What do you do with an #EZPass transponder that has just started beeping? Wrong answers only 😅

First of all, this seems to be part of a much wider #smishing campaign that people are more familiar with: Fake road toll collection #scams

These have been a nuisance all year, and some of the sites hosting the same #phishing kit appear to be using that same ruse, simultaneously with the new one.

Did you get a message telling you that you owe $6.99 (or $6.69 - nice) in tolls? Probably part of this larger network of scammers.

Note how they have expanded to a variety of different locales: the City of Los Angeles, Seattle, Columbus (Ohio), and even the Canadian province of Ontario are all reflected, as well as the E-ZPass and SunPass multi-state toll payment systems, which together cover most of the US states that operate toll roads.

/2

#phishing #fraud #roadtoll #tollscams #netcraft #NetcraftConfirmsIt #EZPass #SunPass

Hmmm...so, I went through #EZpass tolls in NY and MA last week, and I just received this #phishing attempt from what appears to be a UK phone number (but is probably forged). The domain name in the link is registered with Alibaba Cloud, and the IP addresses run through Cloudflare. #scam

Mashable: Those scam crypto texts are coming from the Karen National Army and a Myanmar warlord. “Over the weekend, we covered the rise of “wrong person” scam texts — seemingly innocent messages that evolve into full-blown crypto cons. And across the U.S., drivers are getting E-ZPass toll road scam texts in droves. Now, we have a clearer picture of where these types of scam texts are coming […]

https://rbfirehose.com/2025/05/16/mashable-those-scam-crypto-texts-are-coming-from-the-karen-national-army-and-a-myanmar-warlord/

Mashable: Those scam crypto texts are coming from the Karen National Army and a Myanmar warlord | ResearchBuzz: Firehose

ResearchBuzz: Firehose | Individual posts from ResearchBuzz
Ok, look, if you're gonna scam people with one of these phony notices, at least try harder. PennDOT is not going to send me texts like this, of course. If they did, um, they sure aren't going to end with: "Thank you for ur prompt attention to this matter" 😮 🙄😀 #scam #ezpass #cyberscam🤣
Bluesky

Bluesky Social

Ok, look, if you're gonna scam people with one of these phony notices, at least try harder. PennDOT is not going to send me texts like this. If they did, um, they sure aren't going to end with "Thank you for ur prompt attention to this matter" 😮

#scam #cyberscam #ezpass

Since the middle of Oct. 2024, Talos has seen ongoing #smishing attacks impersonating U.S toll road automatic payment services (such as #ezpass with the intent of financial theft. The actors have so far sent SMS messages to individuals in about eight states in the U.S., including Washington, Florida, Pennsylvania, Virginia, Texas, Ohio, Illinois, and Kansas. Talos identified these states via spoofed domains containing the states’ two-letter abbreviations that we observed in the SMS messages https://blog.talosintelligence.com/unraveling-the-us-toll-road-smishing-scams/
Unraveling the U.S. toll road smishing scams

Cisco Talos has observed a widespread and ongoing financial theft SMS phishing (smishing) campaign since October 2024 that targets toll road users in the United States of America.

Cisco Talos Blog

Security researchers reveal campaign impersonating #EZPass

Threat actors would send text messages with links to a phishing site impersonating E-ZPass. The site collects info such as name, email, address, and credit card.

People receiving these messages are advised to delete them ASAP

#cybersecurity #USA

https://www.bleepingcomputer.com/news/security/toll-payment-text-scam-returns-in-massive-phishing-wave/

E-ZPass toll payment texts return in massive phishing wave

An ongoing phishing campaign impersonating E-ZPass and other toll agencies has surged recently, with recipients receiving multiple iMessage and SMS texts to steal personal and credit card information.

BleepingComputer

This #EZPass #scam seems to be growing. I finally received one in the wild today.

Be safe my friends!

#security

https://www.carlsetzer.com/2025/03/10/ah-yes-another-scam/

Ah, Yes...Another Scam - Carl Setzer

I posted this article to Facebook last week. My son let me know he received one that day. And I won this lottery today! This one is text based. Watch for these E-Z Pass texts that state you have an unpaid toll. Well, it’s fraudulent. As always, DO NOT CLICK THE LINK! Report it as… Continue reading Ah, Yes…Another Scam →

Carl Setzer
Oh look my first #EZPass #scam!