Fake toll road texts sweep America as Chinese scammers target US drivers

Fake toll road texts sweep America as Chinese scammers target US drivers

Phishing scams are evolving and you should as well

by Kurt Knutsson

A new scam has come to light, targeting residents across the United States with text messages that pretend to be from toll road operators. For many who receive these messages, it’s an easy and expensive trap to fall into. The scam begins when people receive a message claiming they have unpaid tolls and may be charged fines. Scammers then ask for card details and a one-time password sent via SMS to steal their money. Security researchers believe that Chinese smishing groups are behind this scam, selling SMS-based phishing kits to thousands of scammers.

 

 

Fake toll road scam text

 

What you need to know about the fake toll scam

As reported by KrebsOnSecurity, the scam begins with a text message claiming to be from a toll road operator, such as E-ZPass or Sunpass. The message warns about unpaid tolls and the possibility of fines, forcing recipients to act quickly. Victims are directed to a fake website mimicking the toll operator’s site, where they are asked to provide sensitive information, including payment card details and one-time passwords.

Security researchers have traced the scam to Chinese smishing groups known for creating and selling sophisticated SMS phishing kits. One such kit, “Lighthouse,” makes it easy for scammers to spoof toll road operators in multiple states. These kits are designed to trick users into sharing financial information, which is then used to commit fraud.

Reports of these phishing attacks have surfaced across the U.S., targeting users of toll systems like EZDriveMA in Massachusetts, Sunpass in Florida, and the North Texas Toll Authority in Texas. Similar scams have been reported in states including California, Colorado, Connecticut, Minnesota, and Washington. The phishing pages are mobile-optimized and won’t load on non-mobile devices, making them even more deceptive.

Fake toll road text scam

 

MASSIVE SECURITY FLAW PUTS MOST POPULAR BROWSERS AT RISK ON MAC

 

Phishing scams are evolving 

Recent advancements in phishing kits include better deliverability through integration with Apple iMessage and Android’s RCS technology, bypassing traditional SMS spam filters. These methods increase the likelihood of victims receiving and engaging with fraudulent messages. The phishing sites are operated dynamically in real-time by criminals, making them harder to detect and shut down. Even individuals who don’t own a vehicle have reported receiving these messages, indicating random targeting.

A person using phone

 

THAT APPLE ID DISABLED MESSAGE? IT’S A DANGEROUS SCAM

 

7 ways to stay safe from toll scam messages

By staying vigilant and following the steps below, you can protect yourself from falling victim to toll scams. 

1) Verify directly with toll operators: If you receive a message about unpaid tolls or fines, do not click on any links. Instead, visit the official website of your toll operator or contact their customer service directly to verify the claim.

 

2) Install strong antivirus software: The best way to safeguard yourself from malicious links is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

My top pick is TotalAV, and you can get a limited-time deal for CyberGuy readers: $19 your first year (80% off) for the TotalAV Antivirus Pro package.  

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices.

 

3) Do not share personal information: Never provide sensitive details like payment card information, Social Security numbers, or one-time passwords (OTPs) via text or unverified websites. Legitimate toll operators will not request such information through SMS.

 

4) Enable two-factor authentication (2FA): Use 2FA for your accounts whenever possible. This adds an extra layer of protection by requiring two forms of verification, reducing the risk of unauthorized access even if some details are compromised.

 

5) Be wary of urgency in messages: Scammers often create a sense of urgency, claiming immediate action is required to avoid penalties. Take a moment to assess the situation and verify the legitimacy of the message through official channels.

 

6) Report suspicious messages: If you suspect a phishing attempt, report it to the Federal Trade Commission (FTC) or the FBI’s Internet Crime Complaint Center (IC3). Include details like the sender’s phone number and any links in the message. Additionally, inform your mobile carrier to help block similar scams.

 

7) Use a personal data removal service: Employ a reputable data removal service to reduce your online footprint and minimize the risk of scammers obtaining your personal information. These services can help remove your data from various data broker sites, making it harder for scammers to target you with personalized scams. While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. 

A service like Incogni can help you remove all this personal information from the internet. It has a very clean interface and will scan 195 websites for your information and remove it and keep it removed.

Special for CyberGuy Readers (60% off):  Incogni offers A 30-day money-back guarantee and then charges a special CyberGuy discount only through the links in this article of $5.99/month for one person (billed annually) or $13.19/month for your family (up to 4 people) on their annual plan and get a fully automated data removal service, including recurring removal from 190+ data brokers. You can add up to 3 emails, 3 home addresses and 3 phone numbers (U.S. citizens only) and have them removed from data-broker databases. I recommend the family plan because it works out to only $4.12 per person per month for year-round coverage. It’s an excellent service, and I highly recommend at least trying it out to see what it’s all about.

Get Incogni here

Get Incogni for your family (up to 4 people) here

 

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET

 

Kurt’s key takeaway

It’s deeply concerning how these scams are becoming increasingly sophisticated and widespread. It’s no longer just about random phishing attempts—these are carefully crafted schemes designed to exploit our trust in systems we rely on daily. The fact that scammers can impersonate toll road operators so convincingly is alarming, and it shows how vulnerable we are to such attacks. It frustrates me to think of how many people may fall victim to these tactics, losing their hard-earned money.

Have you recently received a suspicious text message claiming to be from a toll road operator or any other service? How did you react? Let us know in the comments below. 

TO GET MORE OF MY SECURITY ALERTS, SUBSCRIBE TO MY FREE CYBERGUY REPORT NEWSLETTER

 

https://cyberguy.com/wp-admin/post.php?post=121116&action=edit&classic-editor#

 

Copyright 2025 CyberGuy.com.  All rights reserved.  CyberGuy.com articles and content may contain affiliate links that earn a commission when purchases are made.


   

9 comments

Judy F January 29, 2025 - 5:17 am

I know where I drive/travel. I simply delete and block and report the scam. The first time I received the scam text I was on a bus trip…really?

Reply
Glenda H. January 29, 2025 - 5:32 am

I have received the toll charges text several times over the last several weeks. I knew it was a scam because there are no toll roads in the areas where I drive. I report it as junk and delete.

Reply
Doris V.W. January 29, 2025 - 5:42 am

I recently drove to Orlando FL airport and passed two tolls. The next day I received a message from “Sunpass” saying I was late and penalty would ensue if I didn’t pay. I’ve gotten this once before and felt right away it was a scam as I prepay my account. So I deleted and blocked.

Reply
Beverly W. January 29, 2025 - 5:49 am

Yes, I received the scam toll road text from a trip taken last spring through Texas. We didn’t even realize we had taken a toll road until we received a paper bill awhile after the trip. I promptly paid the bill by phone using the information provided. I had a strong suspicion the text was a scam and did not respond because I was out of town and my payment documentation was at home. The next day the scam message came back with the addition of “this number has been deleted from the group”. That pretty much confirmed my suspicion. Thank you so much for bringing this to light.

Reply
Phil S. January 29, 2025 - 7:21 am

I have received several of these text messages. Having had fraud committed on us before, I am very suspicious of any emails like these. My reaction the first and subsequent instances was to delete the email.

Reply
Jeanne K. January 29, 2025 - 9:57 am

I did get one from EZPay tolls MA.. i did fill out initially but deleted when asked for credit card and decided to call. I did not get connected but did not go back and send any financial information, whew. I thought it might be real as I used them in 2023, but already had paid the ones I used. Thought there may have been an outlier, but thought better of it. Deleted the message with spam removal.

Reply
Chas G. January 29, 2025 - 10:49 am

The #1 way to stay safe on this scam is the very simple one: Did you drive on a toll road? If not, then you know it is a scam. I received one with a date being the same day I got the text, and I was home all day. The #2 should be to remember if you do drive on a toll road, you know how to check if there is a problem. Basic common sense in dealing with this.

Reply
RAYMOND January 29, 2025 - 3:47 pm

Our daughter’s car is on our account. When she received the text, I told her, do not reply at they know our license plate numbers and my email address but not our phone numbers. The text was near identical to the one in the article

Reply
john r. January 29, 2025 - 8:52 pm

I have received 2 or 3 over the last month, I delete.

Reply

Leave a Comment

GET MY FREE CYBERGUY REPORT
Subscribe to receive my latest Tech news, security alerts, tips and deals newsletter. (We won't spam or share your email with anyone else.)

By signing up, you agree to our Terms of Service and Privacy Policy. You may unsubscribe at any time.

Tips to avoid our newsletters going to your junk folder