Highway Robbery 2.0: How Attackers Are Exploiting Toll Systems in Phishing Scams
ID: 7831a6d4-4de3-55d9-9997-a563b8949db6
STIX ID: report--7831a6d4-4de3-55d9-9997-a563b8949db6
Feed Name: Censys Blog
Date Published: 2025-03-07
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; Aidan Holland; Senior Security Researcher
This report details an active, large-scale SMS/iMessage phishing campaign targeting U.S. drivers with fake toll-payment alerts (E‑ZPass, SunPass, TxTag, etc.). Using Censys, the author identified ~27k phishing domains and ~450 IPs—many hosted on Tencent and Alibaba Cloud—highlighted domain naming patterns, sender-number trends (+44/+63), nginx server fingerprints, and recommended avoidance and reporting of such messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
