Residents throughout the US are being inundated with textual content messages purporting to return from toll highway operators like E-ZPass, warning that recipients face fines if a delinquent toll charge stays unpaid. Researchers say the surge in SMS spam coincides with new options added to a preferred business phishing equipment offered in China that makes it easy to arrange convincing lures spoofing toll highway operators in a number of U.S. states.
Final week, the Massachusetts Division of Transportation (MassDOT) warned residents to be looking out for a brand new SMS phishing or “smishing” rip-off concentrating on customers of EZDriveMA, MassDOT’s all digital tolling program. Those that fall for the rip-off are requested to offer cost card information, and ultimately shall be requested to produce a one-time password despatched through SMS or a cell authentication app.
Studies of comparable SMS phishing assaults towards prospects of different U.S. state-run toll amenities surfaced across the similar time because the MassDOT alert. Folks in Florida reported receiving SMS phishing that spoofed Sunpass, Florida’s pay as you go toll program.
This phishing module for spoofing MassDOT’s EZDrive toll system was provided on Jan. 10, 2025 by a China-based SMS phishing service known as “Lighthouse.”
In Texas, residents mentioned they obtained textual content messages about unpaid tolls with the North Texas Toll Authority. Related reviews got here from readers in California, Colorado, Connecticut, Minnesota, and Washington. That is not at all a complete record.

A brand new module from the Lighthouse SMS phishing equipment launched Jan. 14 targets prospects of the North Texas Toll Authority (NTTA).
In every case, the emergence of those SMS phishing assaults coincided with the discharge of latest phishing equipment capabilities that carefully mimic these toll operator web sites as they seem on cell units. Notably, not one of the phishing pages will even load until the web site detects that the customer is coming from a cell gadget.
Ford Merrill works in safety analysis at SecAlliance, a CSIS Security Group firm. Merrill mentioned the amount of SMS phishing assaults spoofing toll highway operators skyrocketed after the New Yr, when at the least one Chinese language cybercriminal group recognized for promoting refined SMS phishing kits started providing new phishing pages designed to spoof toll operators in varied U.S. states.
In line with Merrill, a number of China-based cybercriminals are promoting distinct SMS-based phishing kits that every have a whole lot or hundreds of consumers. The final word objective of those kits, he mentioned, is to phish sufficient data from victims that their cost playing cards will be added to cell wallets and used to purchase items at bodily shops, on-line, or to launder cash by shell corporations.

A element of the Chinese language SMS phishing equipment Lighthouse made to focus on prospects of The Toll Roads, which refers to a number of state routes by Orange County, Calif.
Merrill mentioned the totally different purveyors of those SMS phishing instruments historically have impersonated transport corporations, customs authorities, and even governments with tax refund lures and visa or immigration renewal scams concentrating on individuals who could also be residing overseas or new to a rustic.
“What we’re seeing with these tolls scams is only a continuation of the Chinese language smishing teams rotating from package deal redelivery schemes to toll highway scams,” Merrill mentioned. “Each one in every of us by now could be sick and bored with receiving these package deal smishing assaults, so now it’s a brand new twist on an present rip-off.”
In October 2023, KrebsOnSecurity wrote a couple of large uptick in SMS phishing scams concentrating on U.S. Postal Service prospects. That story revealed the surge was tied to improvements launched by “Chenlun,” a mainland China-based proprietor of a preferred phishing equipment and repair. On the time, Chenlun had simply launched new phishing pages made to impersonate postal companies in the US and at the least a dozen different nations.
SMS phishing kits are hardly new, however Merrill mentioned Chinese language smishing teams just lately have launched improvements in deliverability, by extra seamlessly integrating their spam messages with Apple’s iMessage expertise, and with RCS, the equal “wealthy textual content” messaging functionality constructed into Android units.
“Whereas conventional smishing kits relied closely on SMS for supply, these days the actors make heavy use of iMessage and RCS as a result of telecom operators can’t filter them and so they probably have a better success charge with these supply channels,” he mentioned.
It stays unclear how the phishers have chosen their targets, or from the place their information could also be sourced. A discover from MassDOT cautions that “the focused cellphone numbers appear to be chosen at random and should not uniquely related to an account or utilization of toll roads.”
Certainly, one reader shared on Mastodon yesterday that they’d obtained one in every of these SMS phishing assaults spoofing an area toll operator, once they didn’t even personal a car.
Focused or not, these phishing web sites are harmful as a result of they’re operated dynamically in real-time by criminals. In case you obtain one in every of these messages, simply ignore it or delete it, however please don’t go to the phishing website. The FBI asks that earlier than you bin the missives, contemplate submitting a criticism with the company’s Internet Crime Complaint Center (IC3), together with the cellphone quantity the place the textual content originated, and the web site listed inside the textual content.