Cybersecurity Reach Foundation
← All safety alerts
investigatingBrand: Government of Canada / Service Canada; Kraftfahrt-Bundesamt (KBA)

Phishing campaign impersonating the Canadian government shows signs of preparing German government lures

A CSRF investigation mapped a phishing email impersonating the Government of Canada and Service Canada. The Canadian redirect chain is now offline, but the same GitHub account uploaded a logo belonging to Germany's Federal Motor Transport Authority (KBA) on 2026-08-07. This suggests preparation for a possible German pivot; no live German phishing page has been confirmed. CSRF reported the GitHub account to GitHub.

Observed domain or link

  • redirect-fa486f8e.vercel[.]app
  • servicescanada-health.my[.]id

What to do

  • Do not click links in unexpected government emails.
  • Verify government messages by opening a new browser window and typing the official website yourself.
  • People in Canada can report suspected fraud to the Canadian Anti-Fraud Centre.
  • Organizations in Germany should watch for unexpected messages using KBA or other German government branding and route suspicious samples to their security or incident-response team.
  • Preserve the original message, headers, screenshots, and URLs for reporting; do not forward suspicious links to the public.

What this alert does not establish

  • The Canadian redirect chain mapped in the investigation is no longer active as of 2026-08-07.
  • No live German phishing page or German victim message has been confirmed.
  • The KBA logo upload indicates possible preparation but does not prove that a German campaign has launched.
  • The final Canadian harvesting form was not captured.
  • The GitHub account and technical clues do not establish the operator's identity, nationality, or physical location.
  • The campaign may use different domains or infrastructure not yet linked to this activity.
Observed:
Last updated:

This alert is maintained from the shared Cybersecurity Reach Foundation / ScamArchive alert record.