A phishing campaign , impersonating E-ZPass and other toll services , appears to be targeting more and more users recently, via SMS (on Android and iPhone) with the aim of stealing personal data and credit card information .

Phishing messages embed links that lead the victim to a phishing website impersonating: E-ZPass, The Toll Roads, FasTrak, Florida Turnpike , and other similar services.
The hackers behind the campaign are trying to steal personal information, such as names, email addresses, physical addresses, and credit card details.
See also: What are whale-phishing attacks and how to protect yourself
This scam isn't new. The FBI has been warning about it since April 2024, but according to BleepingComputer, there has been an increase in activity recently . These are likely automated attacks.
The messages try to create a sense of urgency, such as the need to pay the toll in one or two days. Otherwise, the phishing messages claim that there will be an additional charge or license suspension.
“E-ZPass Lane toll payment must be settled by April 4, 2025. To avoid fines and suspension of driving privileges, please pay by the due date,” reads a message seen by BleepingComputer.
Apple iMessage automatically disables links in messages from unknown sendersto protect users from SMS phishing scams. To bypass this security measure, scammers tell users to reply to the message. If they do, they can then click on links.
See also: Lucid phishing platform targets iOS and Android users
If the victim opens the embedded link, they will be taken to a phishing website that mimics E-ZPass and, except for the URL, looks very similar to the legitimate website. The phishing website only loads on mobile, so desktop users will not see it.
The volume of phishing messages sent as part of this scam is so large that users are expressing their frustration and concern for their security.
While the origin of the messages has not yet been determined, a new phishing-as-a-service platform called Lucidbeen linked to such scams. Platforms like Lucid and Darcula use encrypted iMessage and RCS messages to bypass traditional anti-spam filters and send malicious messages to unsuspecting users.
If you receive one of these messages, you should block and report the numberso that the email address or phone number is reported to Apple. You should also avoid responding, as it puts you on the scammers' radar for future attempts.
For those concerned that they have legitimate outstanding toll payments, they should log directly into the toll authority's website to check for any balances.
See also: Morphing Meerkat: New phishing kit imitates 114 brands

General tips for protecting against mobile phishing
- Be careful with suspicious messages: Do not click on links or open attachments from unknown sources. Delete suspicious messages immediately.
- Verify the legitimacy of apps: Only download apps from official app stores and research the developer before downloading.
- Be careful with personal information: Be wary of websites or apps that ask for too much personal information, especially if you're not familiar with them. Legitimate sources usually don't ask for too much personal information.
- Check for security certificates: Before entering any sensitive information on a website, make sure it has a secure connection by checking for HTTPS protocol and a padlock symbol in the address bar.
- Keep your device software up to date: Regularly update your mobile device's operating system and apps to patch any security vulnerabilities.
- Use strong and unique passwords: Create strong and unique passwords for all online accounts to make it harder for attackers to access your information. Consider using a password manager to create and store complex passwords securely.
- Use two-factor authentication: Enable two-factor authentication for all your online accounts to add an extra layer of security.
- Use mobile anti-phishing tools: Install and use anti-phishing tools on your mobile device to detect and prevent phishing attacks.
- Avoid using public Wi-Fi: Public Wi-Fi networks are vulnerable to security breaches, making it easy for attackers to steal your personal information.
- Educate yourself: Stay up to date on the latest phishing techniques and scams so you can recognize them and avoid falling victim.
Source: www.bleepingcomputer.com
