Connect with us

Technology

Massive DMV phishing scam tricks drivers with fake texts

Published

on

Massive DMV phishing scam tricks drivers with fake texts

NEWYou can now listen to Fox News articles!

If you’ve received a text message claiming to be from your state’s Department of Motor Vehicles (DMV) and threatening you with fines or penalties unless you pay up, you’re not alone. A new wave of scam texts is sweeping across the country, targeting drivers in states like Connecticut, Pennsylvania, Georgia, Florida, New York, California, Illinois, New Jersey, Virginia, Colorado, Vermont, Texas, North Carolina and even Washington, D.C.

These messages look official and urgent, warning you about supposed unpaid tickets or tolls and demanding immediate payment. But don’t be fooled, as these texts are sophisticated scams designed to steal your personal information or money. 

The scammers are getting better at making their messages look real, so it can be tricky to spot the fraud. But with a few simple tips, you can learn how to recognize these scams and protect yourself before you click or respond.

Join The FREE CyberGuy Report: Get my expert tech tips, critical security alerts, and exclusive deals — plus instant access to my free Ultimate Scam Survival Guide when you sign up!

Advertisement

DMV scam text. (Kurt “CyberGuy” Knutsson)

How the DMV scam text message works

These scam messages vary slightly depending on the state you’re in, but they’re generally structured in the same way. The text threatens consequences, such as credit score damage, revoked driving privileges, suspended vehicle registration or increased toll fees, if you do not pay the bill you have supposedly incurred. To make the message appear legit, the scammers often include a date for penalties to begin, a fake administrative code and a link that appears to be an official DMV website.

FBI WARNS OF SCAM TARGETING VICTIMS WITH FAKE HOSPITALS AND POLICE

Pro tip: If you’re instructed to copy the link into your browser rather than clicking it directly, it’s a scam.

A person receiving a scam text message on their phone. (Kurt “CyberGuy” Knutsson)

Advertisement

DON’T CLICK THAT LINK! HOW TO SPOT AND PREVENT PHISHING ATTACKS IN YOUR INBOX

Why DMV text scams are so convincing

The scam relies on two key elements to be effective: fear and a sense of urgency. These are two powerful psychological motivators that can send you into a panic since your driving privileges are at risk, or you’re facing financial consequences. The aim is to get you to act hastily without pausing to verify the source. The messages also mimic legitimate government communications by including familiar terms, official-sounding codes and web addresses that appear authentic. Here is an example of what the text might look like:

DMV scam text. (Kurt “CyberGuy” Knutsson)

NEW PHISHING SCAM OUTSMARTS SECURITY CODES TO STEAL YOUR INFO

States known to have issued warnings about DMV scam texts (as of June 2025):

  • Connecticut
  • Pennsylvania
  • Georgia
  • Florida
  • New York
  • California
  • Illinois
  • New Jersey
  • Virginia
  • Colorado
  • Vermont
  • Texas
  • North Carolina
  • Washington, D.C.

Reports are surfacing across the U.S., and the list of affected states is likely to continue growing as more residents come forward.

How to spot and avoid DMV text message scams

If you receive a suspicious text message claiming to be from your state’s DMV and demanding payment or personal information, follow these steps to protect yourself:

Advertisement

1. Be skeptical of any message creating urgency or panic: Scammers rely on fear and urgency to trick you into acting without thinking. If a message pressures you to act immediately, that’s a major red flag.

2. Check for obvious red flags: Look for signs like strange sender addresses, awkward language, misspellings or links that don’t match your state’s official DMV website.

3. Do not click any links or reply, and use strong antivirus software: Legitimate DMVs will not ask for payments, personal details or sensitive information via unsolicited text messages. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices. 

4. Verify directly with your DMV: If you’re concerned the message might be real, contact your state’s DMV using the official website or a trusted phone number. Never use the contact information provided in the suspicious text.

5. Consider a Personal Data Removal Service: Your personal information is widely available online, which can make you a bigger target for these types of scams, therefore you might look into a personal data removal service. These services work by submitting opt-out requests to data brokers that collect and sell your information, helping to reduce your digital footprint and making it harder for scammers to find your contact details. 

Advertisement

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap — and neither is your privacy.  These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet.  By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you. Check out my top picks for data removal services here.

6. Delete the message immediately and block the sender: Removing the text helps prevent accidental clicks and reduces the risk of falling for the scam later. Also, be sure to block phone numbers and texts that send spam or scam messages, reducing future risk.

7. Register your number with the National Do Not Call Registry: While this won’t stop all scams, it can help reduce unwanted communications.

8. Don’t provide any personal or financial information: Never share your Social Security number, driver’s license number, banking information, or passwords in response to an unsolicited text.

Advertisement

9. If you clicked the link or gave out information, act quickly: If you accidentally entered personal or financial information, contact your bank, credit card provider or local law enforcement right away to minimize potential damage.

10. Keep your phone’s security features updated: Ensure your device’s operating system and security software are current to help block known scam numbers and malicious links.

11. Report the scam: Forward the message to 7726 (SPAM) to alert your mobile provider and help block similar messages in the future. Mark the message as junk or spam within your messaging app, if possible. File a complaint with the Federal Trade Commission at reportfraud.ftc.gov or the FBI’s Internet Crime Complaint Center at ic3.gov.

DON’T GET CAUGHT IN THE “APPLE ID SUSPENDED” PHISHING SCAM

Kurt’s key takeaways

Scam texts pretending to be from the DMV are getting more convincing, but you don’t have to be their next victim. Staying skeptical of urgent messages, double-checking anything that seems off and never clicking suspicious links can go a long way in protecting your personal information. Remember, the real DMV will never pressure you for payment or sensitive details over text. By staying alert, you can help prevent these scams and keep your personal information and money secure.

Advertisement

Should tech companies and telecom providers be doing more to protect you from scam texts, or does the responsibility ultimately fall on you to keep your digital life safe? Let us know by writing to us aCyberguy.com/Contact

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most-asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.  

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Creators and communities everywhere take a stand against ICE

Published

on

Creators and communities everywhere take a stand against ICE

It’s not surprising when the guy who’s been yelling about the horrors of late-stage capitalism on Instagram for the last five years turns his ire towards ICE. But something different has been happening over the week or so, following the most recent shootings of civilians by federal agents — even accounts that stay laser focused on golfing, chopping wood, and playing cats like bongos have started to speak out.

The tenor on social media and Reddit took an even sharper turn yesterday, following the killing of Alex Pretti by ICE. Even the moderator of normally politics-free r/catbongos (a subreddit “Where gentlemen, gentlewomen, and gentlethems of quality gather to watch cats being played like bongos”) spokeout in a post where they declared that “If you still support Trump/ICE even slightly, you’re not welcome in this sub.”

That quilters on Instagram or a Facebook account dedicated to New England gravestones have decided enough, is enough, is one thing. But, judging from the comments, it seems like the government has lost the support of r/military as well. The subreddit is filled with angry posters decrying that “this is exactly what tyranny looks like” and sharing memes mocking Secretary of Defense Pete Hegseth. One poster claiming to be an active member of the U.S. Army who has served for 21 years said, “these guys are against all we stand for as Americans. Modern day brownshirts.”

All across Reddit, subs are being inundated with anti-ICE posts. From r/Fauxmoi, to r/NFCNorthMemeWar, and r/DungeonCrawlerCarl. There’s even been some limited signs of revolt among the members of r/conservative, some of whom have taken issue with Kristi Noem’s description of Alexi Pretti as a “domestic terrorist,” and suggested that she should “just be quiet for a while.” And arguments have broken out among community members over perceived hypocrisy around the Second Amendment.

Some big names have also joined the chorus, including Joe Santagato of The Basement Yard podcast, who posted that what was occurring on the streets of Minneapolis was “legit horrifying.” And when someone told him to “Stay out of politics,” and “get back to spitting water out of your mouth and de-jumbling words with your idiot friends.” He shot back, “De-jumble this: ksuc ym slalb.”

Advertisement

Canadian wrestlers and social media influencers Chris and Patrick Vörös have spoken out previously about their anti-ICE views, but took the opportunity to remind people of the only two ICE agents they support. Educational YouTube channel Primer also took to X to say this is no longer about politics, but about the “fabric of society.”

Canadian musician bbno$ decided to break his silence, even if it risked his visa and his current U.S. tour, to throw his support behind the abolish ICE movement. Even Thoren Bradley, the Axe Man himself, whose whole schtick is being a ripped rural dude who chops wood, has decided to call out the hypocrisy of the Christian conservatives to his 10.7 million followers.

That creators like Hank Green are speaking out is no surprise. But when fitness influencers, duck-painting TikTokers, football subreddits, and even Second Amendment rights activists have finally broken their silence, it seems like the government has lost control of the narrative. No matter how hard they try to spin it.

Let us know in the comments what other creators and communities have begun to speakout in the comments.

Updated January 25th: Added additional information about Reddit communities.

Advertisement
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

Continue Reading

Technology

Google Fast Pair flaw lets hackers hijack headphones

Published

on

Google Fast Pair flaw lets hackers hijack headphones

NEWYou can now listen to Fox News articles!

Google designed Fast Pair to make Bluetooth connections fast and effortless. One tap replaces menus, codes and manual pairing. That convenience now comes with serious risk. Security researchers at KU Leuven uncovered flaws in Google’s Fast Pair protocol that allows silent device takeovers. They named the attack method WhisperPair. An attacker nearby can connect to headphones, earbuds or speakers without the owner knowing. In some cases, the attacker can also track the user’s location. Even more concerning, victims do not need to use Android or own any Google products. iPhone users are also affected.

Sign up for my FREE CyberGuy Report

Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

APPLE WARNS MILLIONS OF IPHONES ARE EXPOSED TO ATTACK

Advertisement

Fast Pair makes connecting Bluetooth headphones quick, but researchers found that some devices accept new pairings without proper authorization.       (Kurt “CyberGuy” Knutsson)

What WhisperPair is and how it hijacks Bluetooth devices

Fast Pair works by broadcasting a device’s identity to nearby phones and computers. That shortcut speeds up pairing. Researchers found that many devices ignore a key rule. They still accept new pairings while already connected. That opens the door to abuse.

Within Bluetooth range, an attacker can silently pair with a device in about 10 to 15 seconds. Once connected, they can interrupt calls, inject audio or activate microphones. The attack does not require specialized hardware and can be carried out using a standard phone, laptop, or low-cost device like a Raspberry Pi. According to the researchers, the attacker effectively becomes the device owner.

Audio brands affected by the Fast Pair vulnerability

The researchers tested 17 Fast Pair compatible devices from major brands, including Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech and Google. Most of these products passed Google certification testing. That detail raises uncomfortable questions about how security checks are performed.

How headphones can become tracking devices

Some affected models create an even bigger privacy issue. Certain Google and Sony devices integrate with Find Hub, which uses nearby devices to estimate location. If a headset has never been linked to a Google account, an attacker can claim it first. That allows continuous tracking of the user’s movements. If the victim later receives a tracking alert, it may appear to reference their own device. That makes the warning easy to dismiss as an error.

Advertisement

GOOGLE NEST STILL SENDS DATA AFTER REMOTE CONTROL CUTOFF, RESEARCHER FINDS

Attacker’s dashboard with location from the Find Hub network. (KU Leuven)

Why many Fast Pair devices may stay vulnerable

There is another problem most users never consider. Headphones and speakers require firmware updates. Those updates usually arrive through brand-specific apps that many people never install. If you never download the app, you never see the update. That means vulnerable devices could remain exposed for months or even years.

The only way to fix this vulnerability is by installing a software update issued by the device manufacturer. While many companies have released patches, updates may not yet be available for every affected model. Users should check directly with the manufacturer to confirm whether a security update exists for their specific device.

Why convenience keeps creating security gaps

Bluetooth itself was not the problem. The flaw lives in the convenience layer built on top of it. Fast Pair prioritized speed over strict ownership enforcement. Researchers argue that pairing should require cryptographic proof of ownership. Without it, convenience features become attack surfaces. Security and ease of use do not have to conflict. But they must be designed together.

Advertisement

Google responds to the Fast Pair WhisperPair security flaws

Google says it has been working with researchers to address the WhisperPair vulnerabilities and began sending recommended patches to headphone manufacturers in early September. Google also confirmed that its own Pixel headphones are now patched.

In a statement to CyberGuy, a Google spokesperson said, “We appreciate collaborating with security researchers through our Vulnerability Rewards Program, which helps keep our users safe. We worked with these researchers to fix these vulnerabilities, and we have not seen evidence of any exploitation outside of this report’s lab setting. As a best security practice, we recommend users check their headphones for the latest firmware updates. We are constantly evaluating and enhancing Fast Pair and Find Hub security.”

Google says the core issue stemmed from some accessory makers not fully following the Fast Pair specification. That specification requires accessories to accept pairing requests only when a user has intentionally placed the device into pairing mode. According to Google, failures to enforce that rule contributed to the audio and microphone risks identified by the researchers.

To reduce the risk going forward, Google says it updated its Fast Pair Validator and certification requirements to explicitly test whether devices properly enforce pairing mode checks. Google also says it provided accessory partners with fixes intended to fully resolve all related issues once applied.

On the location tracking side, Google says it rolled out a server-side fix that prevents accessories from being silently enrolled into the Find Hub network if they have never been paired with an Android device. According to the company, this change addresses the Find Hub tracking risk in that specific scenario across all devices, including Google’s own accessories.

Advertisement

Researchers, however, have raised questions about how quickly patches reach users and how much visibility Google has into real-world abuse that does not involve Google hardware. They also argue that weaknesses in certification allowed flawed implementations to reach the market at scale, suggesting broader systemic issues.

For now, both Google and the researchers agree on one key point. Users must install manufacturer firmware updates to be protected, and availability may vary by device and brand.

SMART HOME HACKING FEARS: WHAT’S REAL AND WHAT’S HYPE

Unwanted tracking notification showing the victim’s own device. (KU Leuven)

How to reduce your risk right now

You cannot disable Fast Pair entirely, but you can lower your exposure.

Advertisement

1) Check if your device is affected

If you use a Bluetooth accessory that supports Google Fast Pair, including wireless earbuds, headphones or speakers, you may be affected. The researchers created a public lookup tool that lets you search for your specific device model and see whether it is vulnerable. Checking your device is a simple first step before deciding what actions to take. Visit whisperpair.eu/vulnerable-devices to see if your device is on the list.

2) Update your audio devices

Install the official app from your headphone or speaker manufacturer. Check for firmware updates and apply them promptly.

3) Avoid pairing in public places

Pair new devices in private spaces. Avoid pairing in airports, cafés or gyms where strangers are nearby.

4) Factory reset if something feels off

Unexpected audio interruptions, strange sounds or dropped connections are warning signs.  A factory reset can remove unauthorized pairings, but it does not fix the underlying vulnerability. A firmware update is still required.

5) Turn off Bluetooth when not needed

Bluetooth only needs to be on during active use. Turning off Bluetooth when not in use limits exposure, but it does not eliminate the underlying risk if the device remains unpatched.

Advertisement

6) Reset secondhand devices

Always factory reset used headphones or speakers before pairing them. This removes hidden links and account associations.

7) Take tracking alerts seriously

Investigate Find Hub or Apple tracking alerts, even if they appear to reference your own device.

8) Keep your phone updated

Install operating system updates promptly. Platform patches can block exploit paths even when accessories lag behind.

Kurt’s key takeaways

WhisperPair shows how small shortcuts can lead to large privacy failures. Headphones feel harmless. Yet, they contain microphones, radios and software that need care and updates. Ignoring them leaves a blind spot that attackers are happy to exploit. Staying secure now means paying attention to the devices you once took for granted.

Should companies be allowed to prioritize fast pairing over cryptographic proof of device ownership? Let us know by writing to us at Cyberguy.com

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 

Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter. 

Copyright 2026 CyberGuy.com.  All rights reserved.

Advertisement
Continue Reading

Technology

On the ground in Minneapolis after the killing of Alex Pretti

Published

on

On the ground in Minneapolis after the killing of Alex Pretti

Steven Garcia, as told to Gaby Del Valle:

I was in the middle of a frozen lake when I got the notification from the Minnesota Star Tribune that there had been a shooting. I was on assignment at a pond hockey event, and someone who was supposed to play later that evening said he probably wouldn’t be able to make it — they knew there would be protests and demonstrations happening.

I arrived a little over three hours later. Federal officers had already cleared the scene — the FBI had been there investigating — so the only law enforcement present were state and local officials: the Minneapolis Police Department, their SWAT team, the Hennepin County Sheriff’s Office, and the Minnesota State Patrol.

There were protesters at multiple intersections. People had blocked off the streets with trash cans and dumpsters, and there were mattresses on the ground. Protesters were heckling officers, but there were no physical altercations. Eventually law enforcement retreated by a block and started throwing tear gas. They drove their trucks over the mattresses as they left.

When those tear gas canisters go off, they pop and bang, kind of like a firework. Dozens of canisters were going off. Even initially, there were four, five, six canisters at a time that they were throwing. I had to duck in an alley for a little bit because it got through my mask. It’s not a fun experience, even in very small amounts. You have to keep your eyes closed. It burns your eyes, it burns your mouth. For some people, it causes nausea and burning on the skin. Another local reporter told me his neck was burning and he had to use a decon wipe.

Advertisement

I think because of George Floyd in 2020, people knew how to respond. Gregory Bovino, the head of the US Border Patrol who has been here the whole time, has said community members in Minneapolis are really prepared. A lot of people I’ve talked to have said, “I had my respirator ready from 2020,” and they just restocked on safety supplies, decon wipes, and first aid kits. Even if they weren’t immediately prepared, they could rapidly respond to these kinds of events. At all the events I’ve been to, people will set a table to hand out food and water and hand warmers. It was especially cold today — it wasn’t supposed to get above 0 degrees.

After the officers cleared the scene, everyone convened at the intersection of 26th and Nicolette, just a couple hundred feet from where Alex Pretti was shot. Some community members started a makeshift vigil for him at the location where he was killed. People were spelling his name out with pinecones and starting to leave flowers.

Continue Reading

Trending