Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    JetBrains security advisory (AV26-364) – Canadian Centre for Cyber Security

    April 17, 2026

    Delta Electronics ASDA-Soft | CISA

    April 17, 2026

    The Destroyed Remnants of a Lost World Are Falling to Earth, Scientists Discover

    April 17, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»Alerts»Active Scam Impersonating the Government of Alberta
    Alerts

    Active Scam Impersonating the Government of Alberta

    adminBy adminApril 15, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Active Scam Impersonating the Government of Alberta

    TLP:CLEAR

    Source: CyberAlberta Investigation

    Summary

    CyberAlberta Threat Intelligence has received multiple reports of a malicious domain impersonating the Government of Alberta, claiming to offer Canada Carbon Rebate (CCR) payments to illicit personally identifiable information (PII) from members of the public.

    The threat actor is using this scam in an attempt to gather alberta.ca usernames, social security numbers, and mother’s maiden names. These details are almost certainly later leveraged in attempts to commit fraud. This scam has been observed being delivered on Facebook but could be leveraging other social media platforms also.

    CCR Scam

    Figure 1 – Screenshot of the CCR scam observed on Facebook.

    Threat Actor Infrastructure

    The malicious domain used to host this scam albertagov[.]ca was recently created on June 3rd and currently resolves to IP address 47.239.216[.]183 owned by Alibaba US Technology (AS45102) and based in Hong Kong. Both the domain and IP address have low to no reports of previous malicious activity on open-source repositories.

    The IP address also hosts the following Alberta-themed domains which are/were likely used for the same fraudulent style activity advertising fake CCR payments:

    • myalbertaccr[.]ca
    • ccr-alberta[.]info

    Recommendations

    • Users are strongly encouraged to be aware of this scam and others like it, to not engage with them, and to report any observations of future similar scams to the owners of the platform it is found on.
    • If any users have engaged with this scam and have submitted the requested PII, they should:
    • Contact their banks only if they have reason to believe their financial information has also been compromised
    • If users can no longer access their alberta.ca accounts using their passwords, it could be a sign of account takeover. In this case, it is once again strongly advised to contact alberta.ca by using their urgent issues hotline (844) 643‐2789.
    • Network defenders are advised to block the indicators of compromise (IOCs) listed below, review logs for signs of user impact related to this scam, and engage with affected users to ascertain the context of the activity and enhance awareness.

    Indicators of Compromise

    Indicator Further Detail
    47.239.216[.]183 Alibaba US Technology (AS45102)
    albertagov[.]ca Reported domain
    affordabilityactionplan.albertagov[.]ca  
    myalbertaccr[.]ca  
    ccr-alberta[.]info  



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIncident: NSW cashless gambling trial to focus on data security after hack of smaller pilot program | The Guardian
    Next Article The German Cyber Criminal Überfall: Shifts in Europe’s Data Leak Landscape
    admin
    • Website

    Related Posts

    Alerts

    JetBrains security advisory (AV26-364) – Canadian Centre for Cyber Security

    April 17, 2026
    Alerts

    Delta Electronics ASDA-Soft | CISA

    April 17, 2026
    Alerts

    ZDI-26-287: DriveLock Directory Traversal Information Disclosure Vulnerability

    April 17, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202619 Views

    Catchy & Intriguing

    March 17, 202619 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202619 Views

    Catchy & Intriguing

    March 17, 202619 Views
    Our Picks

    JetBrains security advisory (AV26-364) – Canadian Centre for Cyber Security

    April 17, 2026

    Delta Electronics ASDA-Soft | CISA

    April 17, 2026

    The Destroyed Remnants of a Lost World Are Falling to Earth, Scientists Discover

    April 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.