A mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and personal data, drawing 2,000+ FBI complaints within weeks of an April 2024 IC3 alert and continuing into 2025; the underlying 'Lighthouse' phishing kit was targeted by a Google civil lawsuit in November 2025.
Reviewed by the Social Engineering Examples team.
Starting in early 2024 and accelerating through 2025, toll-road customers across the U.S. received unsolicited SMS text messages claiming they owed a small unpaid toll balance and warning of late fees, account suspension, or referral to collections if they did not pay immediately. The texts included links to phishing websites spoofing the branding and domain style of real state DOTs and toll agencies (E-ZPass, SunPass, PA Turnpike, MassDOT/EZDriveMA, NTTA, Peach Pass, and others), which prompted victims to enter payment card numbers and, per FTC guidance, sometimes driver's license or Social Security numbers. The FBI's Internet Crime Complaint Center (IC3) issued Public Service Announcement I-041224-PSA, 'Smishing Scam Regarding Debt for Road Toll Services,' on April 12, 2024, after receiving more than 2,000 complaints in a matter of weeks. The scam did not stem from any breach of the toll agencies' own systems; agencies stated that legitimate account notices are never sent by unsolicited text demanding immediate payment. In November 2025, Google filed a civil lawsuit against the operators of 'Lighthouse,' the phishing-as-a-service kit that threat-intel vendors tie to this and other smishing campaigns (e.g., USPS delivery-fee smishing), seeking to dismantle the platform's infrastructure; this is the first substantial legal action connected to the kit behind the toll scams, though it is a civil suit rather than a criminal case.
The campaign relied on volume SMS blasts (smishing) sent to large numbers of phone numbers regardless of whether the recipient actually used the impersonated toll system, betting that enough recipients were genuine toll-road users to make the lure plausible. Messages used urgency language (act now, pay immediately, avoid a late fee or suspension) and impersonated official-looking domains resembling the real toll agency's name. Clicking the link led to a phishing page designed to harvest a small 'toll balance' payment via credit card, along with enough personal data to enable further fraud. Some later variants used reply-based workflows, where responding to the initial text triggered delivery of the live phishing link, likely to evade carrier and platform spam filters that scan for URLs in first-contact messages. Security vendors (Cisco Talos, Censys, Silent Push) linked the campaign's infrastructure and kits to commodity phishing-as-a-service platforms (Lucid, and the Smishing Triad's 'Lighthouse' kit) associated with Chinese-language cybercrime ecosystems, suggesting the same kit or affiliate network was resold or reused to spin up lookalike campaigns against toll agency after toll agency as it expanded state-to-state. Google's November 2025 civil complaint corroborates this account, describing Lighthouse as a subscription 'phishing for dummies' kit (SMS and e-commerce versions, hundreds of website templates) sold via Telegram/YouTube channels, with a 'Developer Group' (including the alias 'Wang Duo Yu'), a 'Spammer Group' that provides bulk-SMS infrastructure, and a 'Theft Group' that monetizes stolen credentials/cards.
The lure was a text stating an unpaid toll debt existed on the recipient's account, with a threat of a late fee, account suspension, or referral to collections/DMV if not paid immediately, and a link to 'pay now.' Tells included: the message coming from an unfamiliar or non-official short/long code number, a URL that resembled but did not exactly match the toll agency's real domain, arriving even for people who do not own an E-ZPass/SunPass/etc. transponder or who have no outstanding balance, and requests for a small payment amount via a generic-looking payment form rather than the agency's actual billing portal.
Toll agencies (PA Turnpike, MassDOT, SunPass/Florida's Turnpike, NTTA) and federal agencies (FBI IC3, FTC, FCC) issued repeated public consumer alerts throughout 2024 and into 2025 as the scam recurred and spread to additional states; FBI Atlanta issued a dedicated Peach Pass alert in March 2025. No breach of toll-agency systems occurred. As of the sources reviewed, no public arrests, indictments, or court judgments had been announced specifically tied to this toll-smishing campaign, and this remains true as of mid-2026: attribution to Chinese-linked phishing-as-a-service operators (Smishing Triad, Lucid, Darcula-adjacent tooling) still rests on private-sector threat intelligence rather than confirmed criminal law-enforcement action. The one legal-action update since the original research: on 2025-11-12, Google filed a civil lawsuit (RICO, Lanham Act, CFAA) in the Southern District of New York against 25 unnamed ('John Doe') operators of the Lighthouse phishing-as-a-service platform, the kit Cisco Talos and Netcraft tie to alias 'Wang Duo Yu' and to these toll-road smishing campaigns (among other Lighthouse-enabled scams, e.g. USPS delivery smishing). This is a private civil suit seeking a restraining order, infrastructure takedowns, and damages, not a criminal indictment or arrest. Google said that within roughly 24 hours of filing suit it had disrupted Lighthouse's infrastructure, citing translated Telegram messages in which an alleged operator wrote that the group's 'cloud server has been blocked,' though Google did not detail how the disruption was achieved. Independent researchers who track this ecosystem, including Ford Merrill of SecAlliance (quoted by KrebsOnSecurity), cautioned that the legal action may only temporarily disrupt this particular operation, even as it could make it easier for U.S. federal authorities to bring future criminal charges, given how lucrative the broader Chinese mobile-phishing market remains.
The campaign demonstrates how a single, low-cost commodity phishing kit can be resold or reused to mount parallel smishing waves against dozens of unrelated government agencies (toll authorities in different states) with minimal customization, exploiting the near-universal plausibility of 'you might owe a small toll fee' as a lure. It also shows the limits of the current U.S. response: despite tens of thousands of IC3 complaints and repeated agency alerts across two years, no criminal arrests or indictments have been publicly announced; the first notable legal action, Google's November 2025 civil RICO suit against the Lighthouse platform, came from a private company defending its trademarks and users rather than from law enforcement, underscoring the difficulty of disrupting SMS-based, likely offshore, phishing-as-a-service operations at scale through criminal channels alone.
FBI IC3, FTC, and FCC guidance consistently recommends: never click links in unsolicited toll-payment texts; check account status only by typing the agency's known official URL directly into a browser or by calling the agency's published customer service number; report smishing texts to the FTC (reportfraud.ftc.gov) and IC3 (ic3.gov), and forward the message to 7726 (SPAM); delete the text; and confirm real toll balances through the agency's official app or website rather than any link provided in a text. Toll agencies stated legitimate notices are never sent as urgent unsolicited payment-demand texts, and SunPass specified its legitimate texts originate only from a specific verified short code.
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…