauthorized transactions can be made from anywhere in the world.
This is a highly calculated phishing tactic designed to win user trust by cloning a government platform before stealing their financial credentials.”
Domain analysis reveals that the fraudulent website was registered just recently on May 23 via the NameSilo platform, with the owner’s identity concealed using PrivacyGuardian. Additionally, Cloudflare’s proxy technology was used to mask the actual server location.
Experts strongly advise citizens that Bangladeshi government agencies never use international phone numbers or unrecognized domains to send fine notices.
Vehicle owners are urged not to click on unfamiliar links, to carefully verify domain names, and to never disclose bank card or personal identification details on unverified platforms.

