Case Library / Smishing (SMS Phishing) / Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.

Share:

Social Engineering Examples·17 sources

What Happened

Starting in early 2024 and accelerating through 2025, toll-road customers across the U.S. received unsolicited SMS text messages claiming they owed a small unpaid toll balance and warning of late fees, account suspension, or referral to collections if they did not pay immediately. The texts included links to phishing websites spoofing the branding and domain style of real state DOTs and toll agencies (E-ZPass, SunPass, PA Turnpike, MassDOT/EZDriveMA, NTTA, Peach Pass, and others), which prompted victims to enter payment card numbers and, per FTC guidance, sometimes driver's license or Social Security numbers.

The FBI's Internet Crime Complaint Center (IC3) issued Public Service Announcement I-041224-PSA, 'Smishing Scam Regarding Debt for Road Toll Services,' on April 12, 2024, after receiving more than 2,000 complaints in a matter of weeks. The scam did not stem from any breach of the toll agencies' own systems; agencies stated that legitimate account notices are never sent by unsolicited text demanding immediate payment.

In November 2025, Google filed a civil lawsuit against the operators of 'Lighthouse,' the phishing-as-a-service kit that threat-intel vendors tie to this and other smishing campaigns (e.g., USPS delivery-fee smishing), seeking to dismantle the platform's infrastructure; this is the first substantial legal action connected to the kit behind the toll scams, though it is a civil suit rather than a criminal case.

How the Attack Worked

The campaign relied on volume SMS blasts (smishing) sent to large numbers of phone numbers regardless of whether the recipient actually used the impersonated toll system, betting that enough recipients were genuine toll-road users to make the lure plausible. Messages used urgency language (act now, pay immediately, avoid a late fee or suspension) and impersonated official-looking domains resembling the real toll agency's name.

Clicking the link led to a phishing page designed to harvest a small 'toll balance' payment via credit card, along with enough personal data to enable further fraud. Some later variants used reply-based workflows, where responding to the initial text triggered delivery of the live phishing link, likely to evade carrier and platform spam filters that scan for URLs in first-contact messages.

Security vendors (Cisco Talos, Censys, Silent Push) linked the campaign's infrastructure and kits to commodity phishing-as-a-service platforms (Lucid, and the Smishing Triad's 'Lighthouse' kit) associated with Chinese-language cybercrime ecosystems, suggesting the same kit or affiliate network was resold or reused to spin up lookalike campaigns against toll agency after toll agency as it expanded state-to-state.

Google's November 2025 civil complaint corroborates this account, describing Lighthouse as a subscription 'phishing for dummies' kit (SMS and e-commerce versions, hundreds of website templates) sold via Telegram/YouTube channels, with a 'Developer Group' (including the alias 'Wang Duo Yu'), a 'Spammer Group' that provides bulk-SMS infrastructure, and a 'Theft Group' that monetizes stolen credentials/cards.

The Lure & the Tell

The lure was a text stating an unpaid toll debt existed on the recipient's account, with a threat of a late fee, account suspension, or referral to collections/DMV if not paid immediately, and a link to 'pay now.' Tells included: the message coming from an unfamiliar or non-official short/long code number, a URL that resembled but did not exactly match the toll agency's real domain, arriving even for people who do not own an E-ZPass/SunPass/etc. transponder or who have no outstanding balance, and requests for a small payment amount via a generic-looking payment form rather than the agency's actual billing portal.

Outcome

Toll agencies (PA Turnpike, MassDOT, SunPass/Florida's Turnpike, NTTA) and federal agencies (FBI IC3, FTC, FCC) issued repeated public consumer alerts throughout 2024 and into 2025 as the scam recurred and spread to additional states; FBI Atlanta issued a dedicated Peach Pass alert in March 2025. No breach of toll-agency systems occurred. As of the sources reviewed, no public arrests, indictments, or court judgments had been announced specifically tied to this toll-smishing campaign, and this remains true as of mid-2026: attribution to Chinese-linked phishing-as-a-service operators (Smishing Triad, Lucid, Darcula-adjacent tooling) still rests on private-sector threat intelligence rather than confirmed criminal law-enforcement action.

The one legal-action update since the original research: on 2025-11-12, Google filed a civil lawsuit (RICO, Lanham Act, CFAA) in the Southern District of New York against 25 unnamed ('John Doe') operators of the Lighthouse phishing-as-a-service platform, the kit Cisco Talos and Netcraft tie to alias 'Wang Duo Yu' and to these toll-road smishing campaigns (among other Lighthouse-enabled scams, e.g.

USPS delivery smishing). This is a private civil suit seeking a restraining order, infrastructure takedowns, and damages, not a criminal indictment or arrest. Google said that within roughly 24 hours of filing suit it had disrupted Lighthouse's infrastructure, citing translated Telegram messages in which an alleged operator wrote that the group's 'cloud server has been blocked,' though Google did not detail how the disruption was achieved.

Independent researchers who track this ecosystem, including Ford Merrill of SecAlliance (quoted by KrebsOnSecurity), cautioned that the legal action may only temporarily disrupt this particular operation, even as it could make it easier for U.S. federal authorities to bring future criminal charges, given how lucrative the broader Chinese mobile-phishing market remains.

Why It Matters

The campaign demonstrates how a single, low-cost commodity phishing kit can be resold or reused to mount parallel smishing waves against dozens of unrelated government agencies (toll authorities in different states) with minimal customization, exploiting the near-universal plausibility of 'you might owe a small toll fee' as a lure. It also shows the limits of the current U.S. response: despite tens of thousands of IC3 complaints and repeated agency alerts across two years, no criminal arrests or indictments have been publicly announced; the first notable legal action, Google's November 2025 civil RICO suit against the Lighthouse platform, came from a private company defending its trademarks and users rather than from law enforcement, underscoring the difficulty of disrupting SMS-based, likely offshore, phishing-as-a-service operations at scale through criminal channels alone.

Defenses

FBI IC3, FTC, and FCC guidance consistently recommends: never click links in unsolicited toll-payment texts; check account status only by typing the agency's known official URL directly into a browser or by calling the agency's published customer service number; report smishing texts to the FTC (reportfraud.ftc.gov) and IC3 (ic3.gov), and forward the message to 7726 (SPAM); delete the text; and confirm real toll balances through the agency's official app or website rather than any link provided in a text.

Toll agencies stated legitimate notices are never sent as urgent unsolicited payment-demand texts, and SunPass specified its legitimate texts originate only from a specific verified short code.

Sources
Cite this case

Social Engineering Examples. “Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)”. Accessed 19 September 2026. https://socialengineeringexamples.com/toll-road-smishing-wave-2024-2025

Attack Chain & Defense
1Target-list and lure sourcing
What happened

Operators of the underlying phishing-as-a-service kits (Lucid, Lighthouse/Smishing Triad) typically acquire large phone-number lists from data brokers, prior breach dumps, or bulk-SMS infrastructure providers, rather than targeting specific known toll-account holders, betting that enough recipients in any large batch are genuine toll-road users to make the lure land; Cisco Talos noted it lacked direct evidence of which leaked datasets, if any, fed this specific campaign.

The control that would have stopped it

Consumers cannot prevent their phone numbers from circulating in data-broker or breach-derived lists, so the realistic control sits downstream of this stage, in carrier-level filtering and consumer skepticism toward any unsolicited toll text rather than in stopping number harvesting itself.

2Kit acquisition and infrastructure setup
What happened

Per Cisco Talos and Silent Push, affiliates subscribe to a commercial phishing-as-a-service platform (Lucid or Lighthouse, tied to the alias 'Wang Duo Yu' and the 'Smishing Triad' ecosystem) via Telegram, which supplies ready-made toll-agency-branded website templates, rotating look-alike domains, and bulk iMessage/RCS messaging tools designed to evade carrier spam filters.

The control that would have stopped it

Telecom carriers and platform providers (Apple/Google for iMessage/RCS) disrupting known phishing-as-a-service infrastructure, and legal action like Google's 2025 civil suit seeking to take down Lighthouse's domains and accounts, targets this stage directly, though take-down efforts compete with kits that can rotate domains and servers within hours.

3Mass SMS blast
What happened

The kit's bulk-messaging infrastructure sends near-identical 'you owe a small unpaid toll' texts to large numbers of phone numbers regardless of whether the recipient uses the impersonated toll system, using urgency language (late fee, suspension, collections) and a link or reply-to-unlock link, per FBI IC3 and Censys/Prodaft reporting.

The control that would have stopped it

Carrier spam filtering, keyword/URL detection on inbound SMS, and reporting suspicious texts to 7726 (SPAM) as FTC/FCC/FBI guidance recommends, helps catch and get blasts blocked, though reply-gated links are specifically designed to evade first-contact URL scanning.

4Victim clicks or replies
What happened

The recipient, often a genuine toll-road user who finds the small dollar amount plausible, either clicks the embedded link directly or replies to the text first (a later variant Censys documented, which delays sending the live phishing link until after a reply to dodge first-contact URL scanning).

The control that would have stopped it

Consumer education from toll agencies and federal agencies (never click links in unsolicited toll texts, verify only via a known official app, website typed directly into a browser, or published customer-service number) is the single highest-leverage control, since it stops the chain before any data is entered regardless of how the message got through.

5Credential and payment-data harvesting
What happened

The victim lands on a look-alike toll-agency page and enters payment card details and, per FTC guidance, sometimes driver's license or Social Security numbers into a form designed purely to capture that data, with no real toll balance ever displayed by a legitimate agency system.

The control that would have stopped it

Toll agencies stating clearly that legitimate notices are never sent as urgent unsolicited payment-demand texts (and, per SunPass, only from one verified short code) gives consumers a concrete way to distinguish real from fake at the point of decision, and payment processors' fraud-detection rules can flag card-not-present charges routed through newly registered look-alike domains.

6Monetization and cash-out
What happened

Per Google's civil complaint and Silent Push, a separate 'theft group' within the phishing-as-a-service ecosystem resells or directly uses the harvested card and personal data, completing the objective of payment-card fraud and identity-data theft without ever touching a real toll agency's systems.

The control that would have stopped it

Card issuers' post-compromise fraud monitoring, rapid card reissuance once a breach pattern is identified, and civil/criminal legal action against the phishing-as-a-service operators and their monetization networks are the realistic controls at this final stage, since by this point the individual consumer can no longer prevent the harm, only limit and report it.

Quick Facts
Victim
Toll customers of E-ZPass
(Northeast/Mid-Atlantic), SunPass/Florida's Turnpike, Pennsylvania Turnpike, MassDOT/EZDriveMA (Massachusetts), NTTA (North Texas Tollway Authority), Peach Pass (Georgia), and per FCC guidance also FasTrak (California) and I-PASS (Illinois) customers, across dozens of U.S. states.
Location
United States (nationwide, spreading state-to-state)
Date
2024-04 to 2025
(ongoing recurrence); FBI IC3 PSA issued 2024-04-12; Cisco Talos traces campaign activity to approximately October 2024; FBI Atlanta issued a Peach Pass-specific alert 2025-03-12; PA Turnpike issued a follow-up alert 2025-02-13; Google filed a civil RICO/Lanham Act/CFAA lawsuit against the 'Lighthouse' phishing-as-a-service platform (the kit tied to this campaign) on 2025-11-12
Impact
FBI IC3 2024 Annual Report lists the toll-smishing category at 59,271 complaints and $129,624 in total reported losses for 2024.
FBI Atlanta's Peach Pass-specific alert (2025-03-12) reported 1,720 complaints (Jan 1, 2024 - Feb 28, 2025), including 1,573 in March 2025 alone, and $3,643.42 in losses for that Georgia-specific surge. These are reported/complaint-based figures, likely undercounts of true losses since not all victims file IC3 complaints. Separately, Google's November 2025 civil complaint against the Lighthouse phishing-as-a-service platform (used in this and other campaigns, e.g. USPS smishing) alleges the kit compromised an estimated 12.7 million to 115 million payment cards in the U.S. alone between July 2023 and October 2024 across all Lighthouse-enabled scams (not toll-scam-specific), and affected over 1 million victims in 120+ countries; this figure is from Google's civil pleading, not an adjudicated finding.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Government & Public Sector
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.