Case Library / Smishing (SMS Phishing) / Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

A mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and personal data, drawing 2,000+ FBI complaints within weeks of an April 2024 IC3 alert and continuing into 2025; the underlying 'Lighthouse' phishing kit was targeted by a Google civil lawsuit in November 2025.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Starting in early 2024 and accelerating through 2025, toll-road customers across the U.S. received unsolicited SMS text messages claiming they owed a small unpaid toll balance and warning of late fees, account suspension, or referral to collections if they did not pay immediately. The texts included links to phishing websites spoofing the branding and domain style of real state DOTs and toll agencies (E-ZPass, SunPass, PA Turnpike, MassDOT/EZDriveMA, NTTA, Peach Pass, and others), which prompted victims to enter payment card numbers and, per FTC guidance, sometimes driver's license or Social Security numbers. The FBI's Internet Crime Complaint Center (IC3) issued Public Service Announcement I-041224-PSA, 'Smishing Scam Regarding Debt for Road Toll Services,' on April 12, 2024, after receiving more than 2,000 complaints in a matter of weeks. The scam did not stem from any breach of the toll agencies' own systems; agencies stated that legitimate account notices are never sent by unsolicited text demanding immediate payment. In November 2025, Google filed a civil lawsuit against the operators of 'Lighthouse,' the phishing-as-a-service kit that threat-intel vendors tie to this and other smishing campaigns (e.g., USPS delivery-fee smishing), seeking to dismantle the platform's infrastructure; this is the first substantial legal action connected to the kit behind the toll scams, though it is a civil suit rather than a criminal case.

How the Attack Worked

The campaign relied on volume SMS blasts (smishing) sent to large numbers of phone numbers regardless of whether the recipient actually used the impersonated toll system, betting that enough recipients were genuine toll-road users to make the lure plausible. Messages used urgency language (act now, pay immediately, avoid a late fee or suspension) and impersonated official-looking domains resembling the real toll agency's name. Clicking the link led to a phishing page designed to harvest a small 'toll balance' payment via credit card, along with enough personal data to enable further fraud. Some later variants used reply-based workflows, where responding to the initial text triggered delivery of the live phishing link, likely to evade carrier and platform spam filters that scan for URLs in first-contact messages. Security vendors (Cisco Talos, Censys, Silent Push) linked the campaign's infrastructure and kits to commodity phishing-as-a-service platforms (Lucid, and the Smishing Triad's 'Lighthouse' kit) associated with Chinese-language cybercrime ecosystems, suggesting the same kit or affiliate network was resold or reused to spin up lookalike campaigns against toll agency after toll agency as it expanded state-to-state. Google's November 2025 civil complaint corroborates this account, describing Lighthouse as a subscription 'phishing for dummies' kit (SMS and e-commerce versions, hundreds of website templates) sold via Telegram/YouTube channels, with a 'Developer Group' (including the alias 'Wang Duo Yu'), a 'Spammer Group' that provides bulk-SMS infrastructure, and a 'Theft Group' that monetizes stolen credentials/cards.

The Lure & the Tell

The lure was a text stating an unpaid toll debt existed on the recipient's account, with a threat of a late fee, account suspension, or referral to collections/DMV if not paid immediately, and a link to 'pay now.' Tells included: the message coming from an unfamiliar or non-official short/long code number, a URL that resembled but did not exactly match the toll agency's real domain, arriving even for people who do not own an E-ZPass/SunPass/etc. transponder or who have no outstanding balance, and requests for a small payment amount via a generic-looking payment form rather than the agency's actual billing portal.

Outcome

Toll agencies (PA Turnpike, MassDOT, SunPass/Florida's Turnpike, NTTA) and federal agencies (FBI IC3, FTC, FCC) issued repeated public consumer alerts throughout 2024 and into 2025 as the scam recurred and spread to additional states; FBI Atlanta issued a dedicated Peach Pass alert in March 2025. No breach of toll-agency systems occurred. As of the sources reviewed, no public arrests, indictments, or court judgments had been announced specifically tied to this toll-smishing campaign, and this remains true as of mid-2026: attribution to Chinese-linked phishing-as-a-service operators (Smishing Triad, Lucid, Darcula-adjacent tooling) still rests on private-sector threat intelligence rather than confirmed criminal law-enforcement action. The one legal-action update since the original research: on 2025-11-12, Google filed a civil lawsuit (RICO, Lanham Act, CFAA) in the Southern District of New York against 25 unnamed ('John Doe') operators of the Lighthouse phishing-as-a-service platform, the kit Cisco Talos and Netcraft tie to alias 'Wang Duo Yu' and to these toll-road smishing campaigns (among other Lighthouse-enabled scams, e.g. USPS delivery smishing). This is a private civil suit seeking a restraining order, infrastructure takedowns, and damages, not a criminal indictment or arrest. Google said that within roughly 24 hours of filing suit it had disrupted Lighthouse's infrastructure, citing translated Telegram messages in which an alleged operator wrote that the group's 'cloud server has been blocked,' though Google did not detail how the disruption was achieved. Independent researchers who track this ecosystem, including Ford Merrill of SecAlliance (quoted by KrebsOnSecurity), cautioned that the legal action may only temporarily disrupt this particular operation, even as it could make it easier for U.S. federal authorities to bring future criminal charges, given how lucrative the broader Chinese mobile-phishing market remains.

Why It Matters

The campaign demonstrates how a single, low-cost commodity phishing kit can be resold or reused to mount parallel smishing waves against dozens of unrelated government agencies (toll authorities in different states) with minimal customization, exploiting the near-universal plausibility of 'you might owe a small toll fee' as a lure. It also shows the limits of the current U.S. response: despite tens of thousands of IC3 complaints and repeated agency alerts across two years, no criminal arrests or indictments have been publicly announced; the first notable legal action, Google's November 2025 civil RICO suit against the Lighthouse platform, came from a private company defending its trademarks and users rather than from law enforcement, underscoring the difficulty of disrupting SMS-based, likely offshore, phishing-as-a-service operations at scale through criminal channels alone.

Defenses

FBI IC3, FTC, and FCC guidance consistently recommends: never click links in unsolicited toll-payment texts; check account status only by typing the agency's known official URL directly into a browser or by calling the agency's published customer service number; report smishing texts to the FTC (reportfraud.ftc.gov) and IC3 (ic3.gov), and forward the message to 7726 (SPAM); delete the text; and confirm real toll balances through the agency's official app or website rather than any link provided in a text. Toll agencies stated legitimate notices are never sent as urgent unsolicited payment-demand texts, and SunPass specified its legitimate texts originate only from a specific verified short code.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target-list and lure sourcing: Operators of the underlying phishing-as-a-service kits (Lucid, Lighthouse/Smishing Triad) typically acquire large phone-number lists from data brokers, prior breach dumps, or bulk-SMS infrastructure providers, rather than targeting specific known toll-account holders, betting that enough recipients in any large batch are genuine toll-road users to make the lure land; Cisco Talos noted it lacked direct evidence of which leaked datasets, if any, fed this specific campaign.
Countering Stage 1: Consumers cannot prevent their phone numbers from circulating in data-broker or breach-derived lists, so the realistic control sits downstream of this stage, in carrier-level filtering and consumer skepticism toward any unsolicited toll text rather than in stopping number harvesting itself.
2
Kit acquisition and infrastructure setup: Per Cisco Talos and Silent Push, affiliates subscribe to a commercial phishing-as-a-service platform (Lucid or Lighthouse, tied to the alias 'Wang Duo Yu' and the 'Smishing Triad' ecosystem) via Telegram, which supplies ready-made toll-agency-branded website templates, rotating look-alike domains, and bulk iMessage/RCS messaging tools designed to evade carrier spam filters.
Countering Stage 2: Telecom carriers and platform providers (Apple/Google for iMessage/RCS) disrupting known phishing-as-a-service infrastructure, and legal action like Google's 2025 civil suit seeking to take down Lighthouse's domains and accounts, targets this stage directly, though take-down efforts compete with kits that can rotate domains and servers within hours.
3
Mass SMS blast: The kit's bulk-messaging infrastructure sends near-identical 'you owe a small unpaid toll' texts to large numbers of phone numbers regardless of whether the recipient uses the impersonated toll system, using urgency language (late fee, suspension, collections) and a link or reply-to-unlock link, per FBI IC3 and Censys/Prodaft reporting.
Countering Stage 3: Carrier spam filtering, keyword/URL detection on inbound SMS, and reporting suspicious texts to 7726 (SPAM) as FTC/FCC/FBI guidance recommends, helps catch and get blasts blocked, though reply-gated links are specifically designed to evade first-contact URL scanning.
4
Victim clicks or replies: The recipient, often a genuine toll-road user who finds the small dollar amount plausible, either clicks the embedded link directly or replies to the text first (a later variant Censys documented, which delays sending the live phishing link until after a reply to dodge first-contact URL scanning).
Countering Stage 4: Consumer education from toll agencies and federal agencies (never click links in unsolicited toll texts, verify only via a known official app, website typed directly into a browser, or published customer-service number) is the single highest-leverage control, since it stops the chain before any data is entered regardless of how the message got through.
5
Credential and payment-data harvesting: The victim lands on a look-alike toll-agency page and enters payment card details and, per FTC guidance, sometimes driver's license or Social Security numbers into a form designed purely to capture that data, with no real toll balance ever displayed by a legitimate agency system.
Countering Stage 5: Toll agencies stating clearly that legitimate notices are never sent as urgent unsolicited payment-demand texts (and, per SunPass, only from one verified short code) gives consumers a concrete way to distinguish real from fake at the point of decision, and payment processors' fraud-detection rules can flag card-not-present charges routed through newly registered look-alike domains.
6
Monetization and cash-out: Per Google's civil complaint and Silent Push, a separate 'theft group' within the phishing-as-a-service ecosystem resells or directly uses the harvested card and personal data, completing the objective of payment-card fraud and identity-data theft without ever touching a real toll agency's systems.
Countering Stage 6: Card issuers' post-compromise fraud monitoring, rapid card reissuance once a breach pattern is identified, and civil/criminal legal action against the phishing-as-a-service operators and their monetization networks are the realistic controls at this final stage, since by this point the individual consumer can no longer prevent the harm, only limit and report it.
Quick Facts
Victim
Toll customers of E-ZPass (Northeast/Mid-Atlantic), SunPass/Florida's Turnpike, Pennsylvania Turnpike, MassDOT/EZDriveMA (Massachusetts), NTTA (North Texas Tollway Authority), Peach Pass (Georgia), and per FCC guidance also FasTrak (California) and I-PASS (Illinois) customers, across dozens of U.S. states.
Location
United States (nationwide, spreading state-to-state)
Date
2024-04 to 2025 (ongoing recurrence); FBI IC3 PSA issued 2024-04-12; Cisco Talos traces campaign activity to approximately October 2024; FBI Atlanta issued a Peach Pass-specific alert 2025-03-12; PA Turnpike issued a follow-up alert 2025-02-13; Google filed a civil RICO/Lanham Act/CFAA lawsuit against the 'Lighthouse' phishing-as-a-service platform (the kit tied to this campaign) on 2025-11-12
Impact
FBI IC3 2024 Annual Report lists the toll-smishing category at 59,271 complaints and $129,624 in total reported losses for 2024. FBI Atlanta's Peach Pass-specific alert (2025-03-12) reported 1,720 complaints (Jan 1, 2024 - Feb 28, 2025), including 1,573 in March 2025 alone, and $3,643.42 in losses for that Georgia-specific surge. These are reported/complaint-based figures, likely undercounts of true losses since not all victims file IC3 complaints. Separately, Google's November 2025 civil complaint against the Lighthouse phishing-as-a-service platform (used in this and other campaigns, e.g. USPS smishing) alleges the kit compromised an estimated 12.7 million to 115 million payment cards in the U.S. alone between July 2023 and October 2024 across all Lighthouse-enabled scams (not toll-scam-specific), and affected over 1 million victims in 120+ countries; this figure is from Google's civil pleading, not an adjudicated finding.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing…

Incident 2024Read →

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…

Incident 2023Read →

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…

Incident 2025Read →