Fast Lane, Fast Pain: A Toll-Road Phishing Kit That Bypassed Two-Factor Authentication
- Home
- Threat Intelligence
- Smishing
By Guy Ushomirsky, Factor Security Research · 18 Jul 2026
Factor's research team recently examined a phishing campaign built around one of the most routine notifications a driver can receive: an unpaid toll. The campaign impersonated Kvish 6, Israel's major toll highway, and combined a small, believable charge with a real-time two-factor relay — a pairing that let attackers complete fraudulent transactions before most victims realized anything was wrong.
-
Step 1: The Entry Point
The campaign began with a text message: an unpaid toll notice with a link to pay. The linked page opened with a request for the recipient's national ID number and license plate — details that appear routine for a toll payment and serve to personalize the rest of the flow for the attacker.
-
Step 2: A Charge Small Enough to Ignore
The next screen displayed a modest payment amount, calibrated to be small enough that most recipients would not pause to question it. Low-value, plausible charges are a deliberate design choice in this kind of campaign — they reduce hesitation at exactly the point where a larger, implausible amount would prompt scrutiny.
-
Step 3: The Actual Objective
Having established trust with two low-friction steps, the flow then asked for full credit card details, national ID, and phone number — the data that represents the actual payoff for the attackers, collected under the cover of a transaction the victim believes they initiated.
-
Step 4: Two-Factor Authentication, Captured in Real Time
The final step requested a one-time code, typically delivered by SMS. The kit relayed that code to the attacker's own session in real time, allowing them to authenticate a transaction as it happened rather than after the fact. Once the code was submitted, the victim was redirected to the genuine Kvish 6 site — a detail that reinforces the appearance that nothing went wrong.
-
Why the Campaign Was Effective
Three design choices carried the campaign: a believable, low-value charge that discouraged scrutiny; a flow that felt localized and specific to a real, familiar service; and real-time interception of the two-factor code, which meant the attackers could complete a transaction the moment the victim entered it rather than relying on a stolen credential to be used later. Two-factor authentication is generally an effective control, but a relay attack that captures the code as it is entered defeats it just as surely as if it were never enabled.
-
Detection and Response
The campaign was identified and blocked for protected users through real-time analysis of the link at the moment it was opened, and the case was coordinated with national CERT teams to take down the underlying infrastructure. SMS-delivered lures impersonating routine services — toll notices, delivery updates, account alerts — remain one of the most consistent phishing patterns Factor's research team tracks, precisely because they arrive on mobile, outside the reach of most enterprise or desktop security tools.

