The unpaid toll text scam, and how to tell it from a real toll notice
Updated August 6, 2026
"We've noticed an outstanding toll amount of $12.51 on your record." Twelve dollars and change, with a link attached to settle it. That reasonableness is the trick, and the message is a scam. Delete it. No US toll authority chases overdue tolls by texting strangers a payment link, and the sum is always small, usually somewhere between five and thirteen dollars, because a number that small doesn't feel worth arguing about.
- 1.top domain -- a cheap bulk-registered TLD scam sites use, not real toll agencies
- 2$12.51 balance, $50 late fee -- kept small so it doesn't feel worth disputing
- 3Real domain buried mid-string (ezdrivema-com-yhvqp.top) to look legit at a glance
- 4Real toll agencies mail paper invoices, not texts with payment links
The FBI's Internet Crime Complaint Center published the template back in April 2024, after more than 2,000 complaints in about a month. It has barely changed since. The crews sending these see no reason to improve something that already works.
The wording, close to verbatim
IC3 quoted the original like this: "(State Toll Service Name): We've noticed an outstanding toll amount of $12.51 on your record. To avoid a late fee of $50.00, visit https://myturnpiketollservices.com to settle your balance." Swap the agency name and the dollar figure and you've got most of what's still landing in 2026.
New York phones got a longer version that opened with "New York Toll Services," asked for $5.89, and warned of an extra $150.00 charge. Florida drivers get SunPass branding. Californians get FasTrak, Texans get TxTag, Massachusetts gets EZDriveMA, and everyone east of the Mississippi gets E-ZPass sooner or later.
The newer and nastier variant drops the toll framing entirely and arrives as a court summons: a case number, an official looking seal, a hearing date, and a QR code you're told to scan or face arrest. That one is doing real damage. In May 2026, roughly 200 people turned up at the Denver City and County Building inside two hours because a fake summons told them to. Court staff ended up taping signs to the doors.
Why the amount is so small
Because nobody's after your seven dollars. A security researcher who tracks these domains put it bluntly to CyberScoop: "They don't care about the seven bucks. They want your credit card number." The payment page harvests the full card, the billing address, sometimes your driver's license number, and increasingly a one time passcode so the card can be loaded straight into a mobile wallet on someone else's phone.
The domain is the giveaway, and it's not subtle
Look at the link before you look at anything else. Real toll agencies sit on ordinary, boring addresses. The scam sites live on cheap bulk registered domains:.xin.top.vip.cc.live.win.info. Researchers at Interisle counted 2,258 separate cybercrime domains containing the string "ezdrive" alone, most of them aimed at Massachusetts drivers, with names like ezdrivema-com-yhvqp.top. Across the whole campaign they logged registrations spread over 57 different top level domains.
Here's the trick that fools people. The real agency name gets buried in the middle of the address, so it reads correctly at a glance. Something like sunpass-com-help.info or bayareafastrak.secure-pay.top. Your eye stops at the familiar word. The part that actually decides where you land is the bit immediately before the first single slash, read right to left. If that isn't the agency's plain domain, you're not on the agency's site.
If the message came with a QR code rather than a link, you can decode the QR code from a photo without scanning it and read the destination first. Same principle, one extra step.
Why you get toll texts from states you've never driven through
Because these aren't sent from toll records. They're sent to bulk phone number lists, in blasts, with zero knowledge of whether you own a car. Getting a SunPass text in Idaho isn't a fluke, it's the whole method.
Notice also how the messages arrive. Many come through iMessage or RCS rather than plain SMS, often from an email address instead of a phone number, because internet based messaging sidesteps carrier spam filtering. That's also why some versions tell you to reply "Y" and then reopen the thread before the link becomes tappable. Apple and Google suppress links from unknown senders until you respond, so the scammer talks you into flipping that switch yourself. Replying also confirms your number is live, which is why the follow ups start after you do it.
What genuine toll contact actually looks like
Florida is the clearest case. SunPass says its real texts come only from the short code 786727, and its real email comes from customerservice@sunpass.com or noreply@sunpass.com. Any message about SunPass from a normal ten digit number is fake regardless of what the sender name says.
The Toll Roads in Orange County states plainly that it doesn't text non accountholders at all. FasTrak says it never requests payment by text with a link to a website. For most agencies nationwide, an actual unpaid toll produces a paper invoice mailed to the address on your vehicle registration, and if it escalates it escalates to a collection agency by mail, not to your phone.
There's now one real exception worth knowing about, and it's narrow. The Pennsylvania Turnpike approved roughly $292,000 for a six month pilot with Transworld Systems to text Toll By Plate customers who haven't paid a first invoice, with messages going out around days 31 and 45 to only half of the eligible group as a test. Officials have said those texts will not request payment directly. As of early August 2026 I couldn't confirm the pilot's exact start date or the final wording, so treat any Pennsylvania toll text asking you to pay through a link as fake anyway.
Checking a real balance takes about two minutes
Type the address yourself. Don't tap, don't search and click the first sponsored result, don't call a number printed in the text. E-ZPass member agencies are listed at e-zpassiag.com, though the group itself holds no customer accounts, so you'll be sent to whichever agency issued your tag. Florida is sunpass.com, Orange County is thetollroads.com, the Bay Area is bayareafastrak.org, Texas is txtag.org. If you have a paper statement anywhere, the number on it beats all of this.
Log in. Look at the balance. If it's zero or current, you're done, and you can stop thinking about it.
If you already paid, or entered a card
Move on the card first. Call the number on the back of it, say the card was entered on a phishing site, and ask for it to be closed and reissued rather than just watched. Cancel any card you tried even if the page threw an error, since errors on these sites are frequently fake. Then dispute anything already posted.
If the page asked for a verification code your bank had texted you and you typed it in, say that specifically. That code is usually what lets a stolen card get loaded into a digital wallet, and banks treat it differently from a plain card compromise.
If you reached the payment page by scanning a code rather than tapping a link, the recovery steps are slightly different and worth following in order, which is what our page on what to do after scanning a scam QR code covers. And if the same crew comes back at you as the DMV a few weeks later, which happens often, the tells are laid out in our piece on the DMV traffic ticket text scam.
Reporting, and how much it's worth
Forward the message to 7726, which spells SPAM, so your carrier can act on the sender. File at ic3.gov with the originating number and the full URL, and at reportfraud.ftc.gov. I'll be honest about the odds: reporting almost never gets your specific case resolved, and takedowns barely dent the supply, since researchers estimate a crew that loses a thousand domains can register forty thousand more the next day. Aggregate reports still drive the agency warnings that reach people who'd otherwise pay.
How worried you should actually be
Less than the headlines suggest, if you didn't touch it. Receiving the text does nothing to you. Opening it does nothing. Even tapping the link and closing the page immediately is very unlikely to have cost you anything, because these sites steal by asking, not by exploiting your phone. The damage lives entirely in what you typed. So keep one rule and you can throw the rest of this page away: money you didn't know you owed never arrives by text.