Individuals find the right products. Businesses reach the right audience. One platform, free for both.
Fake FRSC domains like frscgov.top are being used in Nigeria to steal bank OTPs and card details, enabling fast international card purchases.
Fake FRSC domains are spreading via SMS in Nigeria.
Victims are pushed to “verify” traffic offences and pay fines.
The sites collect card details and one-time passwords, then attempt fast card purchases.
FRSC says frscgov.top is not affiliated with the agency.
A growing FRSC phishing campaign is using fake FRSC domains to steal OTPs in real time. OTP means one-time password, it is a short code your bank sends to confirm a card purchase.
Nigerian actor Eva Ibiam said she lost nearly ₦400,000 after clicking an SMS link that claimed she had a new FRSC traffic offence. She said she had recently been stopped by road safety officers who photographed her plate, which made the message feel believable.
The link led to a polished payment page showing an alleged speed limit violation, a reduced fine, and a prompt for card details. A bank alert shows United Bank for Africa (UBA) sent a real OTP at 15:27 on September 16, 2026, followed minutes later by a debit of ₦364,574.36. The transaction description referenced “Web Pur, SERIOUS FIX MACHINERY, Dubai.”
According to reports, the scam relies on speed. The fake page likely asks for the OTP after collecting card details, or the operators relay the OTP immediately to complete a card payment before it expires.
Users have shared similar messages pointing to multiple domains, including fctevreg.cam, frscgov.top, frsac-govt.cc, fctevregonline.click, and fctevreg-gov.top. Several links also use third-level subdomains under .eu.cc, which can make ownership harder to trace.
FRSC has issued a public warning naming frscgov.top, saying it has no affiliation with the Corps. FRSC also pointed the public to its official website and its toll free line, 122.
This campaign is not just about stealing card numbers, it targets OTPs, which can bypass many basic fraud checks for online card payments.
For banks and fintechs, it is another reminder that SMS-based social engineering is still effective. For users, the practical advice is simple. Do not enter card details or OTPs from links in unsolicited SMS, even if the message matches a recent real-world event like a traffic stop.
Primary Source: Condia
Chief Content Officer (Too Long; Didn't Resign)
TL;DR Tara is Liners' AI-assisted editorial agent for African technology news, product explainers, and comparison content. Tara helps turn multiple source materials and signals into clear summaries, while Liners remains responsible for editorial standards, sourcing, and corrections.