A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Social Engineering Examples·17 sources
Starting in early 2024 and accelerating through 2025, toll-road customers across the U.S. received unsolicited SMS text messages claiming they owed a small unpaid toll balance and warning of late fees, account suspension, or referral to collections if they did not pay immediately. The texts included links to phishing websites spoofing the branding and domain style of real state DOTs and toll agencies (E-ZPass, SunPass, PA Turnpike, MassDOT/EZDriveMA, NTTA, Peach Pass, and others), which prompted victims to enter payment card numbers and, per FTC guidance, sometimes driver's license or Social Security numbers.
The FBI's Internet Crime Complaint Center (IC3) issued Public Service Announcement I-041224-PSA, 'Smishing Scam Regarding Debt for Road Toll Services,' on April 12, 2024, after receiving more than 2,000 complaints in a matter of weeks. The scam did not stem from any breach of the toll agencies' own systems; agencies stated that legitimate account notices are never sent by unsolicited text demanding immediate payment.
In November 2025, Google filed a civil lawsuit against the operators of 'Lighthouse,' the phishing-as-a-service kit that threat-intel vendors tie to this and other smishing campaigns (e.g., USPS delivery-fee smishing), seeking to dismantle the platform's infrastructure; this is the first substantial legal action connected to the kit behind the toll scams, though it is a civil suit rather than a criminal case.
The campaign relied on volume SMS blasts (smishing) sent to large numbers of phone numbers regardless of whether the recipient actually used the impersonated toll system, betting that enough recipients were genuine toll-road users to make the lure plausible. Messages used urgency language (act now, pay immediately, avoid a late fee or suspension) and impersonated official-looking domains resembling the real toll agency's name.
Clicking the link led to a phishing page designed to harvest a small 'toll balance' payment via credit card, along with enough personal data to enable further fraud. Some later variants used reply-based workflows, where responding to the initial text triggered delivery of the live phishing link, likely to evade carrier and platform spam filters that scan for URLs in first-contact messages.
Security vendors (Cisco Talos, Censys, Silent Push) linked the campaign's infrastructure and kits to commodity phishing-as-a-service platforms (Lucid, and the Smishing Triad's 'Lighthouse' kit) associated with Chinese-language cybercrime ecosystems, suggesting the same kit or affiliate network was resold or reused to spin up lookalike campaigns against toll agency after toll agency as it expanded state-to-state.
Google's November 2025 civil complaint corroborates this account, describing Lighthouse as a subscription 'phishing for dummies' kit (SMS and e-commerce versions, hundreds of website templates) sold via Telegram/YouTube channels, with a 'Developer Group' (including the alias 'Wang Duo Yu'), a 'Spammer Group' that provides bulk-SMS infrastructure, and a 'Theft Group' that monetizes stolen credentials/cards.
The lure was a text stating an unpaid toll debt existed on the recipient's account, with a threat of a late fee, account suspension, or referral to collections/DMV if not paid immediately, and a link to 'pay now.' Tells included: the message coming from an unfamiliar or non-official short/long code number, a URL that resembled but did not exactly match the toll agency's real domain, arriving even for people who do not own an E-ZPass/SunPass/etc. transponder or who have no outstanding balance, and requests for a small payment amount via a generic-looking payment form rather than the agency's actual billing portal.
Toll agencies (PA Turnpike, MassDOT, SunPass/Florida's Turnpike, NTTA) and federal agencies (FBI IC3, FTC, FCC) issued repeated public consumer alerts throughout 2024 and into 2025 as the scam recurred and spread to additional states; FBI Atlanta issued a dedicated Peach Pass alert in March 2025. No breach of toll-agency systems occurred. As of the sources reviewed, no public arrests, indictments, or court judgments had been announced specifically tied to this toll-smishing campaign, and this remains true as of mid-2026: attribution to Chinese-linked phishing-as-a-service operators (Smishing Triad, Lucid, Darcula-adjacent tooling) still rests on private-sector threat intelligence rather than confirmed criminal law-enforcement action.
The one legal-action update since the original research: on 2025-11-12, Google filed a civil lawsuit (RICO, Lanham Act, CFAA) in the Southern District of New York against 25 unnamed ('John Doe') operators of the Lighthouse phishing-as-a-service platform, the kit Cisco Talos and Netcraft tie to alias 'Wang Duo Yu' and to these toll-road smishing campaigns (among other Lighthouse-enabled scams, e.g.
USPS delivery smishing). This is a private civil suit seeking a restraining order, infrastructure takedowns, and damages, not a criminal indictment or arrest. Google said that within roughly 24 hours of filing suit it had disrupted Lighthouse's infrastructure, citing translated Telegram messages in which an alleged operator wrote that the group's 'cloud server has been blocked,' though Google did not detail how the disruption was achieved.
Independent researchers who track this ecosystem, including Ford Merrill of SecAlliance (quoted by KrebsOnSecurity), cautioned that the legal action may only temporarily disrupt this particular operation, even as it could make it easier for U.S. federal authorities to bring future criminal charges, given how lucrative the broader Chinese mobile-phishing market remains.
The campaign demonstrates how a single, low-cost commodity phishing kit can be resold or reused to mount parallel smishing waves against dozens of unrelated government agencies (toll authorities in different states) with minimal customization, exploiting the near-universal plausibility of 'you might owe a small toll fee' as a lure. It also shows the limits of the current U.S. response: despite tens of thousands of IC3 complaints and repeated agency alerts across two years, no criminal arrests or indictments have been publicly announced; the first notable legal action, Google's November 2025 civil RICO suit against the Lighthouse platform, came from a private company defending its trademarks and users rather than from law enforcement, underscoring the difficulty of disrupting SMS-based, likely offshore, phishing-as-a-service operations at scale through criminal channels alone.
FBI IC3, FTC, and FCC guidance consistently recommends: never click links in unsolicited toll-payment texts; check account status only by typing the agency's known official URL directly into a browser or by calling the agency's published customer service number; report smishing texts to the FTC (reportfraud.ftc.gov) and IC3 (ic3.gov), and forward the message to 7726 (SPAM); delete the text; and confirm real toll balances through the agency's official app or website rather than any link provided in a text.
Toll agencies stated legitimate notices are never sent as urgent unsolicited payment-demand texts, and SunPass specified its legitimate texts originate only from a specific verified short code.
Social Engineering Examples. “Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)”. Accessed 16 September 2026. https://socialengineeringexamples.com/toll-road-smishing-wave-2024-2025
Operators of the underlying phishing-as-a-service kits (Lucid, Lighthouse/Smishing Triad) typically acquire large phone-number lists from data brokers, prior breach dumps, or bulk-SMS infrastructure providers, rather than targeting specific known toll-account holders, betting that enough recipients in any large batch are genuine toll-road users to make the lure land; Cisco Talos noted it lacked direct evidence of which leaked datasets, if any, fed this specific campaign.
Consumers cannot prevent their phone numbers from circulating in data-broker or breach-derived lists, so the realistic control sits downstream of this stage, in carrier-level filtering and consumer skepticism toward any unsolicited toll text rather than in stopping number harvesting itself.
Per Cisco Talos and Silent Push, affiliates subscribe to a commercial phishing-as-a-service platform (Lucid or Lighthouse, tied to the alias 'Wang Duo Yu' and the 'Smishing Triad' ecosystem) via Telegram, which supplies ready-made toll-agency-branded website templates, rotating look-alike domains, and bulk iMessage/RCS messaging tools designed to evade carrier spam filters.
Telecom carriers and platform providers (Apple/Google for iMessage/RCS) disrupting known phishing-as-a-service infrastructure, and legal action like Google's 2025 civil suit seeking to take down Lighthouse's domains and accounts, targets this stage directly, though take-down efforts compete with kits that can rotate domains and servers within hours.
The kit's bulk-messaging infrastructure sends near-identical 'you owe a small unpaid toll' texts to large numbers of phone numbers regardless of whether the recipient uses the impersonated toll system, using urgency language (late fee, suspension, collections) and a link or reply-to-unlock link, per FBI IC3 and Censys/Prodaft reporting.
Carrier spam filtering, keyword/URL detection on inbound SMS, and reporting suspicious texts to 7726 (SPAM) as FTC/FCC/FBI guidance recommends, helps catch and get blasts blocked, though reply-gated links are specifically designed to evade first-contact URL scanning.
The recipient, often a genuine toll-road user who finds the small dollar amount plausible, either clicks the embedded link directly or replies to the text first (a later variant Censys documented, which delays sending the live phishing link until after a reply to dodge first-contact URL scanning).
Consumer education from toll agencies and federal agencies (never click links in unsolicited toll texts, verify only via a known official app, website typed directly into a browser, or published customer-service number) is the single highest-leverage control, since it stops the chain before any data is entered regardless of how the message got through.
The victim lands on a look-alike toll-agency page and enters payment card details and, per FTC guidance, sometimes driver's license or Social Security numbers into a form designed purely to capture that data, with no real toll balance ever displayed by a legitimate agency system.
Toll agencies stating clearly that legitimate notices are never sent as urgent unsolicited payment-demand texts (and, per SunPass, only from one verified short code) gives consumers a concrete way to distinguish real from fake at the point of decision, and payment processors' fraud-detection rules can flag card-not-present charges routed through newly registered look-alike domains.
Per Google's civil complaint and Silent Push, a separate 'theft group' within the phishing-as-a-service ecosystem resells or directly uses the harvested card and personal data, completing the objective of payment-card fraud and identity-data theft without ever touching a real toll agency's systems.
Card issuers' post-compromise fraud monitoring, rapid card reissuance once a breach pattern is identified, and civil/criminal legal action against the phishing-as-a-service operators and their monetization networks are the realistic controls at this final stage, since by this point the individual consumer can no longer prevent the harm, only limit and report it.
Browse by what this case has in common with others in the library.
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a…
Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.