That "Unpaid Toll" Text Is a Scam — Here's How to Tell in 10 Seconds
Getting an unpaid toll text? Learn how to spot fake E-ZPass, SunPass, FasTrak, and TxTag scam messages in seconds. Discover phishing red flags, fake toll links, and what to do if you already clicked.
NEWS
By Muhammad Ibraheem • Founder of Hackers Legacy • Cybersecurity Researcher & Privacy Analyst
8/9/20268 min read


"You owe $6.99 in unpaid tolls. Pay now to avoid additional fees." That's the entire trap. It works because it's boring enough to feel real.
Somewhere between running errands and sitting in traffic, your phone buzzes. A text, short and businesslike: "E-ZPass: Your account has an outstanding balance of $6.99. To avoid a $50 late fee, settle your balance at [link]."
For a split second, your stomach drops. Did you forget a toll? Is your registration about to get flagged? You genuinely can't remember the last time you checked your toll balance, and the amount is small enough to seem plausible, urgent enough to make you want to just deal with it right now.
That split second of doubt is the entire scam. And it's working on a scale that should genuinely alarm you.
According to the Federal Trade Commission, fake toll payment texts have become the fastest-growing form of government imposter fraud in the country, driving a 40% spike in government impersonation reports and contributing to $3.5 billion in total imposter scam losses in a single recent year. The FBI's Internet Crime Complaint Center has separately logged thousands of complaints about this exact scheme in a matter of weeks. If you've received one of these texts, you are nowhere close to alone — you're one of millions of Americans being targeted by an almost absurdly simple scheme that keeps working anyway.
Here's exactly how to spot it, in under ten seconds, every single time.
Why This Scam Works So Well
Credit where it's due — whoever engineered this scam understood human psychology better than most legitimate marketers do.
The amount is deliberately small. You'll typically see something like $4.15, $6.99, or $12.51 — never a suspiciously round number, never large enough to trigger real alarm. That's not random. It's calculated to feel too small to seriously scrutinize but too specific to dismiss as obviously fake. A vague "you owe money" is suspicious. "$6.99" feels like a real system generated it.
The urgency is precisely calibrated. Pay within 48 hours or face a $50 penalty. Not immediately, which would feel panicked and fake — just urgent enough that "I'll deal with it later" starts to feel risky.
It exploits genuine uncertainty. Most people genuinely don't track their toll balance closely. You might have driven through a toll lane weeks ago and honestly not be sure whether it was billed correctly. The scam is built entirely around that small, ordinary gap in your memory.
It's sent at massive scale for almost nothing. Scammers blast these texts to enormous lists without knowing who actually uses toll roads. They don't need a high success rate — they need a tiny fraction of millions of recipients to panic and click, and the economics work out enormously in their favor.


The 10-Second Check: Is This Text Real or Fake?
You don't need to be tech-savvy to catch this. You need to check exactly one thing: the domain in the link.
Every legitimate toll agency has one official website, and you should know it or be willing to look it up independently. A few real ones, for reference: E-ZPass operates through agency-specific sites (like ezpassny.com in New York), SunPass in Florida uses sunpass.com, TxTag in Texas uses txtag.org, and Bay Area FasTrak uses bayareafastrak.org.
Now look at what scam links actually contain. Real examples pulled from documented scam reports include domains like "ezpass-payment-center.com," "sunpass-tollpay.net," and "sunpass.com-8If5.sbs." Notice the pattern: they include the real toll agency's name to look convincing, but the actual domain — the part that matters — is something completely different. "sunpass.com-8If5.sbs" is not SunPass's website. The real domain is everything before the final dot-something at the end, and in that example, it's actually ".sbs," a domain ending scammers favor because it's cheap and rarely used by real companies.
If the link doesn't exactly match your toll agency's known official domain, it's fake. That's the entire check, and it takes less time than reading this paragraph.
Additional Red Flags to Confirm It's a Scam
Beyond the domain check, these signs should immediately raise suspicion:
You're asked to text back before clicking. Some versions instruct you to reply "Y" and then reopen the message to "activate" the link. This is a technique to bypass spam filtering on iPhones, which normally disable links from unknown senders until you respond. It's a strong technical tell that you're dealing with an automated scam operation, not a real toll agency.
Payment is requested through unusual methods. Toll agencies bill through your account, your credit card on file, or your mailed invoice. They do not request payment via gift cards, cryptocurrency, Venmo, or wire transfer. Any of these payment requests is close to a guaranteed sign of fraud.
The message arrives from a number that doesn't match your carrier's normal short codes, or from a phone number that looks like a random cell number rather than an official business line. Scammers also frequently spoof sender information to make it look more official than it is, so don't rely on this alone — but combined with other signs, it adds up.
You don't even use that toll road, or don't own a car registered in that state. Scammers send these blindly to enormous number lists without any idea who actually drives on the roads in question. If the message mentions a toll authority nowhere near where you live or drive, that alone should be a dead giveaway.


What to Do When You Get One of These Texts
The correct response takes less time than reading the scam text itself.
Do not click the link. Not to "just look," not out of curiosity. Even visiting a phishing page can expose your device to tracking or, in some versions, prompt downloads.
Check your actual account independently. If you have a toll account — E-ZPass, SunPass, FasTrak, or whichever applies to you — open your browser, type the official website address yourself (never through the text), and log in directly. If you genuinely owe something, it will show up there, with none of the manufactured urgency.
Report the text. Forward it to 7726 (which spells "SPAM" on your keypad) — this reports it directly to your mobile carrier as spam. Then file a report at ReportFraud.ftc.gov and consider also filing with the FBI's Internet Crime Complaint Center at IC3.gov. These reports feed directly into the pattern-tracking that helps regulators and carriers identify and block these campaigns faster.
Delete the message. Once reported, delete it so you're not tempted to revisit it later, especially if you're someone who tends to circle back to "deal with things eventually."
Tell someone who might be more vulnerable to it. Elderly relatives are frequently and specifically targeted by these scams, partly because they're statistically less likely to double-check a domain name and more likely to worry about legal or registration consequences. A quick heads-up to family members costs you nothing and might save them real money.
If You Already Clicked or Entered Information
If you're reading this because you already tapped the link and entered payment or personal details — don't panic, and don't waste time feeling embarrassed. This scam is specifically engineered to be convincing, and plenty of careful, smart people have fallen for it.
Contact your bank or card issuer immediately. Report the potential fraud and request a replacement card. The faster you act, the better your odds of preventing further unauthorized charges.
Change your password if you entered one, especially if you reused a password you use elsewhere. Update it everywhere that password appears, and enable two-factor authentication on those accounts going forward.
Monitor your credit reports and bank statements closely over the following weeks for any unfamiliar activity. Consider a fraud alert with the major credit bureaus if you provided more sensitive information like a driver's license number.
File the same reports mentioned above — ReportFraud.ftc.gov and the FBI's IC3 — even after the fact. Your report still helps build the picture investigators use to shut these campaigns down.
Frequently Asked Questions
How do I know if a toll text message is real or fake? Check the link's actual domain against your toll agency's known official website (like ezpassny.com, sunpass.com, or txtag.org). Scam links often include the real agency's name but route through a completely different domain, such as "sunpass.com-8If5.sbs." If it doesn't exactly match the official site, it's fake. Never click the link — instead, log into your account by typing the official website address yourself.
Which toll agencies are being impersonated in this scam? The FTC and FBI have identified E-ZPass, SunPass, FasTrak, TxTag, I-Pass, Georgia Peach Pass, and EZ Drive MA, among others, as commonly spoofed toll programs. Scammers send these texts broadly without knowing which recipients actually use toll roads or live in the relevant state.
What should I do if I already clicked the link and entered my information? Contact your bank or card issuer immediately to report potential fraud and request a new card. Change any password you entered, especially if reused elsewhere, and enable two-factor authentication. Monitor your bank and credit statements closely, and report the incident to the FTC at ReportFraud.ftc.gov and the FBI's IC3 at ic3.gov.
Do real toll agencies ever text you about unpaid balances? Toll agencies typically bill through your linked account, credit card on file, or mailed invoice rather than unsolicited text messages demanding immediate payment through a link. If you're unsure, don't rely on the text at all — log into your account directly through the agency's official website to check your actual balance.
How can I report a toll scam text? Forward the message to 7726 (SPAM) to report it to your mobile carrier, then file a report at ReportFraud.ftc.gov. You can also file a complaint with the FBI's Internet Crime Complaint Center at IC3.gov. Reporting helps regulators track and shut down these campaigns.
The genius of this scam is how ordinary it feels. No dramatic threats, no obviously broken English — just a small number and a deadline, sitting quietly in your inbox between a dozen other unremarkable texts. Now that you know exactly what to check, it loses every bit of that power.
Found this useful? Forward it to someone who drives regularly — especially anyone in your family who might not think to check the link before paying.
About the Author
Muhammad Ibraheem
Founder of Hackers Legacy | Cybersecurity Researcher & Privacy Analyst
Muhammad Ibraheem is a cybersecurity content creator with more than three years of experience producing educational content on ethical hacking, OSINT, privacy, and digital security. Through Hackers Legacy, he helps readers separate real cybersecurity threats from viral hype through research-driven analysis and educational content.
References & Further Reading

HACKERS LEGACY


Your ultimate knowledge for Ethical Hacking, Cybersecurity insights, digital products and a global community of curious minds.
LEARN . HACK . LEAD
Quick Links
Resources
Contact Us
> Email Us
> Response Time
Within 24 Hours
> World Wide Access
We are available globally.
©2026 Hackers Legacy
All righs reserved.
Built for learners
Secured for the future.
