On September 16, 2026, Nigerian actor Eva Ibiam described losing almost ₦400,000 after responding to an SMS that claimed she had a new Federal Road Safety Corps, FRSC, traffic offence. She had recently been stopped by road safety officers who photographed her plate, which made the message feel credible. The link led to a polished fake page showing a speed limit violation, a reduced fine, and a prompt for card details.
A bank alert seen by Condia shows UBA sent her a genuine one-time password at 15:27 on September 16, followed minutes later by a debit alert for ₦364,574.36. The transaction description read “Web Pur, SERIOUS FIX MACHINERY, Dubai.” The fraud did not end with a local transfer out of her account. It ended with an international card transaction, authorised using a real OTP from her own bank, routed to a merchant name in the United Arab Emirates.

This shows the fake FRSC page was built to harvest more than a card number. It needed the OTP as well, either through a second fake prompt asking her to enter it on the same site, or through the operators relaying it in real-time to complete the purchase before the code expired. Either method requires the scam to work quickly, which explains the urgency built into the SMS and the page’s design.
A rotating web of domains
What started as one detailed victim account quickly expanded. Multiple people on X and Facebook have been sharing near-identical messages that use a growing list of domains, among them fctevreg.cam, frscgov.top, frsac-govt.cc, fctevregonline.click, fctevreg-gov.top, and several third-level subdomains under the .eu.cc service. Most of the URLs end in the path /ng. The SMS wording stays almost identical across reports, building urgency around a new road traffic offence record that requires immediate action.
These sites do not redirect to official portals. They are the phishing pages themselves, styled to resemble legitimate FRSC or vehicle registration interfaces, built to harvest card and personal details directly.
Public registration data is only available for one domain. fctevreg.cam was registered on September 15, 2026, the day before the reports surfaced, through the Singapore-based registrar Gname.com, with registrant details fully privacy protected and a listed location in Hong Kong.
The domain uses the nameservers a5.share-dns.com and b5.share-dns.net. Nameservers act as the internet’s address book, and using standard shared nameservers like a5.share-dns.com allows the operators to quickly route, update, or shift their fake sites between servers while keeping their identity hidden behind a low-cost third-party provider.
No equivalent registration data is publicly available for the other domains. Several rely on privacy protection, and the .eu.cc addresses are third-level subdomains that typically do not carry independent registration records at all, since the registration sits with the parent service rather than the individual subdomain. This shows how cheap subdomain services can be used to build phishing infrastructure that resists the kind of public scrutiny a standard domain registration would allow.
FRSC responds
The FRSC issued a formal statement the same day the reports surfaced, titled “FRSC Alerts Motorists to Fraudulent SMS, Fake Website” and signed by Corps Public Education Officer Osondu Ohaeri. The statement names frscgov.top directly, states the domain has no affiliation with the Corps, and directs the public to the official FRSC website and the toll-free line 122.

The Corps described the messages as designed to create urgency by claiming a new traffic offence had been recorded, and warned that clicking the links could lead to the loss of personal information, financial details, and other sensitive data. It advised anyone who receives the messages to preserve the evidence and avoid engaging further with the sender.
Corps Marshal Shehu Mohammed directed that the public be sensitised to the scheme and summarised the response in three words distributed as a public campaign line, telling Nigerians to stop, verify, and report before acting on any message claiming to come from the Corps. The statement also commits the Corps to working with law enforcement and cybersecurity authorities on the individuals responsible, though it does not specify what technical steps, if any, have been taken toward identifying or shutting down the domains beyond the one named publicly.
The statement is a clear disownment of the scam. It does not answer the harder question of how the operators obtained the phone numbers used to send the messages, and whether the FRSC’s own systems, vendors, or partner platforms have been checked for any link to that exposure.
An FRSC official has declined further comment on this.
Meanwhile, no public evidence yet identifies the precise source of the phone numbers used in this wave. There is no confirmed leak, insider disclosure, or named database tied directly to the messages sent on September 16.
What is known from the wider Nigerian context makes the campaign feasible without real-time access to FRSC systems. Phone numbers from earlier breaches of banks, corporate registries, and other platforms routinely circulate on underground markets (dark web, black markets) and get reused across unrelated smishing campaigns.
Commercial bulk lists of Nigerian mobile numbers are readily available. Vehicle plate lookup systems in some states have previously exposed owner names and contact details through weakly protected interfaces, and plates can also be collected through simple observation. The fake page itself asks the recipient to enter a plate number, which creates the appearance of a specific offence record even where the operators had none to begin with.
Perfect targeting is unnecessary. Widely available mobile numbers, occasional plate to owner correlations, and low cost bulk SMS delivery are enough to run a campaign at this scale.
Liability
The primary practical burden in a pure phishing case usually falls on the customer who entered the details. Under the Central Bank of Nigeria’s evolving rules on authorised push payment fraud, banks may carry greater responsibility where the victim reports promptly, cooperates fully, and is not found grossly negligent.
An international card transaction complicates that picture further, since recovery or chargeback options depend on the card scheme’s own dispute rules as well as the bank’s internal process, and Evaerys’s case would need to move through that channel rather than a straightforward APP fraud claim.
Telecoms companies that carried the SMS and the government agency that was impersonated generally face little civil liability. The people who built and ran the scheme remain fully criminally liable.
In case it’s not clear, this is a documented, multi-domain operation that rotates lookalike infrastructure to stay ahead of warnings, uses stolen card data and a live OTP to route money out of the country within minutes, and exploits public trust in traffic enforcement to do it.
Read also: DDoS attack expose South Africa’s cybersecurity oversight lapses
Last updated: September 16, 2026


