A sophisticated phishing scheme is taking advantage of compromised Indiana government email accounts to send deceptive TxTag toll payment notifications.
This attack, which surfaced earlier this week, makes use of the GovDelivery platform to deceive recipients with emails that appear to come from credible government sources, giving the scam a veneer of authenticity.
Targeted Phishing Attack Impersonates Indiana Toll System
The fraudulent emails are designed to look like they are sent from official Indiana government addresses, such as DLGF@public.govdelivery.com, and falsely claim that toll charges are unpaid.
The attackers have deployed newly registered, nearly identical domain names to host counterfeit TxTag payment pages that are meticulously crafted to collect sensitive personal data, including credit card information and one-time passcodes (OTPs).
According to a Trustwave SpiderLabs report shared with Cyber Security News, the scam’s primary goal is to harvest personal details through these fake TxTag sites.

A detailed technical investigation uncovered the use of advanced data exfiltration techniques by the cybercriminals behind this scheme.
The counterfeit websites are designed to steal victim data by sending POST requests to endpoints such as https://txtag-us.xyz/api/client/*, and also maintain ongoing WebSocket connections (wss://txtag-us.xyz/sync-message), enabling attackers to monitor user activity in real time.
This persistent connection gives attackers the ability to track user behavior on the phishing site, potentially evading security defenses and increasing the chances of successful data theft.
Abuse of State Email Infrastructure
The Indiana Office of Technology (IOT) has confirmed that the phishing attack originated from a breach tied to a former government contractor.
IOT disclosed that the fraudulent emails are connected to a private vendor whose contract with the state expired last year, but who apparently failed to revoke access to the state’s email system after the contract ended.

Investigations have revealed that despite the Indiana state’s contract with GovDelivery expiring on December 31, 2024, the account linked to it remained active. This oversight allowed cybercriminals to exploit the situation, gaining access to GovDelivery’s email distribution platform by compromising a contractor’s credentials. As a result, the attackers were able to send fraudulent messages to millions of subscribers.
Indiana Secretary of State, Diego Morales, issued a critical advisory on May 13, 2025, emphasizing the threat: “These scams are dangerous, misleading, and disruptive. I urge all Hoosiers to exercise caution when dealing with unsolicited emails, especially those asking for personal details or directing you to unknown websites. Ensuring your security is our highest priority.”
The Indiana Office of Technology (IOT) clarified that legitimate government agencies do not use email or text messages to send toll notices.
Similar alerts have been issued by other states, including Illinois, where the Illinois Tollway confirmed that it does not utilize third-party sites to manage or collect customer account details.
Protective Steps to Take
Experts recommend that anyone receiving suspicious emails:
- Refrain from clicking any links or opening attachments in dubious emails.
- Report any such emails to the relevant authorities (e.g., info@getipass.com for Illinois residents).
- Immediately notify credit card companies if payment information was entered on fraudulent websites.
- Verify toll charges through official channels, such as TxTag.org or customer service numbers like 1-888-468-9824.
This incident highlights the increasing risks associated with compromised government communication systems being exploited for phishing attacks. Given that GovDelivery serves over 300 million subscribers globally, the ramifications of such breaches extend far beyond this specific incident, emphasizing the need for robust security measures in managing government communications platforms.




