A recent EZDriveMA smishing scam, or text messaging scam, has set off warnings by the MassDOT. “MassDOT is underscoring that: EZDriveMA will never request payment by text.”
This screenshot shows an attempt by a scammer at smishing, obtaining money and possibly personal information.
Community Voices Editor
A recent EZDriveMA smishing scam, or text messaging scam, has set off warnings by the MassDOT. “MassDOT is underscoring that: EZDriveMA will never request payment by text.”
It looks so benign.
The reminder appears to come from EZDriveMA, the Massachusetts Turnpike Authority’s electronic tolling program.
“Your bill for $6.99 is due soon.” The text message contains a link and instructs you to “pay and avoid additional fees” by replying with a Y and activating a link or copying the link into your browser.
This is smishing, a text message scam, technically referred to as a tactic at social engineering.
Based on a recent uptick of reports, MassDOT made its third warning about smishing in recent months.
“MassDOT is underscoring that: EZDriveMA will never request payment by text,” according to the warning. “All links associated with EZDriveMA will include www.EZDriveMA.com.”
This screenshot shows an attempt by a scammer at smishing, obtaining money and possibly personal information.
The FBI Internet Crime Complaint Center recognized the unpaid toll smishing scam in early March 2024 and noted more than 2,000 complaints had been made by April 12, when it put out its first alert.
Since then, periodically, state highway and turnpike authorities have put out alerts, including all six New England states and New York.
The U.S. Postal Service and the IRS have also put out alerts about smishing attempts with texters impersonating their agencies.
Smishing, a cute word that sounds vaguely Yiddish, was coined in 2006, according to Merriam-Webster. It combines the acronym SMS, which stands for short message service referring to a text message, with phishing, the term for email or internet-based scams.
Brian Levine said he gets smishing attempts all the time, though he hasn’t received the EZDriveMA one. He’s a distinguished professor at the University of Massachusetts at Amherst in the Manning College of Information and Computer Sciences.
“I think it’s pretty common these days, because everyone has a phone, every phone has a phone number, pretty much, and everyone with a phone number can receive text messages,” he said.
Part of the reason smishing attempts are so common is because the phone texting system isn’t secure.
“It’s easy to send fake messages, meaning they may appear to be from your local town, but they could come from anywhere in the globe, and there’s barely any mechanism that would prevent that,” he said.
While text messages may be thought of as postcards, because they’re “viewable by anyone,” Levine said there’s one crucial difference: the postmark.
“There’s nothing in an SMS message to authenticate where it actually came from and to keep it private,” Levine said.
The FBI recommends anyone receiving such a text take the following steps:
File a complaint with the IC3, www.ic3.gov, be sure to include:
Check your account using the toll service’s legitimate website.
Contact the toll service’s customer service phone number.
Delete any smishing texts received.
If you clicked any link or provided your information, take efforts to secure your personal information and financial accounts. Dispute any unfamiliar charges.
Smishing attempts are designed to take advantage of typical behaviors — or social engineering — and this one does in specific ways.
“People are busy, and they’re used to receiving real messages that are important on their phone, because they’re from their family or their jobs or places they do business with, like their banks,” he said. “We’re busy and we’re distracted, we say: ‘Oh, my God, this is important. I have to react to this. I owe someone money.’”
However, the inclination to instantly resolve the issue could create far bigger ones: from the loss of $6.99 to identity theft.
While these attacks have a low chance for success, they’re easy to automate and don’t cost much to initiate, which is why they’ve become so prevalent, Levine said.
“If it costs very little to carry out, that can be very profitable,” he said.
He said the $6.99 amount was likely chosen by the scammer because victims will consider that amount small and pay it without stopping to question the legitimacy of the demand.
There are often clues within scams that indicate the source is fake. In the EZDriveMA scam, Levine noted the URL ending. Any Massachusetts agency would have .ma as the final extension.
But even if the targets of a smishing attempt don’t recognize that sort of clue, there’s a way to ensure they’re not trapped by these scams.
Levine recommends using the following strategy to avoid getting caught by smishing, phishing or vishing. Vishing is the name given to similar attacks using voicemail, phone calls using either real or computer-generated voices.
Don’t click on a link or interact with the text message, the caller or the email, Levine advises. Don’t interact with that number or email and instead contact the entity using a known and trusted website, email address or phone number.
“It’s annoying to be secure,” Levine said. “It takes extra work, and that’s what they’re taking advantage of. It’s much easier to just click this link in your text message and not think about it, but that’s what you’ve got to do.”
Levine uses a free messaging app called Signal, which filters text messages.
Similarly, he has three email addresses: one for personal friends, a second for work and a third for receipts.
Levine said older adults may be vulnerable to smishing and recommends placing safeguards to prevent the loss of lifelong savings.
He’s also concerned about those new to cellphones, such as children, who may be unfamiliar with scams. While they may not be vulnerable to this one because they may not be old enough to drive, there are others involving gifts and packages.
“This should be part of their financial education,” he said.
Jane Kaufman is Community Voices Editor at The Berkshire Eagle. She can be reached at [email protected] or 413-496-6125.
Beyond data breaches, the privacy of our data is compromised by what we knowingly and unwittingly share with others.
If you recently got a text message trying to collect money for outstanding parking tickets in Williamstown, it’s a scam, town police say.
Community Voices Editor
The Cantilena Chamber Choir will present its annual Martin Luther King Jr. Concert at Trinity Church at 3 p.m. Sunday. The concert features a return appearance by the Urban Choral Arts Society from Baltimore and readings by Berkshire County student essay winners.
The nonprofit gives $5,000 to eight families a month, and $10,000 in December for Christmas. This month, families from Housatonic and Lee were the benefactors.
Rabbi Shira Stern of Lenox has been deployed to Los Angeles by the American Red Cross as supervisor of the Disaster Spiritual Care Division; she will lead a team tasked with providing spiritual support to those affected by the fires.
As Massachusetts races to meet its clean energy goals and electric cars catch on, more electric vehicles are arriving in the Berkshires. While there are plans in the works and on the books for more public EV chargers in Berkshire County, as of now, 19 towns don’t have public charging stations.
If you recently got a text message trying to collect money for outstanding parking tickets in Williamstown, it’s a scam, town police say.
At the Officer Michael J. Silver Memorial Game at Berkshire School on Saturday, Boston Bruins Alumni took on the Berkshire County Law Enforcement team to honor the late Silver, a Pittsfield Police officer who died in October.
{{summary}}
Your browser is out of date and potentially vulnerable to security risks.
We recommend switching to one of the following browsers:
Get up-to-the-minute news sent straight to your device.