$5 SMS Scam Alert: Toll Road Users Targeted

Smishing Campaign Targets Toll Road Users Across the U.S.

A widespread SMS phishing (smishing) campaign is actively targeting toll road users across the United States, posing a serious threat to motorists’ financial security.

Since mid-October 2024, cybercriminals have been impersonating legitimate toll payment services—such as E-ZPass—in an attempt to steal credit card information from unsuspecting users. At least eight states have been affected, including Washington, Florida, Pennsylvania, Virginia, Texas, Ohio, Illinois, and Kansas.

Victims receive deceptive text messages claiming they owe a small toll—usually under $5—and warning of late fees up to $35 if payment is not made promptly. These messages contain links to spoofed websites designed to mimic official toll service portals.

To increase urgency, the messages often include threats of penalties or legal action for non-payment. One sample message reads:
“Please settle your toll immediately after reading this message to avoid penalties for delaying the payment. Thank you for your cooperation.”

Attackers enhance credibility by using typosquatted domains with state abbreviations to make the URLs appear legitimate.

According to Cisco Talos researchers, the campaign was uncovered through detailed analysis of phishing infrastructure and message patterns. Their findings suggest multiple financially motivated threat actors are using a shared smishing toolkit developed by an individual known as “Wang Duo Yu.”

Once a victim clicks the link, they are guided through a layered phishing process. It begins with a fake CAPTCHA, followed by a counterfeit page featuring the toll service’s logo. The site asks for basic information—name and ZIP code—to “display the bill.”

Inside the Phishing Flow

The scam escalates with a fake bill showing the victim’s name, a small outstanding balance (~$4), and a warning about a $35 late fee. Upon clicking “Proceed Now,” users are directed to another fake page that collects extensive personal and financial data, including address, phone number, and credit card details.

The infrastructure behind the campaign is supported by domains registered between October 2024 and March 2025, resolving to IP addresses such as 45.152.115.161, 82.147.88.22, and 43.156.47.209. Domain names like “e-zpass.com-etcjr.xin” and “txtag.vipsf.top” are crafted to appear authentic.

New domain registrations as recent as March 2025 suggest this campaign is still ongoing, underlining the importance of continued awareness and caution among toll road users nationwide.

More Articles & Posts