Scammers are globally targeting drivers with fraudulent text messages impersonating toll operators, parking authorities, and transport agencies, according to a recent analysis by Bitdefender Labs. Since December 2025, researchers have tracked these "smishing" campaigns, which have sent over 79,000 deceptive messages across 12 countries. The active campaigns aim to trick recipients into paying fake fines, divulging sensitive personal and financial information, or downloading malware.
The operation, dubbed "Operation Road Trap," employs tactics such as rapid domain generation, sender-ID spoofing, and evasion techniques designed to bypass mobile security measures. Messages are delivered in multiple languages, including English, Spanish, Portuguese, French, and Hindi, and are tailored to specific regions. While the campaigns are widespread and coordinated in their methods, Bitdefender Labs has not yet attributed them to a single threat actor.
These scams commonly create a sense of urgency by claiming an unpaid toll, traffic fine, or parking ticket, often threatening consequences like additional fees, license suspension, or legal action within a short timeframe, typically 24 to 72 hours. Recipients are then directed to click a link that leads to a fraudulent website designed to mimic official payment portals. In some instances, these links are used to distribute malware.
The United States has seen the largest volume of these attacks, with campaigns impersonating state Departments of Motor Vehicles (DMVs) and toll systems like E-ZPass, SunPass, and FastTrak. Over 25,000 phishing URLs have been identified in this region, with California and Texas being particularly targeted. Some messages use spoofed sender names and are delivered via short codes, which can appear more legitimate.
In Canada, particularly in British Columbia, the scams begin with parking citation messages but can escalate to target Interac e-Transfer credentials, potentially leading to broader financial theft. Messages impersonate local parking or city collection services, with Alberta and Ontario also experiencing these attacks.
The United Kingdom is experiencing a campaign focused on road or journey payments, using minimal text and direct links to prompt quick action. Unlike other regions, these messages do not typically mention fines or legal consequences, opting for a low-friction approach.
Ireland's campaign impersonates eFlow, the electronic toll system for the M50 motorway, using the short code 7726, also seen in US campaigns. These messages claim an unpaid toll and direct users to a payment link.
Australia is targeted by scams impersonating the toll operator Linkt. These campaigns utilize shortened URLs and spoof the sender name "Linkt," potentially causing messages to appear within legitimate conversation threads on some devices.
New Zealand sees scams impersonating NZ Police and the Ministry of Justice, warning of overdue traffic fines and using government-themed domains. Messages often include mobile-specific instructions to encourage interaction.
France is experiencing ULYS toll payment scams, with messages tailored to local users and resembling legitimate notifications for small unpaid toll amounts. The Île-de-France, Rhône-Alpes, and Provence-Alpes-Côte d'Azur regions are most affected.
Luxembourg's campaign impersonates Guichet.lu, the official government services portal, with messages concerning parking violations. These scams include case reference numbers and specific dates to appear more official.
Colombia has also seen a significant volume of scam messages related to tolls and traffic fines, making it the second-largest wave of attacks tracked.






