Phishing and fraud
INCIBE warns of emails and texts impersonating Spain's DGT with fake traffic fines
An active email and SMS campaign is impersonating the DGT, Spain's traffic authority, to collect non-existent fines and steal card details. INCIBE has rated it as high importance. If your company has vehicles or handles traffic paperwork, this is exactly the kind of message that can slip into the routine.
DGT (Dirección General de Tráfico, Spain's traffic authority) — Impersonated body — not the victim or the sender of the messages

In 30 seconds
- INCIBE warns of emails and text messages impersonating the DGT to collect fines that don't exist.
- The link leads to a copy of the DGT website that asks for your name, number plate and full card details, including the CVV.
- Always check fines by going to the official DGT website or app yourself — never through the link in a message.
- If someone has entered company card details, call the bank immediately and have the card blocked.
Does this affect me?
Yes, if your company has vehicles registered in its name, if anyone on the team uses their phone for company business or, above all, if you're a gestoría (administrative agency) handling traffic paperwork for clients: a notice about a case file is a routine email, and that's where the risk lies. The campaign targets individuals, but a company card entered on the fake site is just as useful to the attacker.
What happened
On 28 September 2026, INCIBE (Spain's National Cybersecurity Institute) published a high-importance alert about an email and SMS campaign impersonating the Dirección General de Tráfico (DGT), Spain's traffic authority. The messages report a supposed fine or pending case file and include a link to a website that mimics the DGT's.
Among the subject lines detected, INCIBE lists two (in Spanish, as they arrive):
- «El proceso de gestión de su expediente sigue en curso» ("Your case file is still being processed")
- «Ultimo recordatorio antes del recargo de su multa – Expediente n.º XXXXXXX» ("Final reminder before your fine is surcharged – Case no. XXXXXXX")
What we know
- What they ask for: the fake site requests your full name, the vehicle's number plate and all your card details: number, expiry date and CVV code.
- How they pressure you: according to the examples INCIBE collected, the messages mention amounts of 100, 200 or 400 euros and threaten surcharges if payment isn't made within 24 hours. The fraudulent site shows a 140-euro charge "reduced" to 70 if paid on the spot.
- Why it works: it combines a body everyone knows, a small amount and immediate urgency. Few people stop to think before paying 70 euros to avoid a surcharge.
What we don't know yet
INCIBE gives no figures on how many messages have been sent, how many people have entered their details or who is behind the campaign.
Why it matters
The DGT is the focus of this alert, but the pattern is the usual one: an official sender, a manageable amount and a deadline. The same scheme is repeated with the Tax Agency, Social Security or courier companies. Learning to recognise it once protects you against all its variants.
What it means for an SME
The campaign is aimed at individuals, but it gets into a company in three ways:
- Companies with vehicles in their name: receiving traffic notices is normal, and whoever handles them may pay with the company card without a second thought.
- Gestorías handling traffic paperwork for clients: for you, an email about a traffic case file isn't unusual — it's everyday work. And a client may forward you the message asking whether they should pay it.
- Phones used for everything: the text arrives on a personal phone, but the card entered may be the company one.
What your company should do this week
- Share one clear rule with the whole team: fines are checked and paid by going to the official DGT website or app yourself, never through the link in a message. That's the verification INCIBE recommends.
- Appoint a single person to handle fines for company vehicles. Any notice, however it arrives, is forwarded to that person and never paid on the spot.
- If you're a gestoría, warn your clients about this campaign. It's a useful message that strengthens their trust in you.
- If someone has already entered their details, follow INCIBE's advice:
- Contact the bank through its official channels, ask for the card to be blocked and review the transactions.
- Call INCIBE's Cybersecurity Helpline on 017.
- Keep the evidence (messages, screenshots of the site) and report it to the police.
- If you only received the message and did nothing, block the sender, delete it and, if you like, report it to INCIBE's anti-fraud service.
If you want your team to learn to spot these messages with real examples, we explain it in our guide to phishing in gestorías (in Spanish).
Sources
- INCIBE — «Correos y SMS suplantan a la DGT para robar tus datos con falsas multas» (high-importance alert, 28 September 2026)Primary source
Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.
