Cybersecurity Reach Foundation
Investigations

Threat investigation

The Government Health-Card Email That Looked Safe to Scanners

A fake Government of Canada health-card email reached a potential victim through InboxSpotter's email intake and was forwarded for CSRF research.

Investigator
Faisal Hossain · CTI Researcher, Cybersecurity Reach Foundation
Published
August 4, 2026
Scope
Email received July 17, 2026, analysis conducted July 28 – August 3, 2026.
On this page

What readers need to know

This "Government of Canada" health-card email is a scam — one that security scanners rate as safe.

On July 17, 2026, a potential victim forwarded this email to InboxSpotter and opted in for CSRF to research it. InboxSpotter says: "Emails are anonymized and never sold or shared." The message pretended to come from the Government of Canada and Service Canada and tried to get people to click a link and share personal and identity details.

The message was designed to hide its scam page from security tools and researchers. A link may look harmless or even send you to the real canada.ca if you visit it from the wrong place. A clean-looking result does not prove that an email is genuine.

If you receive a similar email:

  • Do not click links in an unexpected government email.
  • Do not provide personal, health-card, identity, or banking details through an email link.
  • Open a new browser window and type canada.ca yourself instead of using the message's link.
  • Report the message to the Canadian Anti-Fraud Centre (antifraudcentre-centreantifraude.ca).
  • If you already clicked the link and entered any details, contact your bank right away, keep a close watch on your accounts and credit, and report what happened to the Canadian Anti-Fraud Centre.

1. What we investigated

Are the emails claiming to come from the government of Canada fraudulent and if so can we identify their source and intent?

The reported email

On July 17, 2026, a potential victim forwarded an email to InboxSpotter and opted in for CSRF to research it. InboxSpotter says: "Emails are anonymized and never sold or shared." The recipient's name and email address are redacted from this public report.

The message impersonated the Government of Canada and Service Canada with a health-card renewal lure. It claimed the recipient needed to update and verify an account, offered a "Continue to Portal" link, and described supposed home-delivery and service-location pickup options for a replacement card.

2. What we found

The July 17, 2026 email is a phishing scam impersonating the Government of Canada / Service Canada, built to harvest people's personal and identity details. It is heavily disguised: the link runs through a fake "security check," and the page only reveals itself to visitors who look like genuine Canadian targets. Anyone else (wrong location, a VPN, or a researcher) is redirected to the real canada.ca, so nothing looks wrong and most automated scanners rate it clean. We confirmed the whole chain was live during our analysis and mapped every step, but could not reach the final form itself, which stays hidden behind those checks. The evidence points to a single group running this wave of emails, though the disguise technique it relies on is a common one seen across many unrelated scams.

Status update (August 7, 2026): Since this investigation was conducted, the Vercel deployment that handled the email's redirect has been taken down and the chain we mapped is no longer active. The operator, however, is still at work: on August 7 the same GitHub account was uploading fresh logo assets, including the logo of Germany's Federal Motor Transport Authority (KBA). That strongly suggests the campaign is continuing on new addresses and expanding beyond Canada to German government lures. We have reported the account to GitHub. This doesn't change the lesson: the operation is cheap and disposable, the same setup can be rebuilt quickly under a new address, and a "clean" scan result still doesn't prove an email is genuine.

3. Why this matters

This scam targets ordinary Canadians with a government and health-card lure and is built to steal identity information, so warning the public directly has real protective value. It matters more than the average scam because its layered disguise makes it nearly invisible to automated defenses. Scanners and browsers rate it clean, so people won't get an automatic warning, and a plainly written explanation is one of the few things that can actually reach them. It is also part of a wider wave that can reappear under new addresses, so the guidance stays relevant even now that the chain we mapped has gone offline.

4. How we reviewed the email

Work period: Email received July 17, 2026, analysis conducted July 28 – August 3, 2026.

Sources covered:

  • Phishing email
  • Sender domain and its Amazon SES delivery record
  • GitHub account and repositories hosting the lure image
  • Redirect/gate and the landing infrastructure
  • urlscan.io (existing public scans plus our own unlisted Canada/mobile scans)
  • ANY.RUN interactive detonation
  • Certificate Transparency logs
  • Public reference sources (Canadian Anti-Fraud Centre guidance, Amazon SES documentation).

Exclusions:

  • We did not reach or capture the form or its exact fields.
  • We did not establish the identity of the operator.
  • The email's original authentication results were stripped when the message was forwarded, so it is uncertain whether the sender is spoofed or compromised.

5. What we observed directly

ObservationDate
Email is a Government of Canada / Service Canada health-card phishing lure. Sender "H81HealthHub", sent from an unrelated small business's domain (redacted), "update/verify" theme, "Continue to Portal" button2026-07-29
Delivered via Amazon SES, Tokyo region. Message-ID …@ap-northeast-1.amazonses.com in the forward's threading headers2026-07-29
Emailed "Continue to Portal" link carries no token. Bare redirect-fa486f8e.vercel[.]app in both parts2026-07-29
One byte-identical Canadian-flag PNG reused across the operator's repos2026-07-28
Operator artifacts in commit history. All commits UTC+8; "Delete 下载.png" (下载 = "download"); consistent author2026-07-28
First stop is a fake "Security Check" reCAPTCHA. AWS-hosted; overall verdict clean (urlscan ML flagged 99); gate JS globals getOrFetchToken / buildTargetUrl / verify2026-07-30
Chain reaches landing servicescanada-health.my[.]id (full path withheld), which 302-redirects to the real www.canada.ca2026-07-30
Landing rejects datacenter/VPN IPs even from Canada. M247 Montréal (217.138.213.53) still 302'd to canada.ca2026-08-03
No stored capture of the final form exists. Urlscan domain search near-empty2026-07-30
Same GitHub account uploaded new logo assets, including the logo of Germany's Federal Motor Transport Authority (KBA), indicating preparation of German government lures2026-08-07
Figure 1. Canadian flag image reused in the campaign's GitHub repositories.
Figure 1. Canadian flag image reused in the campaign's GitHub repositories.
Figure 2. The fake "Security Check" shown before the redirect.
Figure 2. The fake "Security Check" shown before the redirect.

6. What other sources reported

ClaimSourceDate
A potential victim forwarded this to InboxSpotter and opted in for CSRF to research it (establishes only that they received/reported it)InboxSpotter email intake (emails are anonymized and never sold or shared; identity redacted)~2026-07-17
Gate rated "not malicious" overall (score 0). No community or Google Safe Browsing classification, but urlscan's ML engine scored it 99/maliciousurlscan result 019fb0d12026-07-30
Gate IP 216.198.79.195 = AWS (AS16509 AMAZON-02, US); landing on Cloudflare (AS13335); VM exit 217.138.213.53 = M247, Montréal CA (hosting location ≠ operator location)urlscan geoip/ASN + ipinfo.io2026-07-30 / 07-31
Gate TLS certificate issued by Google Trust Services "WR1," ~3-month validity from 2026-06-28urlscan / certificate2026-07-30
servicescanada-health.my[.]id first observed 2026-07-12 (shows domain age, not who registered it)Certificate Transparency logs (via urlscan)2026-07-12
Sender domain (redacted) is an aged domain belonging to an unrelated small US service business. It was abused as a sender identity and does not implicate the businessWHOIS / domain lookup~2026-07-29
Amazon SES requires the From domain/address to be a verified identity before sending (supports, doesn't prove, that sending as that domain required domain/mailbox control or a compromised SES account)AWS SES documentation2026-07-29

7. How the evidence fits together

The trap only springs for the "right" victim. The scam checks each visitor and shows its fake Service Canada form only to someone who looks like a real Canadian target on a normal home or mobile connection. Everyone else, including security scanners and researchers, is redirected to the legitimate canada.ca instead. Because of this, automated tools rate it clean: most of the time it appears to be a real government site. It's also cheap and disposable, run on free, trusted internet services and sent through an ordinary bulk-email tool. Therefore shutting down one piece doesn't stop it as the operators are able to rebuild quickly.

The evidence gives us a profile of who is behind it but not an identifiable person. Independent clues (a reused image, the timing of the work, and language traces) line up, and together they suggest a single operator working in an East-Asian, Chinese-language setting.

Figure 3. GitHub commit history showing the filename "下载.png".
Figure 3. GitHub commit history showing the filename "下载.png".
Figure 4. GitHub profile showing the public repositories associated with the account.
Figure 4. GitHub profile showing the public repositories associated with the account.

We found several near-identical versions of the same setup, which points to one group running an ongoing operation rather than a single email. At the same time, the particular hiding trick it uses turns up across many unrelated scams, so that technique is not something unique to this group.

Finally, the email reached inboxes by abusing a small, unrelated business's identity: it was pushed out through a legitimate mass-email service under that business's address. What we still can't say is exactly what the final form asks victims for. We never got past its defenses to see it.

8. Why this is a scam

Alternative explanationHow we tested itWhat we found
It's a genuine Government of Canada / Service Canada emailChecked the premise and the senderThere's no federal health card, as health cards are provincial. The sender wasn't a government address, and the link runs through a fake security check to a non-government look-alike. This alternative is ruled out.
The business whose address is on it is behind itLooked at where the mail actually came from, and the contentIt didn't come from that business's own email system. It was pushed through a bulk-email service using their address and the content has nothing to do with their business. Their identity was abused with no sign they're involved.
It's harmless and it just takes you to the real canada.caFollowed the whole chain, not just the endpointThe chain passes through the fake landing first and only bounces to the real canada.ca for visitors it rejects. The "harmless" appearance is the disguise.
The scam is already dead / taken down (that's why we only see canada.ca)Re-tested the live infrastructureThe gate and landing were still up and actively sorting visitors as of August 3. We can't fully rule out that the harvest page is dormant, but the operation is live, not gone.
Another organization is running itChecked for any link beyond that one imageThe only tie is a single shared image file. Hosting, registration, contacts, and tooling are all unrelated, and that organization looks like a real business. This can be considered an unverified lead, not an accusation.
It's many unrelated scammers, not one operatorCompared the copies and the hiding trickThe near-identical copies point to one operator running this wave, while the hiding trick itself is common across unrelated scams. So we can conclude this is one group here with a common toolkit.

9. What we could not confirm

Path triedResult
Reaching the final harvest form (direct scan of the landing; the emailed link; free ANY.RUN; a Canadian datacenter VPN)All failed or got bounced to the real canada.ca.
Looking for an existing capture (urlscan history, Wayback)None exists.
Confirming spoofed-vs-compromised sender for certainInconclusive. The email's original authentication results were stripped when it was forwarded to us.
Tying the campaign to a separate Canadian-branded scam toolkit (name withheld; unverified lead)Inconclusive. Only a single shared image, no other overlap.
Naming who is behind itNot possible with what we have. We can't identify individuals from these artifacts alone.

10. Bottom line

This is a hidden phishing operation impersonating the Government of Canada / Service Canada to steal Canadians' personal and identity information. It showed its fake form only to the "right" victims and quietly sent everyone else, including security scanners and researchers, to the real canada.ca, which is why it slipped past automated checks. The specific chain we mapped is no longer active as of August 7, 2026, but the operator remains active: on August 7 the same GitHub account was uploading new government logo assets, including Germany's Federal Motor Transport Authority (KBA), indicating the campaign is continuing and expanding to German government lures.

Confidence

High — that it's a phishing scam; that the chain worked as described, with layered cloaking and a decoy to the real government site; that it was live during our analysis and running as more than one campaign (one operator behind this cluster).

Moderate — the operator's location/language profile; that the sender's identity was abused.

Low / unresolved — exactly what the final form collects (never captured); who the operators actually are; any real link to the separate Canadian-branded toolkit lead.

What we will do next

The scam's landing page sat on a .my.id domain — a cheap corner of the internet's naming system that offers scammers disposable, trusted-looking web addresses. CSRF will follow up with a dedicated investigation into abuse of the .my.id domain space and publish what we find.

Reader safety

Why this matters

This scam targets ordinary Canadians with a government and health-card lure and is built to steal identity information, so warning the public directly has real protective value.