Highway Robbery 2.0: How Attackers Are Exploiting Toll Systems in Phishing Scams

March 12, 2025, 7:54 a.m.

Description

A massive SMS phishing campaign targeting U.S. drivers exploits various toll systems, including E-ZPass, SunPass, and TxTag. The scam uses fake payment alerts sent via iMessage and SMS from foreign numbers to lure victims to fraudulent websites. Analysis reveals a pattern in domain names and infrastructure, with most phishing sites hosted on Chinese ASNs like Tencent and Alibaba Cloud. The campaign employs nginx web servers and constantly shifts tactics to evade detection. Over 2,000 complaints have been filed with the FBI's Internet Crime Complaint Center, prompting warnings from the FTC and toll authorities. The scam's effectiveness stems from the inconsistency in legitimate toll collection domain names, making it challenging for users to distinguish between real and fake websites.

Date

  • Created: March 10, 2025, 1:04 p.m.
  • Published: March 10, 2025, 1:04 p.m.
  • Modified: March 12, 2025, 7:54 a.m.

Attack Patterns

  • T1584.006
  • T1102.003
  • T1583.006
  • T1608.004
  • T1583.001
  • T1608.001
  • T1589.002
  • T1566.002
  • T1071.001

Additional Informations

  • Transportation
  • United States of America