Over the weekend I left my car in an unusual spot. A few hours later my phone buzzed with a text from “Regitra”:
“Jūsų automobilis užregistruotas kaip pažeidęs parkavimo tvarką. Peržiūrėkite dokumentą čia: [link]”

(Your vehicle has been registered as violating parking rules. View the document here.)
My heart rate jumped. For a second, I believed it. I had parked somewhere odd, so the message fit my situation perfectly.
Then I looked at the link and remembered what Regitra actually does: vehicle registration and driver’s licences. Parking fines aren’t their job. They come from the police or municipal authorities. The domain was also a jumble of characters, nothing like an official address. I deleted the message and moved on.
The timing was pure coincidence, but that’s exactly why it’s worth writing about.
Why it almost worked
Scammers don’t need to be clever. They need to land a message at a moment when you’re primed to believe it. This one used three levers:
- Authority: a name you recognise and trust, in this case a state institution.
- Context: a plausible reason to be contacted. Most of us drive, and most of us have parked badly at some point.
- Urgency and fear: a fine implies a deadline, a penalty and a mistake you’ve made.
When all three line up, your brain reacts before it analyses. The emotional jolt comes first, and the rational check (“wait, does Regitra even do this?”) comes second, if at all. Scammers are counting on you to tap before the second step.
How these scams work behind the scenes
This type of attack is called smishing, which is phishing by SMS.
Here’s the typical chain:
- Mass sending. Criminals send thousands or millions of texts to numbers they’ve bought, scraped or simply generated. They don’t know who owns a car or where it’s parked. Some people will always happen to match, and that’s all they need.
- A lookalike link. The URL imitates a real institution with extra characters, a different domain ending, or random numbers. On a phone screen, where the address is truncated, it’s easy to miss.
- A fake page. The link opens a convincing copy of an official site or payment portal. It may ask you to “confirm the fine”, log in with your bank or e-government credentials, or enter card details to pay a small amount.
- Data harvesting. Whatever you type goes straight to the attacker. Some pages also ask for the one-time code your bank sends, which lets the criminal approve a transaction in real time while you think you’re paying a €15 fine.
Some of these messages can even appear in the same thread as genuine messages from the real sender, because SMS sender names can be spoofed. A familiar sender name is not proof.
What the consequences can be
- A small “fine” can be the entry point to something much bigger:
- Direct financial loss: drained bank accounts or unauthorised card payments, sometimes within minutes.
- Identity theft: names, ID numbers, addresses and vehicle details are enough to open accounts or run further scams in your name.
- Account takeover: if you reuse passwords, one stolen login can unlock your email, social media and online shopping.
- Malware: some links install malicious apps or prompt you to grant permissions that give attackers access to your phone.
- Follow-up attacks: once you’ve engaged, you may be flagged as a “responsive” target and hit with more convincing scams, such as a fake call from “your bank’s fraud department”.
What to do instead
Before you click:
Ask whether this organisation actually handles this matter. Regitra deals with registration and licences, not parking enforcement.
Never trust the link. Open the official website by typing the address yourself, or use the official app, and check for any real fine there.
Look at the domain character by character. Extra numbers, odd spellings and unfamiliar endings are red flags.
Be suspicious of any message that creates pressure to act immediately.
If you’ve already clicked or entered details:
- Call your bank right away. Block your cards and ask them to review recent transactions. Speed matters most here.
- Change your passwords for any account you entered, and for any other account that uses the same password. Turn on multi-factor authentication.
- Check your phone. If you installed anything or granted permissions, remove the app and consider running a security scan.
- Report it. Tell the police and your national cybersecurity authority (in Lithuania, the National Cyber Security Centre). The real institution being impersonated often wants to know too, as it helps them warn others.
- Watch for follow-ups. Expect suspicious calls or messages in the following days and treat them with extra caution.
The takeaway
I didn’t avoid this because I’m especially savvy. For a moment, my pulse went up like anyone’s would. What saved me was a habit: pause, then ask who actually handles this and where the link really goes.
Scammers rely on speed. A five-second pause is one of the strongest defences you have, so build it into the way you read messages.
Share this with someone who might tap before they think. And if you’ve had a close call yourself, I’d like to hear about it in the comments.