TUNIS — Tunisia's National Cybersecurity Agency issued a public warning on Thursday about a fresh wave of text messages that tell recipients they owe an unpaid traffic fine and steer them toward counterfeit websites built to capture their bank card details.

The messages arrive from foreign numbers, according to the agency, and carry a link. The page the link opens is a replica of an official payment portal. Anything typed into it — card number, expiry date, security code, the one-time password sent by the bank — goes to the operator of the fake site.

The ANCS advised the public to ignore suspicious messages, particularly those from international numbers, and to enter no personal or banking information on any platform whose origin is not clearly established. Its most concrete instruction concerns the address bar: Tunisian institutional websites use the national .tn domain, without exception. A payment page for a road fine that does not sit on a .tn address is not a Tunisian government page.

Why the traffic fine

The choice of pretext is not incidental. A fine notice is plausible for almost anyone who drives, carries an implicit deadline, and produces exactly the reaction the attack needs — pay quickly, do not investigate. It is the same design logic behind the parcel-delivery and customs-charge scams that have run through European mobile networks for several years, adapted to a local administrative reference.

The delivery channel is what makes it hard to stop. SMS has no sender authentication: the display name attached to a message can be set almost arbitrarily by the sending party, and messages routed through foreign gateways bypass the filtering that domestic aggregators apply. The user sees what looks like an official alert, in a thread that may even group with genuine ones on their handset.

A warning that has been issued before

The uncomfortable point is that this is a repeat. The same fake-fine scam was documented in Tunisia in mid-June, and the agency has been publishing similar advisories — about fictitious competitions, fraudulent investment platforms, cloned financial sites — for well over a year. That the operation has resurfaced in July, largely unchanged, suggests the earlier alerts did not disrupt it.

That is a limitation worth naming. Public awareness messaging is the cheapest tool available and the weakest one. It places the entire burden of defence on the individual, at the moment they are least equipped to exercise it, and it must be repeated indefinitely because the population of drivers renews itself faster than any campaign can reach it. Nothing in an advisory takes down a phishing domain or blocks the route the messages travel.

What actually stops it elsewhere

The interventions that have measurably reduced this category of fraud in other markets are carrier-side and registry-side rather than user-side.

Several European and Gulf regulators have introduced protected sender-ID registries, under which alphanumeric sender names belonging to public bodies and banks can only be used by the registered owner, and messages arriving from abroad claiming those names are dropped at the gateway. The United Kingdom and Ireland have run such lists for years. A second layer is takedown speed: a national CERT with a standing arrangement with registrars can pull a cloned domain within hours rather than days, and the great majority of a phishing campaign's yield arrives in its first hours.

A third measure sits with the banks. Card schemes' strong-authentication rules are designed so that a stolen card number alone is not enough to complete a transaction; where fraud persists it is usually because the victim relays the one-time code to the attacker in real time, which better-designed bank confirmation messages — naming the merchant and the amount in plain language — make considerably harder.

None of these requires the driver receiving the message to be alert. That is the point of them.