logo

Highway Robbery 2.0: How Attackers Are Exploiting Toll Systems in Phishing Scams

ID: 7831a6d4-4de3-55d9-9997-a563b8949db6

STIX ID: report--7831a6d4-4de3-55d9-9997-a563b8949db6

Feed Name: Censys Blog

Threat Score
60/100

Date Published: 2025-03-07

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; Aidan Holland; Senior Security Researcher

...
...

This report details an active, large-scale SMS/iMessage phishing campaign targeting U.S. drivers with fake toll-payment alerts (E‑ZPass, SunPass, TxTag, etc.). Using Censys, the author identified ~27k phishing domains and ~450 IPs—many hosted on Tencent and Alibaba Cloud—highlighted domain naming patterns, sender-number trends (+44/+63), nginx server fingerprints, and recommended avoidance and reporting of such messages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.