Drivers in Pennsylvania are being targeted by GPS-based Phishing scam, but the source of the data isn't clear Police in Tredyffrin, Pennsylvania are warning drivers about a new scam that uses accurate GPS information. The messages being sent to drivers claim to be speeding tickets; and in order to lend legitimacy to the scam, they contain accurate personal information as well as location data.The emails contain an attachment, but it isn’t clear if the attachment itself is malicious. To be on the safe side, drivers are warned to avoid opening the attachment, because if it is malicious it could infect the system.The email contains the victim’s first and last name, and it’s addressed to an email address they’re familiar with. In addition to accurate personal details, the email also contain valid GPS information (including roads traveled and speed.)An example of the email was provided by the law enforcement agency: From: Speeding Citation To: [REDACTED]Date: 03/11/2016 03:08 PMSubject: [External] Notification of excess speedFirst Name: [REDACTED]Last Name: [REDACTED]Notification of excess speedRoute: [REDACTED]Date: 8 March 2016Time: 7:55 amSpeed Limit: 40Detected Speed: 52The Infraction Statement contains an image of your license plate and the citation which must be paid in 5 working days.The Tredyffrin police department raised the alert last week, and promptly notified other local police departments and the district courts.The source of the GPS data isn’t known, but given the level of accuracy in the information provided, Tredyffrin police have placed the blame on some type of traffic or mobility application. It’s possible the application isn’t malicious itself, but the information collected is being used for malicious purposes. This means the application could come from a third-party source, or directly from Google Play or iTunes.Another possibility is that the information is being recorded in a database that has been left available to the public online (e.g. a poorly configured MongoDB instance) and criminals are abusing the stored data.Either way, the Tredyffrin police department reminds drivers that citations such as this wouldn’t be delivered by their agency. Drivers who receive such a notification should ignore it.At this time, it isn’t clear if drivers outside of Tredyffrin, Pennsylvania have received similar notifications.“Many consumers will readily dismiss the possibility that someone would care about their location data, but this is a prime example of how this seemingly low value data can play into a larger attack,” said Craig Young, a cybersecurity researcher for Tripwire.“While a fake speeding ticket email might ordinarily be recognized as fake and ignored, including a person’s name along with a road they regularly drive immediately gives authenticity to the scam making it far more likely that the attack will succeed. Social engineering is one of the most fundamental tools in the hacking toolkit and every hacker knows that realism is key in these efforts.” Related content news Gwinnett Medical Center investigating possible data breach After being contacted by Salted Hash, Gwinnett Medical Center has confirmed they're investigating a security incident By Steve Ragan Oct 02, 2018 6 mins Regulation Data Breach Hacking news Facebook: 30 million accounts impacted by security flaw (updated) In a blog post, Facebook’s VP of product management Guy Rosen said the attackers exploited a flaw in the website's 'View As' function By Steve Ragan Sep 28, 2018 4 mins Data Breach Security news Scammers pose as CNN's Wolf Blitzer, target security professionals Did they really think this would work? By Steve Ragan Sep 04, 2018 2 mins Phishing Social Engineering Security news Congress pushes MITRE to fix CVE program, suggests regular reviews and stable funding After a year of investigation into the Common Vulnerabilities and Exposures (CVE) program, the Energy and Commerce Committee has some suggestions as to how it can be improved By Steve Ragan Aug 27, 2018 3 mins Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe