A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Social Engineering Examples·17 sources
Starting in early 2024 and accelerating through 2025, toll-road customers across the U.S. received unsolicited SMS text messages claiming they owed a small unpaid toll balance and warning of late fees, account suspension, or referral to collections if they did not pay immediately. The texts included links to phishing websites spoofing the branding and domain style of real state DOTs and toll agencies (E-ZPass, SunPass, PA Turnpike, MassDOT/EZDriveMA, NTTA, Peach Pass, and others), which prompted victims to enter payment card numbers and, per FTC guidance, sometimes driver's license or Social Security numbers.
The FBI's Internet Crime Complaint Center (IC3) issued Public Service Announcement I-041224-PSA, 'Smishing Scam Regarding Debt for Road Toll Services,' on April 12, 2024, after receiving more than 2,000 complaints in a matter of weeks. The scam did not stem from any breach of the toll agencies' own systems; agencies stated that legitimate account notices are never sent by unsolicited text demanding immediate payment.
In November 2025, Google filed a civil lawsuit against the operators of 'Lighthouse,' the phishing-as-a-service kit that threat-intel vendors tie to this and other smishing campaigns (e.g., USPS delivery-fee smishing), seeking to dismantle the platform's infrastructure; this is the first substantial legal action connected to the kit behind the toll scams, though it is a civil suit rather than a criminal case.
The campaign relied on volume SMS blasts (smishing) sent to large numbers of phone numbers regardless of whether the recipient actually used the impersonated toll system, betting that enough recipients were genuine toll-road users to make the lure plausible. Messages used urgency language (act now, pay immediately, avoid a late fee or suspension) and impersonated official-looking domains resembling the real toll agency's name.
Clicking the link led to a phishing page designed to harvest a small 'toll balance' payment via credit card, along with enough personal data to enable further fraud. Some later variants used reply-based workflows, where responding to the initial text triggered delivery of the live phishing link, likely to evade carrier and platform spam filters that scan for URLs in first-contact messages.
Security vendors (Cisco Talos, Censys, Silent Push) linked the campaign's infrastructure and kits to commodity phishing-as-a-service platforms (Lucid, and the Smishing Triad's 'Lighthouse' kit) associated with Chinese-language cybercrime ecosystems, suggesting the same kit or affiliate network was resold or reused to spin up lookalike campaigns against toll agency after toll agency as it expanded state-to-state.
Google's November 2025 civil complaint corroborates this account, describing Lighthouse as a subscription 'phishing for dummies' kit (SMS and e-commerce versions, hundreds of website templates) sold via Telegram/YouTube channels, with a 'Developer Group' (including the alias 'Wang Duo Yu'), a 'Spammer Group' that provides bulk-SMS infrastructure, and a 'Theft Group' that monetizes stolen credentials/cards.
The lure was a text stating an unpaid toll debt existed on the recipient's account, with a threat of a late fee, account suspension, or referral to collections/DMV if not paid immediately, and a link to 'pay now.' Tells included: the message coming from an unfamiliar or non-official short/long code number, a URL that resembled but did not exactly match the toll agency's real domain, arriving even for people who do not own an E-ZPass/SunPass/etc. transponder or who have no outstanding balance, and requests for a small payment amount via a generic-looking payment form rather than the agency's actual billing portal.
Toll agencies (PA Turnpike, MassDOT, SunPass/Florida's Turnpike, NTTA) and federal agencies (FBI IC3, FTC, FCC) issued repeated public consumer alerts throughout 2024 and into 2025 as the scam recurred and spread to additional states; FBI Atlanta issued a dedicated Peach Pass alert in March 2025. No breach of toll-agency systems occurred. As of the sources reviewed, no public arrests, indictments, or court judgments had been announced specifically tied to this toll-smishing campaign, and this remains true as of mid-2026: attribution to Chinese-linked phishing-as-a-service operators (Smishing Triad, Lucid, Darcula-adjacent tooling) still rests on private-sector threat intelligence rather than confirmed criminal law-enforcement action.
The one legal-action update since the original research: on 2025-11-12, Google filed a civil lawsuit (RICO, Lanham Act, CFAA) in the Southern District of New York against 25 unnamed ('John Doe') operators of the Lighthouse phishing-as-a-service platform, the kit Cisco Talos and Netcraft tie to alias 'Wang Duo Yu' and to these toll-road smishing campaigns (among other Lighthouse-enabled scams, e.g.
USPS delivery smishing). This is a private civil suit seeking a restraining order, infrastructure takedowns, and damages, not a criminal indictment or arrest. Google said that within roughly 24 hours of filing suit it had disrupted Lighthouse's infrastructure, citing translated Telegram messages in which an alleged operator wrote that the group's 'cloud server has been blocked,' though Google did not detail how the disruption was achieved.
Independent researchers who track this ecosystem, including Ford Merrill of SecAlliance (quoted by KrebsOnSecurity), cautioned that the legal action may only temporarily disrupt this particular operation, even as it could make it easier for U.S. federal authorities to bring future criminal charges, given how lucrative the broader Chinese mobile-phishing market remains.
The campaign demonstrates how a single, low-cost commodity phishing kit can be resold or reused to mount parallel smishing waves against dozens of unrelated government agencies (toll authorities in different states) with minimal customization, exploiting the near-universal plausibility of 'you might owe a small toll fee' as a lure. It also shows the limits of the current U.S. response: despite tens of thousands of IC3 complaints and repeated agency alerts across two years, no criminal arrests or indictments have been publicly announced; the first notable legal action, Google's November 2025 civil RICO suit against the Lighthouse platform, came from a private company defending its trademarks and users rather than from law enforcement, underscoring the difficulty of disrupting SMS-based, likely offshore, phishing-as-a-service operations at scale through criminal channels alone.
FBI IC3, FTC, and FCC guidance consistently recommends: never click links in unsolicited toll-payment texts; check account status only by typing the agency's known official URL directly into a browser or by calling the agency's published customer service number; report smishing texts to the FTC (reportfraud.ftc.gov) and IC3 (ic3.gov), and forward the message to 7726 (SPAM); delete the text; and confirm real toll balances through the agency's official app or website rather than any link provided in a text.
Toll agencies stated legitimate notices are never sent as urgent unsolicited payment-demand texts, and SunPass specified its legitimate texts originate only from a specific verified short code.
Social Engineering Examples. “Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)”. Accessed 19 September 2026. https://socialengineeringexamples.com/toll-road-smishing-wave-2024-2025
Operators of the underlying phishing-as-a-service kits (Lucid, Lighthouse/Smishing Triad) typically acquire large phone-number lists from data brokers, prior breach dumps, or bulk-SMS infrastructure providers, rather than targeting specific known toll-account holders, betting that enough recipients in any large batch are genuine toll-road users to make the lure land; Cisco Talos noted it lacked direct evidence of which leaked datasets, if any, fed this specific campaign.
Consumers cannot prevent their phone numbers from circulating in data-broker or breach-derived lists, so the realistic control sits downstream of this stage, in carrier-level filtering and consumer skepticism toward any unsolicited toll text rather than in stopping number harvesting itself.
Per Cisco Talos and Silent Push, affiliates subscribe to a commercial phishing-as-a-service platform (Lucid or Lighthouse, tied to the alias 'Wang Duo Yu' and the 'Smishing Triad' ecosystem) via Telegram, which supplies ready-made toll-agency-branded website templates, rotating look-alike domains, and bulk iMessage/RCS messaging tools designed to evade carrier spam filters.
Telecom carriers and platform providers (Apple/Google for iMessage/RCS) disrupting known phishing-as-a-service infrastructure, and legal action like Google's 2025 civil suit seeking to take down Lighthouse's domains and accounts, targets this stage directly, though take-down efforts compete with kits that can rotate domains and servers within hours.
The kit's bulk-messaging infrastructure sends near-identical 'you owe a small unpaid toll' texts to large numbers of phone numbers regardless of whether the recipient uses the impersonated toll system, using urgency language (late fee, suspension, collections) and a link or reply-to-unlock link, per FBI IC3 and Censys/Prodaft reporting.
Carrier spam filtering, keyword/URL detection on inbound SMS, and reporting suspicious texts to 7726 (SPAM) as FTC/FCC/FBI guidance recommends, helps catch and get blasts blocked, though reply-gated links are specifically designed to evade first-contact URL scanning.
The recipient, often a genuine toll-road user who finds the small dollar amount plausible, either clicks the embedded link directly or replies to the text first (a later variant Censys documented, which delays sending the live phishing link until after a reply to dodge first-contact URL scanning).
Consumer education from toll agencies and federal agencies (never click links in unsolicited toll texts, verify only via a known official app, website typed directly into a browser, or published customer-service number) is the single highest-leverage control, since it stops the chain before any data is entered regardless of how the message got through.
The victim lands on a look-alike toll-agency page and enters payment card details and, per FTC guidance, sometimes driver's license or Social Security numbers into a form designed purely to capture that data, with no real toll balance ever displayed by a legitimate agency system.
Toll agencies stating clearly that legitimate notices are never sent as urgent unsolicited payment-demand texts (and, per SunPass, only from one verified short code) gives consumers a concrete way to distinguish real from fake at the point of decision, and payment processors' fraud-detection rules can flag card-not-present charges routed through newly registered look-alike domains.
Per Google's civil complaint and Silent Push, a separate 'theft group' within the phishing-as-a-service ecosystem resells or directly uses the harvested card and personal data, completing the objective of payment-card fraud and identity-data theft without ever touching a real toll agency's systems.
Card issuers' post-compromise fraud monitoring, rapid card reissuance once a breach pattern is identified, and civil/criminal legal action against the phishing-as-a-service operators and their monetization networks are the realistic controls at this final stage, since by this point the individual consumer can no longer prevent the harm, only limit and report it.
Browse by what this case has in common with others in the library.
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…