logo

Beware! Fake Unpaid Tolls Messages Used in Phishing Attack to Steal Login Credentials

ID: 6809b315-c86d-5ea2-a0cf-d2bb1e1660c9

STIX ID: report--6809b315-c86d-5ea2-a0cf-d2bb1e1660c9

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

A large-scale PhaaS platform called Lucid, attributed to the Chinese-speaking XinXin group, is powering toll-related SMS/iMessage/RCS phishing campaigns that ask victims to reply and then deliver links to phishing sites to steal personal and financial information. The platform offers affiliates customizable templates, domain generation, geo-targeting, anti-detection features, and a monitoring dashboard; researchers report tens of thousands of domains and cross-region targeting. Authorities recommend not replying or clicking links, verifying claims with official toll agencies, reporting spam to 7726, and contacting financial institutions and law enforcement if compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.