Fraudulent messages have been identified through which citizens are sent false notifications of traffic fines, requesting payment through links.
One such message, sent to hibrid.info by a reader, had the telephone prefix “+63” and was presented on behalf of the Kosovo Vehicle Management.
The content of the message claims that the recipient can pay the fine with a 50% discount if payment is made within 24 hours of receiving the notification.
The message also warns that, in the event of non-payment, the case will be taken to court and the freezing of bank accounts and other assets will follow.
What is the truth?
Such messages are misleading.

First, the telephone prefix of the sender of this message does not belong to the state of Kosovo. After research, it was found that the prefix “+63” is used in the Philippines (see here).
Subsequently, hibrid.info directly checked the link contained in the message (see here). After opening it, a page appears that has the logo of the state electronic platform "E-Kosova", with a space where you are required to enter your car's license plate data, in order to proceed with the payment of the claimed fine.

After entering the fictitious data, the next page opened contains a digital notice for a traffic fine titled "Traffic violation recorded". At the top is a field showing the verified driving license number with the value 08-234-AB, followed by a yellow background notification text explaining that the violation occurred for excessive speed in a radar-controlled urban area, specifying that no penalty points are applied.
In the middle of the page is a structured table with indicators and values, specifying that the speed recorded is 57 km/h in a zone where the limit was 50 km/h. It also states that the penalty points are 0, the date of the violation is 16/05/2026, the regular amount of the fine is €80.00, while the amount with a 50% discount if paid within 7 days is €40.00.
Below this table is a large blue button that says “Continue.” The page concludes at the bottom with another box with a yellow frame, listing four warning points about the administrative and financial measures that will follow if payment is not made within the required deadline, such as loss of discount, increase in debt due to interest, and further procedures for recovering the amount.

After continuing, the page opens, where the user is sent to a form titled “Secure Payment” to pay the fine. In the upper left corner, the logo of the “eKosova” platform is visible, followed by a subtitle stating that personal data is protected and not shared with third parties.
The transaction details are displayed in a box with a yellow frame, where the reference number is marked as XK-U82JK1056 and the amount for payment is specified at €40.
Below is the bank card payment form, which requires the completion of mandatory fields marked with a red asterisk. The fields include the name of the cardholder, the card number (under which the logos of payment networks such as Visa, Mastercard, Amex and Diners appear), the expiration date in MM/YY format, and the CVV security code. At the end of these fields is a large blue button that says “Send”, while at the bottom of the entire page, in small letters, is placed text claiming that the project was made possible by the Information Society Agency (ASHI) and the Ministry of Interior, Government of Kosovo.

Due to suspicions, the investigation was not continued with the provision of bank data.
Hibrid.info tried to verify the URL through the "urlscan" service.
The official state website is "ekosova.rks-gov.net”. The address “ekosova.rksgov.bond” appears to have been created by removing the hyphen '-' and replacing the suffix “.net” with “.bond” (a private domain).
The scan shows that this site is located on a server in Frankfurt, Germany, which is owned by the Chinese technology company Tencent.
Although the site has the security padlock symbol (https://), scanning reveals that this certificate was only issued for 3 months.
Technical scanning reveals that the backend of the site is built as an interactive application (using Vue.js code). This means that as soon as the citizen presses the “Submit” button, the code is programmed to retrieve the bank card details and immediately send them to the server.

So, based on this scan data, due to technical inconsistencies, the URL of the link sent in this message can be assessed as suspicious.
Another fact that makes the message suspicious are the public announcements on Friday (May 22) by institutions such as "Ministry of Internal Affairs","Kosovo Police" and the platform "e-Kosovo", through which it has been made known that messages with this content and sent in this format are frauds.
In institutional responses, citizens who receive these messages are asked not to click on the included links and to report the cases to the relevant institutions.
Analyze:
Traffic fine messages are not legal and are not sent by official Kosovo institutions.
Such messages contain typical elements of fraudulent schemes, including the use of a telephone prefix that does not belong to Kosovo and requests for payments through suspicious links.
Analysis of the link included in the message reveals a page that imitates the state platform "e-Kosova", but uses a different domain than the official one and requests banking data, which is not practiced by public institutions.
Technical scans show that the site is hosted on external infrastructure and built as an interactive application, designed to collect bank card data.
Also, relevant institutions in Kosovo have publicly confirmed that such messages are scams and have called on citizens not to click on such links and to report the cases.
Therefore, based on the evaluation methodology, hibrid.info rates the content as "Fraud".
rationale
The “Deception” rating is given to informational content that is manipulated in terms of visual (deepfake, cheapfake), audio, or textual content to deceive the audience. This form of deception is usually used to produce false and manipulated content.