logo
FBI warns of dangerous new ‘smishing' scam targeting your phone

FBI warns of dangerous new ‘smishing' scam targeting your phone

Fox News15-03-2025

Smishing is a type of phishing scam that works through text messages.
The name comes from a mix of "SMS" and "phishing," since scammers use fake messages to trick people into giving away personal information. It's been around for a while, but lately, it's gotten so bad that even the FBI and several U.S. cities have started warning people.
Hackers have set up over 10,000 fake websites to keep these scams going, targeting both iPhone and Android users with texts designed to steal their personal and financial information.
Cities across the United States are warning residents about an ongoing mobile phishing campaign in which scammers impersonate parking violation departments. The fraudulent text messages claim recipients have unpaid parking invoices and threaten a $35 daily fine if left unpaid. As reported by cybersecurity publication BleepingComputer, the latest wave of phishing texts has prompted alerts from multiple cities, including Annapolis, Boston, Greenwich, Denver, Detroit, Houston, Milwaukee, Salt Lake City, Charlotte, San Diego and San Francisco.
The campaign, which began in December, remains active. The smishing texts claim to be from a government authority and instruct recipients to click a link to pay an alleged overdue fine.
"This is a final reminder from the City of New York regarding the unpaid parking invoice. A $35 daily overdue fee will be charged if payment is not made today," one fraudulent message says.
The same phishing template has been observed in similar scams targeting residents of other cities. The FBI has also raised concerns about a broader smishing campaign affecting U.S. residents. In a recent alert, the agency warned that scammers have expanded beyond parking fines and are now impersonating road toll collection services.
"Since early March 2024, the FBI Internet Crime Complaint Center (IC3) has received over 2,000 complaints reporting smishing texts representing road toll collection services from at least three states," the agency stated. "IC3 complaint information indicates the scam may be moving from state to state."
A new report from cybersecurity firm Palo Alto Networks' Unit 42, the company's cybersecurity division specializing in threat intelligence and incident response, has uncovered that these scams are designed to steal sensitive information, including credit card and bank account details.
What started as a scheme involving fraudulent toll payment notifications has now expanded to include fake delivery service alerts, tricking users into clicking malicious links.
The scam appears to be operated by local cybercriminals using a toolkit developed by Chinese hacking groups. Notably, research from Unit 42 shows that many of the scam's root domains and fully qualified domain names use the Chinese .XIN top-level domain (TLD).
1. Verify before you trust: Treat unsolicited texts with caution. If a message claims to be from a government agency or company, don't click any links or act immediately. Instead, verify the claim by contacting the organization directly using an official phone number or checking their verified website.
2. Avoid clicking suspicious links and use strong antivirus software: Scammers use links to direct you to fake websites that can steal your personal or financial information. Instead of clicking on any link in an unexpected text, manually type the known URL into your browser or search for the organization's official website.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
3. Keep your devices secure: Regularly update your devices' operating systems and apps to ensure you have the latest security patches. Consider installing reputable security software that can help detect phishing attempts and warn you about potentially dangerous websites or messages.
4. Use a password manager: A trusted password manager can help protect your sensitive information by automatically filling in credentials only on verified sites. This minimizes the risk of entering details on fraudulent websites and can alert you if a site doesn't match what's expected. Get more details about my best expert-reviewed Password Managers of 2025 here.
5. Report suspicious activity: If you receive a text that seems off, report it immediately to your mobile carrier, local law enforcement or the FBI's Internet Crime Complaint Center (IC3). Reporting helps authorities track down scammers and prevent further attacks.
6. Consider using a personal data removal service: Personal data removal services can help reduce your exposure to smishing attacks by removing your sensitive information — like phone numbers, addresses and email details — from data broker websites. Scammers often rely on these publicly available databases to target victims with personalized phishing texts. These services aren't foolproof, but they can make it harder for cybercriminals to find and exploit your information. While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.
I've been tracking these smishing scams, and it's clear they're evolving fast, from fake parking fines to bogus toll notifications. With the FBI and cities like New York, San Francisco and others sounding the alarm, I'm stepping up my own security game. As a general rule, if you receive a text from an unknown number or email address that's an out-of-the-blue greeting, asks you to click a link, pay a bill or respond in any way, just block it and report the number. It's better to be safe than sorry when it comes to protecting your personal information.
Do you feel that mobile phone providers and tech companies are doing enough to protect users from these types of scams? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

FBI Confirms iPhone And Android Warning—Delete These New Texts
FBI Confirms iPhone And Android Warning—Delete These New Texts

Forbes

timean hour ago

  • Forbes

FBI Confirms iPhone And Android Warning—Delete These New Texts

FBI confirms new DMV text attacks AFP via Getty Images Attacks on iPhone and Android users surged more than 700% this month, with malicious texts targeting multiple cities and states. Following alerts from police forces across the country, the FBI has now confirmed the latest warning and stepped in. This threat comes directly from China, and you need to delete all these texts immediately. As I reported earlier this week, the infamous unpaid toll texts that have plagued American smartphone users for more than a year 'have seen a significant decline recently. But the DMV texts that have replaced them are 'more threatening.' That's the warning from Guardio, whose researchers have been tracking these attacks for months. Its team 'spotted a 773% surge in DMV scam texts during the first week of June,' which shows no signs of slowing. 'These scam texts lead to phishing websites designed to steal people's credit card information and make unauthorized charges.' DMV text surge Guardio Now the FBI has confirmed it is investigating the DMV scam. According to FBI Tennessee's Supervisory Special Agent David Palmer, the unpaid toll cybercriminals have 'pivoted to the DMV scam.' Confirming the gangs operate from overseas, Palmer warns these texts can 'put malware on your phone, which then can go in and steal information from your device, or collect your payment information.' Palmer warns smartphone users 'if you don't know who [a text] is from, don't click the link.' Those links use domains crafted to trick users into thinking they're legitimate. As Guardio explains, 'scammers generate a new domain for almost every DMV text. The format is usually the name of a state followed by a generic domain. Sometimes they include '.gov' as part of the URL to make the website appear legitimate.' DMV Texts Guardio There will be millions of these texts sent out over the coming weeks and months. As Resecurity warns, 'just one threat actor can send "up to 2,000,000 smishing messages daily,' which means targeting 'up to 60,000,000 victims per month, or 720,000,000 per year, enough to target every person in the U.S. at least twice every year.' Just as with undelivered packages and unpaid tolls, the FBI's advice is to 'delete any smishing texts received.' You don't want the dangerous links left on your phone, even though many are only active for a few hours before they're detected and blocked. The new DMV attacks go beyond the late payment lure with the toll texts, these cite a non-specific traffic offense and threaten suspensions of driving licenses and vehicle registrations. They create a sense of panic and urgency to push users to engage. Don't. Every one of these texts is a scam. If you have any doubts, contact your DMV using public channels. You can report the text. But you must delete it

Man arrested as part of FBI investigation, charged in connection with 3 pipe bomb incidents
Man arrested as part of FBI investigation, charged in connection with 3 pipe bomb incidents

Yahoo

timean hour ago

  • Yahoo

Man arrested as part of FBI investigation, charged in connection with 3 pipe bomb incidents

A man was arrested as part of an FBI investigation and has been charged in connection with three pipe bomb incidents. [DOWNLOAD: Free WHIO-TV News app for alerts as news breaks] The FBI Joint Terrorism Task Force arrested 50-year-old Robert Gilb in Green Township, according to an FBI Cincinnati spokesperson. As previously reported by News Center 7, FBI agents were seen going in and out of a home in an Ohio neighborhood. TRENDING STORIES: 6-year-old hit, killed by car in Harrison Township Officers respond after vehicle reportedly hits Miami County motel Former school staffer who pleaded guilty to sexual relationship with student sentenced to prison Gilb has been charged with three counts of possessing an unregistered destructive device and three counts of transporting explosive materials, the spokesperson said. 'This alleged activity posed a serious risk to public safety,' said Elena Iatarola, FBI Cincinnati Special Agent in Charge. 'The FBI worked closely with our law enforcement partners to neutralize this potential danger and protect the community.' Gilb is accused of detonating three improvised explosive devices (IEDs) in Hamilton and Butler counties, according to court documents. 'A complaint affidavit details that on April 12, Hamilton County sheriff's deputies were dispatched to Miami Township for a report of a loud explosion. They discovered what appeared to be a blast crater and components of an improvised explosive device (IED),' said FBI Cincinnati. 'Further investigation revealed that there were two prior incidents in Morgan Township that allegedly had similar characteristics to the incident in Miami Township. Butler County sheriff's deputies had responded to incidents there on March 23 and March 28.' Witnesses allegedly saw Gilb in a white BMW near the site where at least one of the IEDs exploded, FBI Cincinnati said. He faces up to 10 years in prison if he's convicted of both charges. [SIGN UP: WHIO-TV Daily Headlines Newsletter]

Milwaukee shooting Wednesday, 41st and Meinecke; 1 injured
Milwaukee shooting Wednesday, 41st and Meinecke; 1 injured

Yahoo

time3 hours ago

  • Yahoo

Milwaukee shooting Wednesday, 41st and Meinecke; 1 injured

The Brief A 20-year-old was injured in a shooting in Milwaukee on Wednesday, June 11. It happened around 4:20 p.m. near 41st and Meinecke. The circumstances leading up to the shooting are under investigation. MILWAUKEE - One person was injured in a shooting in Milwaukee on Wednesday, June 11. What we know The Milwaukee Police Department said it happened around 4:20 p.m. near 41st and Meinecke. The 20-year-old victim was taken to the hospital for treatment of injuries. FREE DOWNLOAD: Get breaking news alerts in the FOX LOCAL Mobile app for iOS or Android The circumstances leading up to the shooting are under investigation. Police continue to seek anyone involved. What you can do Anyone with any information is asked to contact the MPD at 414-935-7360 or to remain anonymous, contact Crime Stoppers at 414-224-TIPS or use the P3 Tips app. The Source The Milwaukee Police Department

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store