A text claiming that a small unpaid toll could lead to late fees, suspended driving privileges or legal action may look official, but federal agencies warn that it is probably part of a widespread phishing campaign.
The messages impersonate agencies such as E-ZPass, FasTrak and state toll authorities. They usually demand immediate payment through a link that leads to a convincing copy of a legitimate toll website. Cybersecurity researchers identified more than 10,000 domains registered for campaigns impersonating toll and package-delivery services across multiple U.S. states and Ontario, Canada.
The scam has become so widespread that the Federal Trade Commission issued a dedicated warning, advising consumers not to click the link or respond to the message.
How the Unpaid Toll Text Scam Works
The message usually claims that the recipient has a small outstanding toll balance. The amount may be only a few dollars, making it seem easier to pay than investigate.
Scammers add urgency by warning that the balance will increase, the vehicle’s registration may be suspended or the recipient could face additional penalties. The goal is to make the person react before checking whether the claim is genuine.
The embedded link opens a website designed to resemble the real toll authority’s payment portal. It may display the agency’s name, logo, colors and familiar payment fields.
The fake page then asks for information such as the driver’s name, address, phone number, license-plate details and credit-card information. Some versions may also request a driver’s licence number or account credentials.
The FBI’s Internet Crime Complaint Center began warning about toll-related “smishing” campaigns after receiving more than 2,000 complaints starting in March 2024. The FBI noted that nearly identical messages were appearing in different states, suggesting that the campaign was moving from one toll system to another.
More Than 10,000 Fake Domains Supported the Campaign
The scale of the operation became clearer when cybersecurity researchers investigated the infrastructure behind the messages.
Palo Alto Networks reported that a threat actor had registered more than 10,000 domains associated with toll-payment and package-delivery scams. The fraudulent pages impersonated services in at least 10 U.S. states and the Canadian province of Ontario.
Registering thousands of domains helps criminals keep the campaign operating even when phone companies, browsers or security providers block individual links. Once one fake site is reported and removed, another domain can replace it.
The addresses are often designed to look believable at a quick glance. A criminal may combine a recognizable toll-service name with words such as “invoice,” “payment,” “notice” or “expresslane.”
However, the real domain may contain an unfamiliar ending, extra letters, misplaced punctuation or a name that does not match the toll authority’s official web address.
A larger academic analysis later documented tens of thousands of confirmed toll-scam domains, finding registration patterns consistent with automated and coordinated campaigns. Researchers observed that many were created in concentrated bursts and relied heavily on a small number of less common domain extensions and registration providers.
Why the Messages Can Look Convincing
Toll scams are effective because they use a situation that feels plausible.
A person may have recently taken a road trip, driven a rental car or passed through an electronic toll point without noticing it. Even someone who does not regularly use toll roads may wonder whether a family member drove the vehicle.
The requested payment is also often deliberately small. A demand for $4.95 or $11.75 may not trigger the same suspicion as a request for hundreds of dollars.
Scammers rely on the possibility that recipients will decide the amount is not worth investigating. Once the fake site captures the card information, however, the potential loss can extend far beyond the original payment.
The criminals may make unauthorized purchases, attempt additional charges or sell the stolen information. Personal details collected through the form can also support future identity-theft attempts.
In 2024, consumers reported losing $470 million to scams that began with text messages, according to FTC figures cited by The Washington Post. That was approximately five times the amount reported in 2020, although many incidents are never officially reported.
Some Messages Ask Recipients to Reply With “Y”
Certain versions of the scam include a strange instruction telling iPhone users to reply with “Y,” close the message and reopen it before clicking the link.
This tactic is designed to get around security restrictions that may prevent links from unknown senders from becoming immediately clickable. Once the recipient responds, the device may treat the conversation differently.
Replying creates another problem because it confirms that the phone number is active and monitored. The number could then receive more scam messages or be included in lists shared with other fraud operations.
The Federal Communications Commission’s toll-scam warning advises consumers not to respond, click links or provide information through unsolicited toll-payment messages.
Even replying with “STOP” may be unwise when the sender is clearly fraudulent. The message is not coming from a legitimate marketing service that is required to honor an opt-out request.
How to Verify Whether a Toll Is Real
A person concerned about a genuine unpaid toll should avoid every link and phone number included in the text.
Instead, the driver should open a browser independently and type the toll authority’s known official address or use a verified mobile application already installed on the device.
The account can then be checked directly for outstanding charges. Another option is to call the customer-service number printed on an official statement or found through the agency’s verified website.
Some regions do send legitimate notifications, which is why the presence of a text alone may not prove fraud. The important question is whether the recipient can verify the balance through an independently located official channel.
Many agencies have clearly warned that they do not use unsolicited texts to demand immediate payment. For example, Utah officials stated that the state transportation department does not send texts or make phone calls to collect toll charges.
Regional systems also publish active scam alerts. California’s Toll Roads, for example, maintains an official phishing warning telling drivers to disregard fraudulent messages claiming unpaid tolls or violations.
Warning Signs That a Message Is Fraudulent
An unexpected payment request is the first warning sign, especially when it threatens severe consequences over a very small balance.
A suspicious domain is another strong indicator. The link may contain the toll agency’s name but use an unrelated web address or unusual domain ending.
Poor grammar can reveal some scams, but professional-looking language does not prove legitimacy. Criminal groups increasingly use polished templates that reproduce official branding and payment-page designs.
Pressure to act within hours is also suspicious. Genuine agencies typically provide formal notices and a defined dispute or payment process rather than threatening immediate arrest, prosecution or licence suspension through an unexpected text.
The message may not include the recipient’s name, vehicle information or a specific toll location. However, even personalized information cannot confirm authenticity because scammers may obtain names, addresses or vehicle details from data breaches and commercial records.
What to Do After Receiving the Text
The safest response is to avoid interacting with the message.
The recipient should take a screenshot when documentation may be useful, report it as junk through the phone’s messaging application and delete it. The text can also be forwarded to 7726, which spells SPAM, to help the mobile carrier investigate the sender.
The incident can be reported through the FTC’s fraud-reporting system and the FBI’s Internet Crime Complaint Center. These reports help investigators identify repeated wording, phone numbers, domains and payment infrastructure.
The suspicious website should not be opened merely to investigate it. Visiting the page may expose the device to tracking or create an opportunity for accidental interaction.
Responding to mock or insult the scammer is also risky. Cybersecurity experts warn that engagement confirms the number is active and may reveal details about the recipient’s location, habits or availability.
What to Do After Clicking the Link
Opening the website without entering information does not always mean the device or account has been compromised, but the person should still close the page and avoid downloading anything.
The browser’s history and downloaded files should be reviewed, and the device’s operating system and security software should be updated.
Anyone who entered payment-card information should contact the card issuer immediately using the number printed on the card. The issuer may cancel the card, block transactions and issue a replacement.
Recent account activity should be checked for unfamiliar charges. Fraud alerts can also help identify attempted use before a major loss occurs.
A person who provided a Social Security number or other sensitive identity information should review the Federal Trade Commission’s IdentityTheft.gov recovery guidance and consider placing a fraud alert or credit freeze.
Passwords entered on the fake page should be changed immediately anywhere they were reused. Multi-factor authentication should also be enabled where available.
The Scam Works Because It Creates Uncertainty
The unpaid-toll message does not need to convince every recipient. It only needs to reach enough people who recently used a toll road, share a vehicle or are worried about missing a legitimate notice.
The network of more than 10,000 fake domains shows that this is not an isolated prank sent by a single individual. It is a coordinated form of digital fraud built to imitate trusted transportation agencies and process victims at scale.
A genuine toll charge can be verified without using an unsolicited link. That simple habit removes most of the scam’s power.
When a text demands immediate payment for an unfamiliar toll, the safest assumption is that the message is fraudulent until the balance has been confirmed through the authority’s official website or customer-service channel.