investigating Brand: Government of Canada / Service Canada; Kraftfahrt-Bundesamt (KBA)
A phishing campaign impersonating the Canadian government shows signs of preparing German government lures
A CSRF investigation mapped a phishing email impersonating the Government of Canada and Service Canada. The Canadian redirect chain is now offline, but the same GitHub account uploaded a logo belonging to Germany's Federal Motor Transport Authority (KBA) on 2026-08-07. This suggests preparation for a possible German pivot; no live German phishing page has been confirmed. CSRF reported the GitHub account to GitHub.
Observed domain or link
- redirect-fa486f8e.vercel[.]app
- servicescanada-health.my[.]id
What to do
- Do not click links in unexpected government emails.
- Verify government messages by opening a new browser window and typing the official website yourself.
- People in Canada can report suspected fraud to the Canadian Anti-Fraud Centre.
- Organizations in Germany should watch for unexpected messages using KBA or other German government branding and route suspicious samples to their security or incident-response team.
- Preserve the original message, headers, screenshots, and URLs for reporting; do not forward suspicious links to the public.
What this alert does not establish
- The Canadian redirect chain mapped in the investigation is no longer active as of 2026-08-07.
- No live German phishing page or German victim message has been confirmed.
- The KBA logo upload indicates possible preparation but does not prove that a German campaign has launched.
- The final Canadian harvesting form was not captured.
- The GitHub account and technical clues do not establish the operator's identity, nationality, or physical location.
- The campaign may use different domains or infrastructure not yet linked to this activity.
Share this warning
This alert is also on WatchOut, our shareable alert feed, with one-tap sharing and free email alerts.