The Federal Bureau of Investigation is telling smartphone owners across the country to delete a specific kind of text message before it costs them money. The messages claim the recipient owes an unpaid highway or bridge toll and demand quick payment through a link, a setup investigators say exists purely to harvest card numbers and personal information. The bureau’s cybercrime arm has been fielding a steady stream of complaints about the scheme for well over a year, and renewed warnings suggest the campaign has not slowed down.
How the Fake Toll Bill Text Is Built
The messages typically open with a variation on the same line: a toll payment is overdue and must be settled immediately to avoid a late fee, a suspended vehicle registration, or a referral to a collection agency. A shortened link sits beneath the warning, pointing to a page designed to resemble a real toll authority’s payment portal. Anyone who taps through is asked to enter a card number, an expiration date, and often a name and billing address before the page ever specifies which toll road, bridge, or tunnel supposedly generated the charge in the first place.
Researchers who track the campaign describe it as a form of SMS phishing, or smishing, that exploits how quickly people react to a text message compared with an email that might sit unread in a spam folder for days. The urgency built into the wording, paired with a web address that looks close enough to a real toll agency’s domain, is enough to get a share of recipients typing in payment details before they stop to consider whether they have driven on a toll road recently at all.
What the Internet Crime Complaint Center Has Logged
The FBI’s Internet Crime Complaint Center, known as IC3, first flagged this exact pattern in a public advisory describing more than 2,000 complaints tied to fraudulent texts impersonating toll collection services in several states. Complainants described nearly identical wording across the messages, with only the toll agency’s name and the return phone number changing from state to state, a detail investigators pointed to as evidence that a single template was being reused at scale rather than written fresh for each target. That advisory has continued to draw new reports well after it was first issued, and the bureau’s more recent guidance, detailed by Newsweek, indicates the people running the scheme have kept it active rather than retiring it once it drew attention.
The Toll Agencies and States Being Targeted
Complaints have referenced toll systems on the East Coast, in Texas, and in California, where messages have spoofed the state’s FasTrak electronic toll program. The impersonation is rarely exact, since the people sending the texts have no way of knowing which toll system a given phone number’s owner actually uses, so the wording stays generic enough to sound plausible to a wide range of recipients no matter where they live. That scattershot approach, blasting the same basic message to phone numbers regardless of location, is part of why the scheme spread nationwide instead of staying confined to drivers in a single state or region.
Investigators have also noted that the messages rarely name a specific toll gantry, exit, or date of travel, relying instead on vague language about “a recent trip” or “an outstanding balance” that could plausibly apply to almost anyone who has driven on a highway in the past few months. That vagueness is deliberate: a text naming a specific bridge or route the recipient never used would immediately break the illusion, while a generic claim leaves enough ambiguity for a nervous reader to assume it might be real.
What Happens After Someone Enters Payment Details
Once a card number is typed into the fake payment page, the information is often used or resold within hours, and victims frequently notice unfamiliar charges before they ever hear anything further about the toll balance the original text claimed they owed. Some versions of the scam go a step further, asking for a driver’s license number or date of birth under the guise of verifying identity before a refund or adjustment can supposedly be processed, handing the operators enough personal data to attempt additional fraud well beyond a single stolen card number.
Because the fake payment pages are built to look like legitimate checkout forms, many victims do not realize anything was wrong until a card statement shows an unfamiliar merchant or a cash advance they never authorized. Banks and card issuers can reverse some fraudulent charges after the fact, but recovering a stolen driver’s license number or date of birth is far harder, since that information can be reused for identity theft long after the original charge has been refunded.
Why the Scheme Keeps Reappearing After Coverage
Toll-payment smishing has drawn law enforcement warnings before, yet the volume of complaints has kept climbing rather than dropping off, which security researchers attribute to how cheap the scheme is to run. A single template can be blasted to enormous batches of phone numbers with almost no cost beyond registering fresh web domains once older ones get flagged and blocked, and only a tiny fraction of recipients need to fall for it to make the effort profitable. That economics, more than any technical sophistication, is why the same basic toll-text script keeps resurfacing under new domains months after the first round of warnings.
The FBI’s Recommended Response
Investigators advise against clicking any link inside an unsolicited toll-payment text, no matter how official it looks. The recommended steps are to check an account balance directly through a toll agency’s own website or app, call the agency’s published customer service line rather than any number listed in the text, and delete the message once it has been confirmed as fraudulent. Anyone who already entered payment information is urged to contact their card issuer immediately and to file a report with IC3, which uses the volume and exact wording of incoming complaints to track how the scheme’s language and targets are shifting over time.
This article was produced with the assistance of AI and reviewed by Morning Overview editors.
More from Morning Overview
- The NSA is again telling phone owners to switch off one location setting
- A handful of car transmissions are so tough mechanics say they almost never fail
- A handful of SUVs keep hitting 300,000 miles, and they share one engine trait
- Supplements now rank as the fifth-leading cause of death from liver disease.