WARNING: HIGHWAY phishing campaign

Discussion in 'Trucking Electronics, Gadgets and Software Forum' started by CousinVinny, Jan 17, 2025.

  1. CousinVinny

    CousinVinny Medium Load Member

    Joined:
    Jan 26, 2015
    Messages:
    615
    Thanks Received:
    1,774
    Location:
    New Jersey
    0
    I recently was made aware of a new phishing campaign masquerading as a HIGHWAY onboarding request. The phishing campaign appears to have begun some time in December and is ramping up with recent additional domain registrations. I suspect there may be a lot of potential victims out there who might let their guard down since HIGHWAY started the practice of demanding ELD access and the required credentials. I am posting this to hopefully prevent those of you here from becoming a victim.

    I have attached screenshots of two of these phishing emails, as well as two screenshots of the phishing website that is masquerading as an official HIGHWAY service.

    The following domains are related to this campaign:

    highwayon[dot]com
    • Registry Expiration: 2026-01-17 18:59:48 UTC
    • Updated: 2025-01-17 18:59:48 UTC
    • Created: 2025-01-17 18:59:48 UTC

    auth-highway[dot]com
    • Registry Expiration: 2026-01-16 13:28:47 UTC
    • Updated: 2025-01-16 13:30:31 UTC
    • Created: 2025-01-16 13:28:47 UTC

    connect-secured[dot]com
    • Registry Expiration: 2025-12-19 13:28:55 UTC
    • Updated: 2025-01-04 03:31:12 UTC
    • Created: 2024-12-19 13:28:55 UTC

    onboardstatus[dot]com

    • Registry Expiration: 2025-12-23 21:09:04 UTC
    • Updated: 2025-01-01 01:58:45 UTC
    • Created: 2024-12-23 21:09:04 UTC
    Here are samples of what these fraudulent emails look like:

    hwphish2.png

    hwphish1.png

    Here are samples of what one of the actual phishing websites look like.

    Take note of the "L" in the spelling of "highway". This has been observed in two of the subdomains taking part in this campaign.

    IMG_7815.jpg


    IMG_7816.jpg

    If you have fallen victim to one of these, I STRONGLY suggest that you immediately update the login credentials for every online service you use.
     
    MACK E-6, D.Tibbitt, 86scotty and 7 others Thank this.
  2. Meonthenet

    Meonthenet Bobtail Member

    Joined:
    May 9, 2019
    Messages:
    29
    Thanks Received:
    41
    0
    HIGHWAY is a phishing campaign.
    I tell every broker that gets in bed with Highway; Sorry I won't do Highway. Highway isn't selling me. I wish everyone would.
     
    Not Right Thanks this.
  3. 86scotty

    86scotty Road Train Member

    Joined:
    Aug 27, 2017
    Messages:
    4,736
    Thanks Received:
    13,007
    Location:
    Appalachia
    0
    Thanks for posting this Vinny. That will trip lots of people up.