ScamsPhishing & quishingAnatomy of a scam: the "unpaid toll" text, dissected word by word
Elevated

Anatomy of a scam: the "unpaid toll" text, dissected word by word

A text says you owe $12.51 in tolls and face a $50 late fee unless you pay now. It is the most common scam text in America. We pull one apart phrase by phrase — and show the one move that beats every version of it.

Sources checked:FBI IC3FCC

This is the second in our series taking a single scam apart line by line. Our subject is the most-reported scam text in the country: the unpaid-toll smishing message. Since early March 2024, the FBI’s Internet Crime Complaint Center (IC3) logged thousands of complaints about it, and it has only spread since. The whole con fits in two sentences on your lock screen — which is exactly why dissecting it is worth doing.

Here’s a representative example. The toll brand is invented; real services like E-ZPass, FasTrak, and I-PASS are impersonated by these texts, and those companies have nothing to do with them.

StateToll Notice: Dear customer, our records show an unpaid toll balance of $12.51. To avoid a late fee of $50.00, please settle within 12 hours: statetoll-paypoint[.]com/us

Four short lines. Five separate hooks. Let’s mark each one.

”Dear customer” — the tell hiding in plain sight

A real toll account knows your name. The generic greeting is the first crack: the FCC lists “generic greetings such as ‘Dear Customer’” among the red flags, because the sender is blasting the same text to thousands of numbers at once and has no idea who you are. If a company that supposedly has your account can’t address you by name, it doesn’t have your account.

”$12.51” — small on purpose

The amount is the cleverest part. It’s tiny, and it’s oddly precise — not “$12” but “$12.51” — which reads as a real system-generated charge. The FBI found the amount was “commonly $12.51” across complaints. A small, specific number does two things at once: it’s too trivial to bother disputing, and it’s specific enough to feel legitimate. Your guard never rises, because the stakes feel like pocket change.

”late fee of $50.00” — the lever

Here’s the turn. The $12.51 lowers your guard; the $50 fine raises the cost of waiting. Suddenly not acting feels expensive. This is the engine of every smishing text — manufactured urgency. The FBI defines smishing as “a social engineering attack using fake text messages to trick people into… sharing sensitive information, or sending money.” The deadline (“within 12 hours”) exists for one reason: to get you to click before you check.

”statetoll-paypoint[.]com” — the look-alike

The link is the payload. It’s built to “impersonate the state’s toll service name” (IC3), but it’s a slightly-off address that leads to a phishing page designed to harvest your card number and personal details. Tapping it is the entire attack — everything before it just exists to get your thumb to that link.

This is the exit, and it’s the same for every version: do not tap the link. Not to check it, not to “see what it says”. The link is the scam.

How to spot it

The tells are in the box below, but the pattern beneath every variant is identical: a small believable charge + a bigger threatened fee + a tight deadline + a look-alike link. Swap “toll” for “package”, “bank”, or “USPS” and it’s the same machine. Recognize the machine and you don’t need to recognize each new paint job.

What to do instead

You don’t need to buy anything to beat this — the free move comes first (see the defense box). The habit is Go Direct: never act on the link in a message; if you want to check a real balance, open your toll account yourself by typing the official address or using the app you already have. Delete the text, and don’t reply — even “STOP” confirms your number is live. The package-delivery cousin of this text is dissected in the fake-delivery smishing scam, and the QR-code version in quishing. For more, see our defense moves and the 60-second quiz.

Warning signs
  • A text claims you owe a small, oddly specific toll (often around $12.51) and threatens a much larger late fee (often $50) unless you pay right now.
  • It carries a link that looks like an official toll service but is a slightly-off look-alike address.
  • It greets you generically ("Dear customer") and pushes urgency — suspension, a deadline, a fine.
Defense move — Go Direct
  • Never tap the link in a toll, delivery, or "account problem" text — the link is the whole attack.
  • Check any real toll balance by going to your toll account yourself: type the official address or use the app you already have.
  • Don't reply at all — not even "STOP" or "N". Any response tells the scammer your number is live.
  • Delete it, and forward unwanted spam texts to 7726 (SPAM). If you already entered card details, call your bank and ask for a new card.
Editor's note

What makes the toll text so effective is how small and plausible it is. It's not a Nigerian prince — it's $12.51, an amount so trivial and so specific that paying feels easier than thinking about it. That's the design: keep the number tiny so your guard never goes up, and bolt on a $50 late fee so you act before you check. The instant I see any 'you owe a small amount, pay via this link now' text, I don't evaluate it — I delete it and, if I'm unsure, open the real app myself. The link in the message is never the way in.

Frequently asked

How do I know I don't actually owe a toll?

You don't have to figure that out from the text — and you shouldn't try. Ignore the message entirely and check your balance by going directly to your toll service's real website or app, or its customer-service number. The FBI's advice is exactly this: verify "from the state's legitimate website" and delete the text. If you genuinely owe something, you'll see it on the real account.

The link looked like my real toll company. Could it be genuine?

A familiar-looking name proves nothing. The FBI notes the link is "created to impersonate the state's toll service name", and the FCC warns the address only appears official while leading to a phishing site. Scammers impersonate real services like E-ZPass, FasTrak, and I-PASS — those companies are victims of the impersonation, not the senders. The look-alike link is the trap.

I clicked and entered my card. What now?

Act fast. Contact your bank or card issuer, report potential fraud, and ask for a new card number. Watch your statements for charges you don't recognize and dispute them. Then delete the text and report it to the FBI's IC3 at ic3.gov, including the sender's number and the website in the message.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›