The Text Everyone Has Received
You have an outstanding toll. It is a final notice. There is a link. If you do not pay today, a late fee applies and your vehicle registration may be suspended.
Almost every American with a mobile phone has received a version of this message, often several times, sometimes for states they have never driven in. It is now common enough that it has stopped registering as a crime and started registering as weather.
That reaction is the problem, because the operation behind it is one of the largest and most industrialised phishing enterprises ever documented β and its economics only work at the volume that has made it feel unremarkable.
The Numbers
Researchers tracking the network known as the Smishing Triad β a Chinese-speaking threat actor active since at least 2023 β documented the scale.
Between January 1, 2024 and June 2025, the group registered 136,933 root domains, totalling 194,345 fully qualified domain names.
Of those, roughly 90,000 impersonated toll services and more than 28,000 impersonated the United States Postal Service. The remainder targeted state Departments of Motor Vehicles, the IRS, multinational financial and investment firms, e-commerce marketplaces, cryptocurrency exchanges, healthcare organisations, law enforcement agencies and social media platforms.
Nearly two hundred thousand domains in eighteen months means the group is registering, burning, and replacing thousands of domains a week. Domain takedowns are not a countermeasure against this. They are an operating cost the business already budgets for.
Phishing-as-a-Service: The Part That Actually Matters
The Smishing Triadβs significance is not that it sends scam texts. It is that it does not have to.
The group operates a fraud-as-a-service network, selling smishing kits through Telegram groups. Kits reportedly go for as little as $8 per 1,000 messages β a price that reframes the entire threat. At that rate, a would-be fraudster with no technical skill, no infrastructure, and effectively no capital can run a campaign against a hundred thousand phone numbers for the cost of a restaurant meal.
Researchers describe the groupβs Telegram channel as having evolved βfrom a dedicated phishing kit marketplace into a highly active community that gathers diverse threat actors.β The division of labour inside it looks like a supply chain, because it is one:
- Data brokers supplying phone number lists.
- Domain sellers providing bulk registrations across permissive registrars.
- Hosting providers with tolerance for abuse complaints.
- Kit developers building the fake toll, DMV and postal pages, complete with mobile-optimised layouts and live card validation.
- Platform providers running the panels operators log into.
- Spammers who handle delivery through SMS gateways and messaging apps like iMessage and RCS.
- Verification staff who confirm which numbers are live and reachable before the expensive part of a campaign begins.
Each specialist can be replaced without disrupting the others. This is why enforcement against any single layer produces so little durable effect β and why the toll text has survived years of public warnings, carrier filtering, and law enforcement advisories.
Why Tolls and the DMV
The choice of pretext is deliberate and worth understanding, because it explains why these messages work on people who would never fall for a Nigerian prince.
The amount is small. A toll notice is for $6.99, or $12.51, or $4.85. The claim is not that you have won something or lost everything. It is that you owe a trivial sum. That defeats the greed heuristic and the fear heuristic simultaneously β there is nothing to be suspicious of.
The claim is unfalsifiable in the moment. Almost nobody keeps a mental ledger of every toll gantry they have driven under. βDid I miss a toll six weeks ago?β is genuinely unanswerable, and uncertainty pushes people toward paying rather than investigating.
Cashless tolling made it plausible. E-ZPass, SunPass, FasTrak and their equivalents legitimately send electronic notices for unpaid tolls to drivers without transponders. The scam impersonates a real process that real people really receive.
The consequences sound bureaucratic and escalating. Late fees, registration holds, licence suspension. Not dramatic β just annoying enough that resolving it for $7 feels like the efficient choice.
The DMV variant adds authority. State motor vehicle agencies are among the few government bodies most adults interact with regularly and dread interacting with. A DMV message about a violation carries institutional weight and a strong incentive not to argue.
What the payment page collects is never really the $6.99. It is the full card number, expiry, CVV, billing address, name and phone β a complete package for card-not-present fraud or resale, plus a confirmed-live number that gets sold on for the next campaign.
How to Tell β and Why the Old Tells Are Weakening
Some indicators remain reliable:
- Real government sites end in
.gov. Toll authorities are state entities. Scam domains use.com,.info,.net,.org,.top,.xyz,.cyouand similar β often with a plausible-looking prefix likeezpass-ordmv-. - Official automated alerts usually come from short codes β five or six digit numbers. Scam texts typically arrive from a full ten-digit number, a foreign country code, or an email-to-SMS address.
- No toll authority will demand card details by text link.
But the traditional advice to look for bad grammar is expiring. Machine translation and language models have removed the awkward phrasing that used to identify these messages, and the cloned payment pages are frequently pixel-accurate copies of the genuine agency sites.
The durable defence is structural, not perceptual: never resolve a claim through the channel that made it.
Protecting Yourself
Never tap a link in an unexpected message about money you owe. Not to check, not to dismiss it, not out of curiosity. Interaction of any kind confirms your number is live.
Go to the source yourself. If you genuinely might owe a toll, open your toll account app or type the agencyβs .gov address directly. Every real unpaid toll will be visible in your account. If it is not there, the text was fake.
Check the exact domain before anything else. ezpassny.com versus ezpass-ny.top is the entire distinction, and it is deliberately designed to survive a two-second glance.
Do not reply, and do not text STOP. Replying to a fraudulent message confirms a live recipient. Delete instead.
Report and block. Forward the message to 7726 (SPAM) β carriers use this feed for filtering β then block the sender and delete. File with the FBIβs IC3 at ic3.gov and at ReportFraud.ftc.gov.
If you already entered card details, treat it as a compromised card. Call your bank, freeze or replace the card, and watch for small test charges. Do not wait for a large fraudulent transaction; the first move is usually a tiny one to verify the card works.
If you entered a driverβs licence number or SSN, escalate. Place a fraud alert or credit freeze with all three bureaus and review your credit report. DMV-themed variants specifically harvest identity documents, not just payment details.
Warn the people who will not read this. These messages perform best against the busy and the elderly. A two-minute conversation establishing one rule β we never click links in texts about money β is worth more than any filter.
The uncomfortable takeaway is that this will not stop. A network capable of registering 194,000 domains in eighteen months and renting access for $8 per thousand messages is not a campaign that gets shut down; it is an industry that gets priced. Which means the only variable that remains under your control is whether the message that reaches you finds someone who taps.



