Scroll to top
Threat Intelligence Factor's research team tracks real-world phishing, impersonation and social-engineering campaigns as they happen. See All Reports →

Fast Lane, Fast Pain: A Toll-Road Phishing Kit That Bypassed Two-Factor Authentication

By Guy Ushomirsky, Factor Security Research · 18 Jul 2026

Factor's research team recently examined a phishing campaign built around one of the most routine notifications a driver can receive: an unpaid toll. The campaign impersonated Kvish 6, Israel's major toll highway, and combined a small, believable charge with a real-time two-factor relay — a pairing that let attackers complete fraudulent transactions before most victims realized anything was wrong.

  1. Step 1: The Entry Point

    The campaign began with a text message: an unpaid toll notice with a link to pay. The linked page opened with a request for the recipient's national ID number and license plate — details that appear routine for a toll payment and serve to personalize the rest of the flow for the attacker.

  2. Step 2: A Charge Small Enough to Ignore

    The next screen displayed a modest payment amount, calibrated to be small enough that most recipients would not pause to question it. Low-value, plausible charges are a deliberate design choice in this kind of campaign — they reduce hesitation at exactly the point where a larger, implausible amount would prompt scrutiny.

  3. Step 3: The Actual Objective

    Having established trust with two low-friction steps, the flow then asked for full credit card details, national ID, and phone number — the data that represents the actual payoff for the attackers, collected under the cover of a transaction the victim believes they initiated.

  4. Step 4: Two-Factor Authentication, Captured in Real Time

    The final step requested a one-time code, typically delivered by SMS. The kit relayed that code to the attacker's own session in real time, allowing them to authenticate a transaction as it happened rather than after the fact. Once the code was submitted, the victim was redirected to the genuine Kvish 6 site — a detail that reinforces the appearance that nothing went wrong.

  5. Why the Campaign Was Effective

    Three design choices carried the campaign: a believable, low-value charge that discouraged scrutiny; a flow that felt localized and specific to a real, familiar service; and real-time interception of the two-factor code, which meant the attackers could complete a transaction the moment the victim entered it rather than relying on a stolen credential to be used later. Two-factor authentication is generally an effective control, but a relay attack that captures the code as it is entered defeats it just as surely as if it were never enabled.

  6. Detection and Response

    The campaign was identified and blocked for protected users through real-time analysis of the link at the moment it was opened, and the case was coordinated with national CERT teams to take down the underlying infrastructure. SMS-delivered lures impersonating routine services — toll notices, delivery updates, account alerts — remain one of the most consistent phishing patterns Factor's research team tracks, precisely because they arrive on mobile, outside the reach of most enterprise or desktop security tools.

Toll road phishing campaign concept