{"id":3939,"date":"2025-05-14T10:03:27","date_gmt":"2025-05-14T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/14\/hacking-abusing-govdelivery-for-txtag-toll-charges-phishing-attack\/"},"modified":"2025-05-14T10:03:27","modified_gmt":"2025-05-14T10:03:27","slug":"hacking-abusing-govdelivery-for-txtag-toll-charges-phishing-attack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/14\/hacking-abusing-govdelivery-for-txtag-toll-charges-phishing-attack\/","title":{"rendered":"Hacking Abusing GovDelivery For TxTag \u2018Toll Charges\u2019 Phishing Attack"},"content":{"rendered":"<p>    Hacking Abusing GovDelivery For TxTag \u2018Toll Charges\u2019 Phishing Attack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated <a href=\"https:\/\/cybersecuritynews.com\/5-ways-threat-intelligence-helps-against-phishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing operation<\/a> exploiting compromised Indiana government sender accounts to distribute fraudulent TxTag toll collection messages.\u00a0<\/p>\n<p>The campaign, which emerged this week, leverages the GovDelivery communications platform to lend legitimacy to the scam emails targeting unsuspecting recipients nationwide.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Sophisticated Phishing Targets Indiana Toll Users\u00a0<\/strong><\/h2>\n<p>The phishing emails, which appear to originate from legitimate Indiana government email addresses like DLGF@public.govdelivery.com, inform recipients of fictitious unpaid toll charges.\u00a0<\/p>\n<p>The attackers utilized newly registered look-alike domains hosting convincing TxTag payment portals designed specifically to harvest sensitive information.<\/p>\n<p>\u201cThe phishing emails used newly registered look-alike domains hosting fake TxTag pages designed to steal personal info, credit card data, and <a href=\"https:\/\/cybersecuritynews.com\/new-gorilla-android-malware-intercept-sms-messages\/\" target=\"_blank\" rel=\"noreferrer noopener\">one-time passcode (OTP)<\/a>,\u201d Trustwave SpiderLabs report shared with Cyber Security News.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc1e10-uY4qNBKNXstIcUCE_NgzoNGIP9AJekphYrNOfOP-q_syStWE8Y4_vSJnaIZ4K2yf0NTwppIoKcyujEqgDdX8VJ2nizP55I94pR_XrQH9YbyPZF3KISVLhBe0bzErslgERg?key=HAtLlMSRBSk3gl81w4I_aQ\" alt=\"\"><\/figure>\n<\/div>\n<p>Technical analysis revealed sophisticated data exfiltration methods employed by the attackers.\u00a0<\/p>\n<p>The fraudulent websites not only collect victim information through POST requests to endpoints like https:\/\/txtag-us.xyz\/api\/client\/* but also maintain persistent WebSocket connections (wss:\/\/txtag-us.xyz\/sync-message) enabling real-time session monitoring.\u00a0<\/p>\n<p>This allows attackers to track victim interactions with the phishing site and potentially bypass security measures.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Exploitation of Government Email Infrastructure<\/strong><\/h2>\n<p>The Indiana Office of Technology (IOT) confirmed that the phishing campaign stems from a security breach involving a former government contractor.\u00a0<\/p>\n<p>The Indiana Office of Technology said the scam emails are linked to a private vendor whose contract with the state ended last year, but apparently did not remove the state\u2019s account from its system.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdpiU4tOn2IKHiojqYswGZQ-M_btV42kOozuUvyS8NyScJ_07Zc-v2gSlUjgSOVBIZ-fdw_Q9B-uSBzUUtrjibpMtMEgdvndhrUkDhCJkuxGHjyBmCy_UgQ4RDS4i6hyeRO5h8YbA?key=HAtLlMSRBSk3gl81w4I_aQ\" alt=\"\"><\/figure>\n<\/div>\n<p>Investigations <a href=\"https:\/\/x.com\/SpiderLabs\/status\/1922481154625601921\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">revealed<\/a> that although the state\u2019s contract with GovDelivery ended on December 31, 2024, the associated account remained active.\u00a0<\/p>\n<p>This oversight provided an attack vector for malicious actors who compromised a contractor\u2019s credentials, gaining access to GovDelivery\u2019s email distribution capabilities that reach millions of subscribers.<\/p>\n<p>Indiana Secretary of State Diego Morales issued an urgent warning on May 13, 2025: \u201cThese scams are dangerous, deceptive, and disruptive. I want to remind all Hoosiers to be cautious before opening emails and clicking on any unsolicited links, especially those that request personal information or direct you to unfamiliar websites. Your security is our top priority\u201d.<\/p>\n<p>The IOT emphasized that legitimate government agencies do not send toll notifications via email or text.\u00a0<\/p>\n<p>Similar warnings have been issued in other states, with the Illinois Tollway confirming they \u201cDO NOT use non-tollway entities \u2013 third-party websites \u2013 to collect or modify customer account information\u201d.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Protective Measures<\/strong><\/h2>\n<p>Security experts recommend that recipients of these emails:<\/p>\n<ul class=\"wp-block-list\">\n<li>Avoid clicking any links or opening attachments in suspicious emails.<\/li>\n<li>Forward suspicious messages to proper authorities (info@getipass.com for Illinois residents).<\/li>\n<li>Contact <a href=\"https:\/\/cybersecuritynews.com\/new-chinese-smishing-kit-dubbed-panda-shop\/\" target=\"_blank\" rel=\"noreferrer noopener\">credit card<\/a> providers immediately if payment information was entered on suspicious sites.<\/li>\n<li>Verify toll charges directly through official websites (TxTag.org) or official customer service numbers (1-888-468-9824).<\/li>\n<\/ul>\n<p>This incident highlights growing concerns about compromised government communication systems being weaponized for phishing campaigns.\u00a0<\/p>\n<p>As GovDelivery serves over 300 million subscribers worldwide, the potential impact of such breaches extends far beyond this single campaign, underscoring the critical importance of secure vendor management practices for government communications infrastructure.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Arm your business against phishing &amp; <strong>suspicious artifacts\u00a0<\/strong> with top threat intelligence,\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=5-ways-ti&amp;utm_content=plans&amp;utm_term=140525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">test TI Lookup with 50 trial requests<\/a>\u00a0<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hacking-abusing-govdelivery-for-txtag-toll-charges\/\">Hacking Abusing GovDelivery For TxTag \u2018Toll Charges\u2019 Phishing Attack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hacking-abusing-govdelivery-for-txtag-toll-charges\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hacking Abusing GovDelivery For TxTag \u2018Toll Charges\u2019 Phishing Attack A sophisticated phishing operation exploiting compromised Indiana government sender accounts to distribute fraudulent TxTag toll collection messages.\u00a0 The campaign, which emerged this week, leverages the GovDelivery communications platform to lend legitimacy to the scam emails targeting unsuspecting recipients nationwide. Sophisticated Phishing Targets Indiana Toll Users\u00a0 The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[677,129,63,124],"tags":[130],"class_list":["post-3939","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-article","category-cyber-security","category-cyber-security-news","category-phishing","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3939"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3939"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3939\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3939"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3939"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3939"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}