(01) - CybersecurityDMSA-2025-PH-001

Phishing Campaign Targeting lto.gov.ph - Philippines

Automated security scans detected a phishing operation impersonating the Land Transportation Office of the Philippines, harvesting personal and payment information.

19 November 20253 min readCybersecurityReports

Executive Summary

During automated threat intelligence gathering, Dymo identified a sophisticated phishing campaign impersonating the Land Transportation Office (LTO) of the Philippines. The attackers created cloned websites mimicking the official lto.gov.ph portal to harvest personal identification and payment information from citizens.

Campaign Overview

Target

  • Official Site: lto.gov.ph
  • Sector: Government - Transportation Authority
  • Country: Philippines

Attack Vector

The phishing operation employed:

  • Domain Spoofing: Registered domains similar to the official LTO domain
  • Website Cloning: Exact replication of the official portal's interface
  • Form Injection: Modified forms to capture submitted data
  • Payment Redirect: Fake payment portals to steal financial information

Data Targeted

  • Driver's license information
  • Vehicle registration details
  • Personal identification numbers
  • Payment card information
  • Contact details

Impact Assessment

This campaign specifically targets:

  • Citizens renewing licenses: Most vulnerable demographic
  • Vehicle owners: Regular interactions with LTO portal
  • Business operators: Fleet and commercial vehicle registrations

The combination of personal ID and payment data makes victims highly susceptible to identity theft and financial fraud.

Indicators of Compromise (IOCs)

The following patterns were detected:

  • Registered domains with typo-squatting patterns
  • SSL certificates issued to non-government entities
  • Form submissions routed to external servers

Actions Taken

  1. Reported to authorities: Philippine Cybercrime Division notified
  2. Domain blacklisting: Added to Dymo's threat intelligence feeds
  3. Public awareness: Released advisory for affected users

Recommendations

For citizens:

  • Always verify the URL before submitting information
  • Use direct government links rather than search engine results
  • Report suspicious sites to official channels

For organizations:

  • Implement DMARC, DKIM, and SPF to prevent email spoofing
  • Monitor for brand impersonation
  • Use threat intelligence services

This phishing campaign was identified through Dymo's continuous security monitoring and automated threat detection.