Active Social Engineering and Financial Phishing Campaign-20260830007

SeverityHIGH
Threat CategorySocial Engineering / Phishing / Fraud
Affected PlatformsFacebook, Web Browsers (Mobile and Desktop)

1. Overview

The Bhutan Computer Incident Response Team (BtCIRT), under the GovTech Agency, is issuing this urgent security advisory to alert government offices, businesses, and the general public in Bhutan to an active financial fraud and social engineering campaign targeting users of local banking systems.
This security advisory is established upon verified threat identification and original alert details disclosed directly by the primary organizations in Bhutan:

  • Bhutan Computer Incident Response Team (BtCIRT), GovTech Agency — Issued an official scam warning on August 28, 2026, identifying fraudulent loan campaigns and detailing lookalike social media assets.
  • Bhutan National Bank (BNB) — Disclosed a formal Scam Alert warning customers against unauthorized Facebook advertisements that misuse the bank’s brand and mPay digital banking assets.
    The core mechanism of this campaign involves malicious actors setting up falsified Facebook pages designed to mimic the visual branding, logos, and names of trusted financial entities in Bhutan—specifically Bhutan National Bank (BNB) and DK Bank. These fake accounts post highly attractive, deceptive loan advertisements. When interested users interact with these posts, they are redirected to external, high-fidelity phishing websites designed to harvest sensitive personal data, physical credentials, and online banking logins.

2. Who is Affected

At the time of issuing this advisory, BtCIRT has confirmed that active phishing websites are actively online, specifically targeting citizens and customers of Bhutan National Bank and DK Bank. While the total number of compromised accounts remains under monitoring, the risk is assessed as extreme and immediate. This assessment is driven by the widespread reliance on Facebook for public outreach and information in Bhutan, combined with the professional visual mimicry of official bank portals used by the scammers.
The following fraudulent pages and phishing websites have been verified as active in this campaign. Individuals and organization members are strongly warned NOT to interact with, click, or enter information on these platforms:
Fraudulent Facebook Pages Identified:

  • Bhutan Bnb (links to the unofficial subdomain tss[.]it[.]com)
  • BnB Loan Services (links off Facebook to fraudulent portals bnblon[.]life and dkbh[.]live)


Verified Phishing Web Domains:

  • dkbh[.]live
  • dkbh[.]online
  • dklon.work
  • dkloan[.]online
  • bruk[.]tuch-id[.]it[.]com/tbhut/ (targeted phishing subdomain mimicking local portals)

3. How the [Threat/Vulnerability/Attack] Works

The fraudulent loan operation functions as a multi-stage social engineering pipeline:

  • Stage 1 – Digital Brand Duplication: The attackers construct highly professional lookalike Facebook pages such as ‘Bhutan Bnb’ and ‘BnB Loan Services’. They download and display official logos, brand typography, and promotional bank imagery (including specific marketing material for BNB’s ‘mPay’ platform) to establish direct psychological trust with unsuspecting visitors.
  • Stage 2 – Dissemination of Highly Lucrative Ad Lures: The compromised pages post and sponsor targeted advertisements promoting ‘guaranteed instant approval’ loans with highly unrealistic flat interest rates ranging from 2% to 5%. They emphasize that there is ‘no branch visit required’ and that the process is ‘fully paperless’ to exploit users seeking quick, convenient credit options.
  • Stage 3 – Routing to External Phishing Sites: When an interested victim clicks on the sponsored ‘Apply Now’ or ‘Verify’ call-to-action link, the request is directed away from Facebook’s safe infrastructure. It routes through lookalike or compromised subdomains (e.g., tss[.]it[.]com) and lands on highly realistic, spoofed banking pages like dkbh[.]live, dklon.work, or custom subdirectories mimicking official portals.
  • Stage 4 – High-Pressure Credential Harvesting: The fraudulent sites urge users to quickly submit their details to prevent their ‘application from being removed from the system’. Under this synthetic urgency, victims input their personal banking login details, Account Numbers, Citizenship Identity (CID) card numbers, and mobile-received One-Time Passwords (OTPs), or upload official identity documents.
    Impact: Victims face immediate and complete compromise of their online bank accounts, severe financial theft through unauthorized transactions, and exposure to long-term identity theft due to the submission of CID numbers, scanned documents, and multi-factor authentication (OTP) codes directly to cybercriminals.

4. Indicators to Watch For

Both public users and administrators should be highly alert to the following warning signs:

  • Suspiciously Generous Financial Terms: Any financial offer proposing flat, unusually low interest rates (e.g., 2%–5%), guaranteed instant approval, no in-person branch verification, or entirely paperless operations over social media.
  • Imperfect Social Media Names: Slight naming deviations or spelling variations from official channels. For example, ‘Bhutan Bnb’ instead of the official ‘Bhutan National Bank’, or generic services like ‘BnB Loan Services’ that lack verification badges, established follower history, or regular post history.
  • Urgent and Aggressive Pretexts: Direct messages or posts warning that a ‘loan application will be removed from the system’ or demanding that you must ‘Verify Now’ to continue using an active mobile banking account (such as mPay).
  • Non-Bank Domain Links: Unrecognized links and subdomains pointing to web domains not owned by the official banks. Critical examples include domains ending in TLDs like .life, .work, .online, or complex subdirectories hosted on third-party domains (e.g., tss[.]it[.]com).

5. Recommendations

For organizations and government offices:

  • Distribute this security advisory immediately to all department staff to prevent personnel from falling victim to identity theft or sharing corporate-associated banking details.
  • Implement network-level domain blocking on corporate firewalls and DNS resolvers for the identified malicious domains (bnblon.life, dkbh.live, dkbh.online, dklon.work, dkloan.online, and *.it.com).
  • Instruct administrative teams to monitor corporate proxy logs for any outward communication or data transfer attempts to the flagged phishing domains.
  • Ensure endpoint protection and email gateway filters are set up to scan and flag unsolicited messages containing these specific fraudulent URLs.

For individuals:

  • Verify the Source First: Only trust loan opportunities or maintenance notices posted directly on verified, official social media pages and banking sites. If you receive any notification or offer, verify its authenticity by calling the bank directly via their published, official customer support telephone numbers.
  • Avoid Unofficial External Links: Never click links embedded in Facebook posts, sponsored ads, or direct chat messages that claim to take you to a loan form or digital banking account ‘verification’ screen.
  • Withhold Sensitive Identification and OTPs: Never enter your Account Number, Citizenship Identity (CID) card number, passwords, or One-Time Passwords (OTPs) on any website reached via a social media link. Official banks will never ask you to submit OTPs or upload physical identity documents through social media platforms.
  • Analyze Account Authenticity: Inspect social media page details carefully before interacting. Look for the blue verification badge, evaluate the follower count, and review the overall history and tone of past publications.
  • Report and Block Fake Accounts: If you discover a fraudulent page mimicking a bank, use Facebook’s built-in reporting tool to flag it for impersonation, and block the page immediately.


If you have fallen victim to this scam:

  • Immediate Page Reporting: Flag the fraudulent page or post on Facebook using the in-app reporting system to ensure it is audited and removed, and block the profile to stop further communication.
  • Execute Stop Payments Immediately: If you have shared your financial details, OTP, card credentials, or made an upfront payment, contact your bank immediately to freeze your accounts, block cards, and stop any outgoing transfers.
  • Report the Crime to Law Enforcement: Formally report the incident to the Royal Bhutan Police (RBP) and your bank’s fraud unit to launch a trace, and contact the BtCIRT technical team for technical mitigation advice.

6. Reporting

If you suspect your organization, device, or personal banking account has been affected by this social engineering threat, or if you observe online activity matching the described pattern, please isolate the affected device and report it immediately to BtCIRT at cirt@btcirt.bt.

7. Sources and References

1. Bhutan Computer Incident Response Team (BtCIRT), GovTech Agency Scam Warning (August 28, 2026): “Fraudulent Loan Scams Impersonating Bhutan National Bank and DK Bank” — Official Alert Profile.

Scroll to Top