FBI warns of massive wave of road toll SMS phishing attacks

19 tháng 4, 2024

On April 5, the Federal Bureau of Investigation warned of a massive ongoing wave of SMS phishing attacks targeting Americans with lures regarding unpaid road toll fees.


These attacks started last month, and the federal law enforcement agency says thousands of people have already reported that the scammers have targeted them.


"Since early-March 2024, the FBI Internet Crime Complaint Center (IC3) has received over 2,000 complaints reporting smishing texts representing road toll collection service from at least three states," the FBI explained in a public service announcement published on April 12.


While the mobile phishing campaign has yet to reach some U.S. regions, this can be explained by the fact that complaint information collected so far by IC3 indicates the scam may be moving from state to state.


The FBI says the malicious text messages claim the recipient owes money for unpaid tolls and contain almost identical language.


For instance, all reports mention the attackers using "outstanding toll amount" to trick the targets into clicking an embedded hyperlink.


"However, the link provided within the text is created to impersonate the state's toll service name, and phone numbers appear to change between states," the FBI explains.




Road toll debt SMS phishing message (Pennsylvania State Police)




​Pennsylvania Turnpike, one of the road toll services whose customers were targeted in these attacks, cautioned those receiving the phishing messages not to tap the links.


"Some customers have received phishing-attempt text messages claiming to be from the PA Turnpike's toll services. If you receive such a text, providing you with a link to pay an outstanding toll, do not click on the link, and delete the text," the service said on April 8.


"BE AWARE: We have received multiple concerns regarding the attached scam text message in our area. This link will send you to a fake Turnpike website and collect your information!" the Pennsylvania State Police also warned.


While the FBI did not mention E-ZPass in today's PSA (a toll collection system used across Eastern, Midwestern, and Southern United States), BleepingComputer is aware that the threat actors have also been targeting E-ZPass customers since March.



The FBI asked those who receive one of these SMS phishing messages to:

  1. File a complaint with the IC3 at www.ic3.gov and include the scammer's phone number and the website listed within the text.
  2. Check their account using the toll service's legitimate website.
  3. Contact the toll service's customer service phone number.
  4. Delete any smishing texts received.
  5. If they click any link or provide your information, make efforts to secure your personal information and financial accounts. They should also ensure that all unfamiliar charges are disputed immediately.



Source: bleepingcomputer.com


Bạn cũng có thể quan tâm

4 tháng 6, 2024
Bộ định tuyến chơi game TP-Link Archer C5400X dễ mắc phải các lỗi bảo mật có thể cho phép kẻ tấn công từ xa, không được xác thực thực thi các lệnh trên thiết bị.
3 tháng 6, 2024
Ngày 27 tháng 5 Check Point đã cảnh báo rằng các tác nhân đe dọa đang nhắm mục tiêu vào các thiết bị VPN truy cập từ xa của Check Point trong một chiến dịch đang diễn ra nhằm xâm phạm mạng doanh nghiệp.
31 tháng 5, 2024
Công ty quản lý đơn thuốc Sav-Rx cảnh báo hơn 2,8 triệu cá nhân ở Hoa Kỳ việc họ đã bị vi phạm dữ liệu và dữ liệu cá nhân của họ đã bị đánh cắp trong một cuộc tấn công mạng năm 2023.
Thêm bài viết
Share by: