Persistent Express Toll smishing

Express Toll scams come on a monthly basis now. Two of the latest:

From: [email protected]
From: [email protected]

Both are posing as the E-470 Public Highway Authority (of which there is none) and threatening DMV penalties, including vehicle impoundment, if the toll is not paid.

Payment address for the first is:
https://expresstoll.com-ronc.win/us

Payment address for the second is:
https://expresstoll.com-tiznqmeny.world/pay

Screenshots of the actual text are attached if needed.



Hereโ€™s a new one

๐—˜-๐—ญ๐—ฃ๐—ฎ๐˜€๐˜€ ๐—ก๐—ผ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป: Immediate action ๐—ถ๐˜€ ๐—ป๐—ฒ๐—ฒ๐—ฑ๐—ฒ๐—ฑ to ๐—ฟ๐—ฒ๐˜€๐—ผ๐—น๐˜ƒ๐—ฒ ๐—ฎ ๐˜๐—ผ๐—น๐—น ๐—ฑ๐—ฒ๐—ฏ๐˜ on ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜. Make ๐—ฝ๐—ฎ๐˜†๐—บ๐—ฒ๐—ป๐˜ ๐—ฏ๐˜† ๐— ๐—ฎ๐˜† ๐Ÿญ๐Ÿฌ, 2025 ๐˜๐—ผ avoid further ๐—ฝ๐—ฒ๐—ป๐—ฎ๐—น๐˜๐—ถ๐—ฒ๐˜€.
๐—™๐—ฎ๐—ถ๐—น๐˜‚๐—ฟ๐—ฒ ๐˜๐—ผ ๐—ฎ๐—ฑ๐—ฑ๐—ฟ๐—ฒ๐˜€๐˜€ ๐˜๐—ต๐—ถ๐˜€ ๐—ถ๐˜€๐˜€๐˜‚๐—ฒ may result ๐—ถ๐—ป ๐—ฎ๐—ฑ๐—บ๐—ถ๐—ป๐—ถ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—ณ๐—ฒ๐—ฒ๐˜€, ๐—น๐—ฒ๐—ด๐—ฎ๐—น collection procedures, ๐—ฎ๐—ป๐—ฑ possible suspension.
Review and resolve here: https://rb.gy/bek9fc?LfB=###### {๐—ฆ๐Ÿด:๐——๐—ข:๐—˜๐—ข:๐—ซ๐—ฆ:๐Ÿฒ๐—š:๐Ÿฑ๐—ฅ:๐—จ๐—ซ:๐—”๐Ÿณ:๐—ฉ๐Ÿญ}

The URL redirects to https://ezpassxo.com/ny?LfB=###### where ###### is a six-digit alphanumeric ID. I tried various combinations and they all return the same phishing site so it may just be an ID for accounting purposes.

The site collects various personal information and attempts to charge a small amount to a credit card. It seems that it does some CC validation since fake CC numbers from fakenamegenerator.com are rejected.

You must set your browser user-id to a common mobile browser (Safari on iOS or Chrome on Android).