Hackers Mess With TxTag System to Harvest Credit Card Data via Phishing Campaign
Cybercriminals Exploit Government Email Systems in Sophisticated TxTag Toll Scam – How a $6.69 Fake Toll Notice Became a Major Security Threat
A field guide for Houston drivers and businesses on how to spot the fake unpaid-toll text, verify it in ten seconds, report it, and keep your staff from handing over a company card.
A TxTag scam text is toll smishing: a text-message phishing attack that impersonates the Texas TxTag toll service, claims you owe a small unpaid balance, and rushes you to a fake payment page built to harvest your card. If a Houston driver or one of your employees taps that link and types in a card number, the money and the data are gone in minutes.
The tell that ends the argument: the Texas Department of Transportation, which runs TxTag, says flat out that it does not send text messages about final payment reminders or past-due balances. Any text claiming you owe an unpaid toll is a scam, no matter how real the logo looks or how small the dollar amount. Real TxTag texts arrive only from the short code 22498. A ten-digit cell number or a strange link is your answer.
This is not a rare event. The FBI Internet Crime Complaint Center received more than 60,000 complaints in 2024 about suspicious unpaid-toll messages, and the campaign behind them, tracked by Resecurity as the China-based "Smishing Triad," has spoofed toll services across dozens of states. For a business, one commuting employee who pays a fake $6.69 toll on a company card can hand an attacker a live card number and a foothold. This guide walks the four steps that stop it: recognize, verify, report, protect.
How Do You Recognize a TxTag Scam Text?
Step 1 is pattern recognition. Toll smishing texts share a handful of tells that give them away in seconds once you know what to look for.
A TxTag scam text almost always pairs a small, oddly specific dollar amount with a hard deadline and a threat: pay $6.69 in 12 hours or your vehicle registration goes on hold and the case gets reported to the DMV. That mix of tiny cost and big consequence is engineered to make you pay before you think.
The dollar figure is small on purpose. A demand for $6.69 or $12.51 feels too minor to argue with and too plausible to be fake, so people pay to make it go away. The urgency does the rest. TxDOT and news outlets across the state, from KVUE in Austin to NBC 5 in Dallas-Fort Worth, have documented the same template hitting Texas phones since 2024, with a spike through 2025.
- Check the sender. A legitimate TxTag text comes only from short code 22498. A scam arrives from a regular ten-digit cell number, an email-to-text address, or an overseas number. If it is not 22498, it is not TxTag.
- Read the link, do not tap it. Real TxTag lives at TxTag.org. Scam links use lookalike domains such as txtag-help.xyz, txtag-us.xyz, or other odd endings crammed with the word "toll." The domain right before the first single slash is what matters, and it will not be txtag.org.
- Weigh the pressure. "Pay within 12 hours to avoid a late fee" and "you will be reported to the DMV" are fear levers, not government procedure. Real agencies mail notices; they do not text a countdown clock.
- Notice the delivery. Many of these are not ordinary SMS at all. Researchers at Palo Alto Networks Unit 42 found the Smishing Triad sends lures over iMessage and RCS, which slip past some carrier spam filters, so "it got through, it must be real" is false comfort.
Here is the version that lands in Houston inboxes and phones. In the original wave, the same crew also ran an email variant that abused a real government messaging platform, so the message looked like it came from an official address. Recognition still holds: the amount is tiny, the deadline is fake, and the link is not TxTag.org.
Tap that link and you land on a page that copies the TxTag portal down to the colors. It asks for your name, address, phone, and then the full card number with CVV. The fake site even validates the card in real time, so a wrong-looking number gets rejected and a real one gets stolen. That is the whole point of the tiny toll: it is bait for the card, not the $6.69.
How Do You Verify a Toll Charge Without Tapping the Link?
Step 2 is the habit that makes you scam-proof: never use the contact path a message hands you. Go to the source yourself.
The single move that defeats every toll smishing text is verifying out of band: instead of tapping the link or calling the number in the message, you open a separate channel you already trust. Type TxTag.org into your browser by hand, or call TxTag customer service at 1-888-468-9824, and check whether you actually owe anything.
Out-of-band verification works because the scam depends on you staying inside the message. Every link and phone number the attacker gives you leads back to them. The instant you leave that channel and reach TxTag the way you always would, the fake payment page has nothing to grab. If you genuinely have a small unpaid toll, you will see it on your real account and pay it safely there.
- Do not tap the link, ever. Not to "just check," not to unsubscribe. Tapping can load a data-harvesting page or fingerprint your device. Treat the link as live wiring.
- Type the real address yourself. Open a browser and enter TxTag.org manually, or use a bookmark you saved before. Do not search and click the top result during a rushed moment, and do not trust the link in the text.
- Call the number you look up, not the one you were sent. TxTag customer service is 1-888-468-9824. If a text hands you a different number, that number is part of the trap.
- Sanity-check against the rule. TxDOT confirms TxTag does not text about past-due balances. So even before you verify, you already know a payment-demand text is fake. Verifying just confirms your account is clean.
This one habit generalizes far past tolls. The same out-of-band check stops fake bank alerts, fake package-delivery texts, and fake invoice emails. In 35 years around this work, the businesses that avoid wire fraud and card theft are not the ones with the fanciest tools. They are the ones where "verify through a channel you already trust before you act" is simply how people operate.
Want Your Team to Recognize Smishing Before They Tap?
CinchOps runs security awareness training and simulated phishing and smishing for Houston-area businesses, so your staff spots the fake toll text, the fake invoice, and the fake bank alert before a company card is ever exposed.
Talk to CinchOpsWhere Do You Report a TxTag Scam Text?
Step 3 turns a deleted text into a data point that helps shut the operation down and protects the next Houston driver.
Reporting a toll smishing text takes under two minutes and hits three places: file a complaint with the FBI Internet Crime Complaint Center at ic3.gov, forward the message to your carrier's spam service at 7726 (SPAM), and tell TxTag so they can flag the domain. Then delete it.
Reports matter because they aggregate. The FBI issued its national alert only after IC3 collected thousands of complaints and traced the pattern across states, and Google filed suit in November 2025 against the group behind the toll texts using exactly this kind of victim data. Your two-minute report is a pixel in that picture.
- File with the FBI IC3. Go to ic3.gov and report the message. Include the sender's number or address and the link, without tapping it. This is the database that drives federal action.
- Forward to 7726. On any US carrier, forwarding a scam text to 7726 (which spells SPAM) feeds it to the carrier's abuse team so they can block the source for everyone.
- Tell TxTag and the FTC. Report it to TxTag at 1-888-468-9824 or through TxTag.org, and file with the Federal Trade Commission at ReportFraud.ftc.gov. Both track toll-scam domains.
- If someone already paid, act fast. Call the card issuer to freeze and reissue the card, watch the statement, and consider a fraud alert with the credit bureaus. Speed limits the damage.
For a business, add one internal step: report it to your own IT or security contact too. If one employee got the text, others likely did, and a quick heads-up to the whole team turns a single close call into a company-wide save. That is where the personal habit and the business process meet.
The toll text works because it is small and scary at the same time. Nobody wants to lose their registration over seven dollars, so they tap before they think. I tell every Houston business owner the same thing: teach your people one reflex, which is to verify through a channel they already trust before they ever type a card number. That reflex is worth more than any filter you can buy.
How Do You Protect Your Staff and Company Cards?
Step 4 moves from personal reflex to business policy, because for a company the risk is not one lost toll payment. It is a live company card in a criminal's hands.
For a Houston business, a toll scam text is a phishing test your employees take without warning. Protecting the company means making the right move the easy move: a simple verify-before-you-pay rule, ongoing awareness training, tight controls on company cards, and a fast way for staff to ask "is this real?"
The exposure is bigger than most owners assume. Commuting employees across Katy, Cypress, Sugar Land, and The Woodlands drive the toll roads daily, so they are exactly the people who find a $6.69 toll notice believable. Put a corporate card in that person's pocket and one tap can expose a card the whole team uses. Google's investigation estimated the group behind these texts may have compromised tens of millions of US cards, which tells you the machine on the other end is industrial, not amateur.
- Write one rule everyone knows. No one pays a bill, toll, or invoice from a link in a text or email. They verify through the official site or a known phone number first. Put it in the handbook and the onboarding checklist.
- Train on the real thing. Regular security awareness training with simulated phishing and smishing builds the reflex under safe conditions. People who have seen a fake toll text in a drill do not fall for the live one.
- Lock down company cards. Use per-card limits, transaction alerts, and virtual cards where you can, so a single stolen number is capped and easy to kill. Make it painless to report a card and get a new one.
- Give staff a fast lane to ask. A dedicated channel or address where anyone can forward a suspicious message and get a quick answer beats a policy nobody reads. Reward the question, never punish it.
Toll smishing is one flavor of a broader shift. The same crews run fake bank alerts, fake package texts, and, increasingly, tricks like ClickFix and QR-code quishing that push a target to act against their own interest. Train your team for the pattern, not just the toll, and you are covered when the next lure swaps a toll for a package or a payroll change.
Turn One Scam Text Into a Trained, Protected Team
CinchOps delivers security awareness training, simulated phishing and smishing, advanced email and message filtering, and 24/7 monitoring for Houston-area businesses, so a fake toll text becomes a teachable moment instead of a stolen card. It is part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity services →How CinchOps Helps Houston Businesses Beat Toll Smishing
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, turning a scam text like the TxTag toll fraud into a caught, reported, and forgotten non-event.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Beating smishing takes trained people and layered defenses working together, which is exactly what a managed partner provides:
- Security awareness training. Ongoing education plus simulated phishing and smishing, so staff recognize the fake toll text and the fake invoice before they act.
- Email and message filtering. Advanced filtering and threat intelligence that catches impersonation attempts traditional filters miss.
- 24/7 monitoring and response. Fast detection and containment if a credential or card is exposed, before one mistake spreads.
- Access and card-abuse controls. Authentication, access controls, and endpoint protection that limit what a stolen credential can reach.
You do not need your commuting employees to be security experts. You need a partner who trains them, filters the worst of it out, and stands ready when something slips through. If your business in Houston or Katy wants the fake toll text to be a shrug instead of a scramble, talk to CinchOps and we will build the training and defenses that make it one.
Frequently Asked Questions
Is the TxTag unpaid-toll text a scam?
Yes. The Texas Department of Transportation confirms TxTag does not send text messages about past-due balances or final payment reminders. Any text claiming you owe an unpaid toll is toll smishing, no matter how small the amount. Real TxTag texts come only from short code 22498, so a ten-digit number or an odd link is a scam.
What should I do if I get a TxTag scam text?
Do not tap the link. Verify by typing TxTag.org yourself or calling 1-888-468-9824 to check your real balance. Then report it: file at ic3.gov, forward the message to 7726, and tell TxTag. Delete it. If you already entered a card, call your issuer immediately to freeze and reissue it.
How do I tell a real TxTag text from a fake one?
Check the sender first. Legitimate TxTag texts arrive only from short code 22498; scams come from regular cell numbers or email-to-text addresses. Real links go to TxTag.org, while scam links use lookalike domains like txtag-help.xyz. Real agencies do not text a payment countdown or threaten your registration, so urgency plus a tiny dollar amount is the tell.
Why are Houston drivers targeted by toll smishing?
Houston-area commuters across Katy, Cypress, Sugar Land, and The Woodlands use toll roads daily, so a small unpaid-toll notice feels believable. The China-based group Resecurity tracks as the Smishing Triad spoofs toll services state by state, and the FBI IC3 logged more than 60,000 unpaid-toll complaints in 2024. High toll usage plus name recognition makes Texas a prime target.
How can a business protect employees from toll scam texts?
Set one rule: no one pays a bill or toll from a text or email link without verifying through the official site or a known number first. Add regular security awareness training with simulated phishing and smishing, tight company-card controls with alerts and limits, and a fast channel where staff can ask "is this real?" without being punished for asking.
Discover More
Sources
- FBI Internet Crime Complaint Center (IC3), Smishing Scam Regarding Debt for Road Toll Services (PSA240412)
- TxDOT, Warning Drivers of Spike in Texting Scams Targeting TxTag Customers (short code 22498; TxTag does not text about balances)
- Resecurity, Smishing Triad Is Now Targeting Toll Payment Services in a Massive Fraud Campaign Expansion
- Palo Alto Networks Unit 42, The Smishing Deluge: China-Based Campaign Flooding Global Text Messages (iMessage/RCS delivery)
- Krebs on Security, Chinese Innovations Spawn Wave of Toll Phishing Via SMS
- Cofense, TxTag Takedown: Busting Phishing Email Schemes (fake domains, lookalike portal, card validation)
- NBC 5 Dallas-Fort Worth, Text Messages Claiming Unpaid Toll Bills Are a Scam, Officials Warn