Also called: toll scam text · unpaid toll scam · parcel scam · redelivery fee scam · smishing
A toll or delivery text claims you owe a small charge — an unpaid road toll, a redelivery fee, a customs payment — and links to a payment page that captures your card. The amount is deliberately trivial so that nobody queries it. The card details are the objective, not the charge.
Key facts
Category
Identity theft
First documented
2020
Typical loss
$20–$3k USD, per victim
Main channels
SMS, iMessage, RCS, WhatsApp, email
Who is targeted
Everyone with a mobile phone — this is the highest-volume scam message type in most countries; Anyone expecting a delivery, which is most people most weeks; Drivers in regions with electronic tolling, where a small unpaid charge is routine; People who recently moved or travelled, for whom an unexpected charge is plausible
Documented origins
China, Russia, Nigeria, United Kingdom, United States
Main targets
United States, United Kingdom, Canada, Australia, New Zealand, Ireland, Singapore, Germany
Case files
3 documented cases
Last reviewed
2026-09-06
The stages of the scheme, in order, with the point where it can still be stopped.
What it is
A text arrives. You owe £2.40 in unpaid tolls. Or a parcel could not be delivered and a £1.99
redelivery fee is required. Or there is a customs charge on something arriving from abroad. There is a
link.
The amount is the design, and it is worth pausing on. It is small enough that paying it is not a
decision — it is an errand. Nobody rings their bank about £2.40, nobody researches the sender, and
almost nobody notices the domain. That is the entire mechanism, because the charge is not the
theft. The card details entered on the page are.
The scale is enormous and the shape is changing. In Australia, text scam reports fell 62.4% in a
single year, from 77,365 to 29,058, which the National Anti-Scam Centre attributes to disruption work
across the ecosystem. Losses through the same channel rose, from A$14.0 million to A$18.0 million. In
the United States the FTC logged 246,784 fraud reports where the contact was by text, with $470
million in losses and a $1,000 median — higher than email, lower than phone.
How it actually works
A tiny outstanding amount
An unpaid toll, a redelivery fee, a customs charge, a small account adjustment. Chosen to be
beneath the threshold at which anyone investigates anything.
It is probably true
You did drive somewhere. You are expecting a parcel. Most people, most weeks, have a plausible
reason for this message to be real. The scheme does not need to be believed so much as to be
unremarkable.
A link you cannot inspect
On a phone the domain is truncated and the sender is a name rather than an address. Spoofed sender
IDs mean the message may arrive inside a genuine thread from the real organisation.
A payment page that looks right
Correct branding, correct amount, a card form. Modern kits proxy the genuine site, so it behaves
exactly as it should.
Where it could have stopped
Never resolve a charge through a link in a message — even when the charge is real. Go to the operator’s own website or app the way you normally would, and the debt either exists in your account or it does not. This costs a minute and makes the entire category ineffective.
The card is captured
Sometimes with a one-time code request, which hands over the very protection the code exists to
provide.
The follow-up call
Days later, a “fraud team” rings about the suspicious transaction you just made. This is often
where the real money goes — see
the safe account scam. The text was
groundwork.
Why it works
The premise is usually true. Unlike a lottery you never entered, an unpaid toll is entirely
plausible. The message does not have to be convincing, only unremarkable.
The amount removes deliberation. People apply scrutiny in proportion to stakes. £2.40 gets none,
which is precisely why that figure and not £240.
Phones defeat inspection. Truncated URLs, name-based senders, and a few seconds of attention while
doing something else.
Spoofed sender IDs put scams in real threads. A message appearing directly beneath genuine texts
from the postal service defeats one of the few checks people actually perform.
Volume costs nothing. Millions of messages, a fraction of a percent conversion, and the economics
work. There is no targeting to get wrong.
And the aftermath is invisible. A stolen card number is used weeks later, somewhere else, in a way
the victim never connects to a £2 toll payment they have forgotten making.
Where it comes from
Large-scale smishing infrastructure aimed at Western countries has been repeatedly attributed to
Chinese-language criminal groups operating phishing-as-a-service platforms — subscription products
supplying templates for hundreds of postal services, tolling authorities, banks and tax agencies, with
hosting, domain rotation and a dashboard of harvested cards.
That structure explains the pattern people notice: the same message wording appearing against Royal
Mail, USPS, Australia Post and Canada Post within days, and toll templates appearing region by region
as electronic tolling schemes are introduced.
The victims’ side is entirely domestic — stolen card details are used or sold wherever they work — but
the production is industrial, remote, and rented rather than owned.
On 3 September 2026 the FTC warned consumers that people have reported scammers covering up legitimate QR codes on parking meters with codes of their own. Scanning the substituted code leads to a fake site built to take payment details, personal information, or both. It is the physical version of a phishing link, and it defeats every habit people have learned about checking where a link goes.
US phishing and spoofing complaints fell from 298,878 in 2023 to 191,561 in 2025, while reported losses rose from $18.7 million to $215.8 million — roughly eleven times. Australia saw the same divergence in a single year: Scamwatch phishing reports fell 33.2%, while combined national phishing losses rose 15.5%. Phishing is becoming a smaller, far more expensive crime.
Australian text-message scam reports fell from 77,365 in 2024 to 29,058 in 2025 — a 62.4% collapse that the National Anti-Scam Centre attributes to disruption across the ecosystem. Losses through the same channel went the other way, rising from A$14.0 million to A$17.9 million, driven by high-value losses in job, investment and phishing scams. Blocking is working on volume and not on harm.
A small charge with a link to pay it. The genre in one line.
Urgency out of all proportion — a £2 toll that must be settled within 12 hours or penalties apply.
A delivery you are not expecting, or one you are, which is exactly what makes it work.
A domain that is nearly right — an extra word, a hyphen, an unusual ending.
A payment page asking for more than a payment needs: date of birth, full address, account login.
A request for a one-time code to complete the payment.
Your password manager does not offer to fill the page.
A message that arrives in the same thread as genuine ones. Thread position proves nothing.
A follow-up call about the transaction you just made.
If it’s happening to you
If you received one and did nothing. Forward it to 7726 where that service exists — free in the
UK, Australia, Canada, the US and elsewhere — then delete and block. Do not reply STOP; replying
confirms the number is live.
If you entered card details.
Cancel the card now. Do not wait to see whether a charge appears. The details are the theft.
Expect a call. A “fraud team” ringing about the transaction is a common sequence and leads
directly to the safe-account script. Your bank will not call and ask you to move money.
Check for a small test charge and treat it as confirmation rather than as the extent of it.
If you entered a login rather than a card. Change that password immediately from your own app or
bookmark, change it anywhere else you used it, and revoke active sessions.
If the charge might be real. Check it at the source. Go to the tolling operator or the postal
service the way you normally would and look at your account. Almost every one of these organisations
now publishes a page saying explicitly that they do not request payment by text link — because they
are tired of being impersonated.
Where the money goes
The £2 goes to a payment processor that will be abandoned within weeks, and it barely matters. The card
number is the product.
Stolen card details are validated with a small transaction — which is often the charge the victim
actually made — then bundled and sold, or used to buy goods that can be resold. The gap between
capture and use is deliberate: by the time a fraudulent purchase appears, the victim has long stopped
connecting it to a toll message.
Where the page harvested a login instead, the credential goes into the same market as any other phished
credential, and is used by someone with no connection to whoever sent the text.
No agency publishes a line item for most of the schemes on this site, so these charts show the
official categories that contain this scheme. Each series is labelled with the agency's
own category name. See how the mapping works.
Consumer Sentinel Network Data Book 2024.
US Federal Trade Commission. Accessed 2026-09-06. Supports: 246,784 US fraud reports with text as the contact method, $470m in losses, a $1,000 median, and 164,634 unsolicited text reports.
2025 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: US phishing and spoofing complaint and loss totals, the category recording toll and delivery texts.
Reporting fraud.
UK Government, Stop! Think Fraud campaign. Accessed 2026-09-06. Supports: The 7726 text-forwarding route.
Because a £2.40 charge does not feel like a decision. Anything large enough to make you stop and think would defeat the purpose. The payment is not the theft — it is the mechanism for capturing the card details, which are worth far more than the charge.
The text appeared in the same thread as real messages from the postal service.
Sender IDs can be spoofed, which places a scam message inside a legitimate thread. Thread position tells you nothing about who sent something. It is one of the most effective tricks in this category precisely because it defeats a check that feels sensible.
I do actually have an unpaid toll. How do I check?
Go to the tolling operator's own website or app the way you normally would, and look at your account. The debt either exists there or it does not. Never resolve a charge through a link in a message, even when the charge turns out to be real.
I paid £2. Should I worry about such a small amount?
Yes — treat it as seriously as a large one. The small charge is a test transaction, and the card details will be used or resold afterwards. Cancel the card, do not simply watch the account.
What is the follow-up call?
Frequently the expensive part. Days later, a 'fraud team' rings about the suspicious transaction you made, and the safe-account script begins. If you have entered card details on a phishing page, expect that call and refuse it.
Should I reply STOP?
No. Replying confirms the number is live and in use, which increases what it is worth. Forward the message to 7726 where that service exists, then delete and block.
Where the money goes after it leaves, and where it becomes hard to recover.
Reporting is what produces the enforcement data on this page. Find the right agency and phone
number for your country on the report page. If money moved in the last
few hours, call your bank first.