- by foxnews
- 16 Mar 2025
Smishing is a type of phishing scam that works through text messages.
The name comes from a mix of "SMS" and "phishing," since scammers use fake messages to trick people into giving away personal information. It's been around for a while, but lately, it's gotten so bad that even the FBI and several U.S. cities have started warning people.
The campaign, which began in December, remains active. The smishing texts claim to be from a government authority and instruct recipients to click a link to pay an alleged overdue fine.
"Since early March 2024, the FBI Internet Crime Complaint Center (IC3) has received over 2,000 complaints reporting smishing texts representing road toll collection services from at least three states," the agency stated. "IC3 complaint information indicates the scam may be moving from state to state."
What started as a scheme involving fraudulent toll payment notifications has now expanded to include fake delivery service alerts, tricking users into clicking malicious links.
The scam appears to be operated by local cybercriminals using a toolkit developed by Chinese hacking groups. Notably, research from Unit 42 shows that many of the scam's root domains and fully qualified domain names use the Chinese .XIN top-level domain (TLD).
1. Verify before you trust: Treat unsolicited texts with caution. If a message claims to be from a government agency or company, don't click any links or act immediately. Instead, verify the claim by contacting the organization directly using an official phone number or checking their verified website.
2. Avoid clicking suspicious links and use strong antivirus software: Scammers use links to direct you to fake websites that can steal your personal or financial information. Instead of clicking on any link in an unexpected text, manually type the known URL into your browser or search for the organization's official website.
5. Report suspicious activity: If you receive a text that seems off, report it immediately to your mobile carrier, local law enforcement or the FBI's Internet Crime Complaint Center (IC3). Reporting helps authorities track down scammers and prevent further attacks.
I've been tracking these smishing scams, and it's clear they're evolving fast, from fake parking fines to bogus toll notifications. With the FBI and cities like New York, San Francisco and others sounding the alarm, I'm stepping up my own security game. As a general rule, if you receive a text from an unknown number or email address that's an out-of-the-blue greeting, asks you to click a link, pay a bill or respond in any way, just block it and report the number. It's better to be safe than sorry when it comes to protecting your personal information.
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
The founder of American Veterans Archaeological Recovery spoke with Fox News Digital about a recent veteran-led excavation at Camden Battlefield in South Carolina.
read more