
It looks so benign.
The reminder appears to come from EZDriveMA, the Massachusetts Turnpike Authorityโs electronic tolling program.
โYour bill for $6.99 is due soon.โ The text message contains a link and instructs you to โpay and avoid additional feesโ by replying with a Y and activating a link or copying the link into your browser.
This is smishing, a text message scam, technically referred to as a tactic at social engineering. Based on a recent uptick of reports, MassDOT made its third warning about smishing in recent months.
โMassDOT is underscoring that: EZDriveMA will never request payment by text,โ according to the warning. โAll links associated with EZDriveMA will include www.EZDriveMA.com.โ
The FBI Internet Crime Complaint Center recognized the unpaid toll smishing scam in early March 2024 and noted more than 2,000 complaints had been made by April 12, when it put out its first alert.
Since then, periodically, state highway and turnpike authorities have put out alerts, including all six New England states and New York.
The U.S. Postal Service and the IRS have also put out alerts about smishing attempts with texters impersonating their agencies.
Smishing, a cute word that sounds vaguely Yiddish, was coined in 2006, according to Merriam-Webster. It combines the acronym SMS, which stands for โshort message serviceโ referring to a text message, with phishing, the term for email or internet-based scams.
Brian Levine told the Berkshire Eagle he gets smishing attempts all the time, though he hasnโt received the EZDriveMA one. Heโs a distinguished professor at the University of Massachusetts Amherst in the Manning College of Information and Computer Sciences.
โI think itโs pretty common these days, because everyone has a phone … and everyone with a phone number can receive text messages,โ he said.
Part of the reason smishing attempts are so common is because the phone texting system isnโt secure.
โItโs easy to send fake messages, meaning they may appear to be from your local town, but they could come from anywhere in the globe, and thereโs barely any mechanism that would prevent that,โ Levine said.
While text messages may be thought of as postcards, because theyโre โviewable by anyone,โ Levine said thereโs one crucial difference: the postmark.
โThereโs nothing in an SMS message to authenticate where it actually came from and to keep it private,โ Levine said.
Smishing attempts are designed to take advantage of typical behaviors โ or social engineering โ and this one does in specific ways.
โPeople are busy, and theyโre used to receiving real messages that are important on their phone, because theyโre from their family or their jobs or places they do business with, like their banks,โ he said. โWeโre busy and weโre distracted. We say, โOh, my God, this is important. I have to react to this. I owe someone money.โโ
However, the inclination to instantly resolve the issue could create far bigger ones: from the loss of $6.99 to identity theft.
While these attacks have a low chance for success, theyโre easy to automate and donโt cost much to initiate, which is why theyโve become so prevalent, Levine said.
โIf it costs very little to carry out, that can be very profitable,โ he said.
He said the $6.99 amount was likely chosen by the scammer because victims will consider that amount small and pay it without stopping to question the legitimacy of the demand.
There are often clues within scams that indicate the source is fake. In the EZDriveMA scam, Levine noted the URL ending. Any Massachusetts agency would have .ma as the final extension.
But even if the targets of a smishing attempt donโt recognize that sort of clue, thereโs a way to ensure theyโre not trapped by these scams.
Levine recommends using the following strategy to avoid getting caught by smishing, phishing or vishing. Vishing is the name given to similar attacks using voicemail, phone calls using either real or computer-generated voices.
Donโt click on a link or interact with the text message, the caller or the email, Levine advises. Donโt interact with that number or email and instead contact the entity using a known and trusted website, email address or phone number.
โItโs annoying to be secure,โ Levine said. โIt takes extra work, and thatโs what theyโre taking advantage of. Itโs much easier to just click this link in your text message and not think about it, but thatโs what youโve got to do.โ
Levine uses a free messaging app called Signal, which filters text messages. Similarly, he has three email addresses: one for personal friends, a second for work and a third for receipts.
Levine said older adults may be vulnerable to smishing and recommends placing safeguards to prevent the loss of lifelong savings.
Heโs also concerned about those who are new to cellphones, such as children, who may be unfamiliar with scams. While they may not be vulnerable to this one because they may not be old enough to drive, there are others involving gifts and packages.
โThis should be part of their financial education,โ Levine said.

