Toll and delivery texts

Also called: toll scam text · unpaid toll scam · parcel scam · redelivery fee scam · smishing

A toll or delivery text claims you owe a small charge — an unpaid road toll, a redelivery fee, a customs payment — and links to a payment page that captures your card. The amount is deliberately trivial so that nobody queries it. The card details are the objective, not the charge.

Key facts

Category
Identity theft
First documented
2020
Typical loss
$20–$3k USD, per victim
Main channels
SMS, iMessage, RCS, WhatsApp, email
Who is targeted
Everyone with a mobile phone — this is the highest-volume scam message type in most countries; Anyone expecting a delivery, which is most people most weeks; Drivers in regions with electronic tolling, where a small unpaid charge is routine; People who recently moved or travelled, for whom an unexpected charge is plausible
Documented origins
China, Russia, Nigeria, United Kingdom, United States
Main targets
United States, United Kingdom, Canada, Australia, New Zealand, Ireland, Singapore, Germany
Case files
3 documented cases
Last reviewed
2026-09-06
Anatomy of a toll or delivery textAnatomy of a toll or delivery text. The amount is tiny on purpose. The card details are the product, not the payment. 1. A tiny outstanding amount: An unpaid toll of £2.40, a redelivery fee, a customs charge on a parcel. 2. It is probably true: You did drive somewhere. You are expecting a parcel. Most weeks, most people are. 3. A link you cannot inspect: On a phone the domain is truncated. The message may sit inside a real message thread. 4. A payment page that looks right: Correct branding, correct amount, a card form. Nothing about it feels like a decision. 5. The card is captured: Sometimes with a one-time code request, which defeats the protection it was meant to add. 6. A call about the transaction: Often the expensive part: a "fraud team" rings about the payment you just made. The diagram marks stage 4 as the point where the scheme can still be stopped: The amount is small so that you will not think about it. The charge is not the theft — the card details are. Never pay a toll, fee or charge from a link in a message; go to the operator's own site or app, where the debt either exists or does not.Anatomy of a toll or delivery textThe amount is tiny on purpose. The card details are the product, not the payment.1A tiny outstandingamountAn unpaid toll of £2.40, aredelivery fee, a customscharge on a parcel.Seconds2It is probably trueYou did drive somewhere.You are expecting a parcel.Most weeks, most peopleare.Seconds3A link you cannotinspectOn a phone the domain istruncated. The message maysit inside a real messagethread.Seconds4A payment page thatlooks rightCorrect branding, correctamount, a card form.Nothing about it feels likea decision.Seconds5The card is capturedSometimes with a one-timecode request, which defeatsthe protection it was meantto add.Seconds6A call about thetransactionOften the expensive part: a"fraud team" rings aboutthe payment you just made.Hours to daysWhere it can still be stopped — stage 4The amount is small so that you will not think about it. The charge is not the theft — the card details are. Never pay a toll, fee or charge from a link in amessage; go to the operator's own site or app, where the debt either exists or does not.Stages documented in FBI IC3 phishing reporting and Australian National Anti-Scam Centre text-message data for 2024 and 2025.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

A text arrives. You owe £2.40 in unpaid tolls. Or a parcel could not be delivered and a £1.99 redelivery fee is required. Or there is a customs charge on something arriving from abroad. There is a link.

The amount is the design, and it is worth pausing on. It is small enough that paying it is not a decision — it is an errand. Nobody rings their bank about £2.40, nobody researches the sender, and almost nobody notices the domain. That is the entire mechanism, because the charge is not the theft. The card details entered on the page are.

The scale is enormous and the shape is changing. In Australia, text scam reports fell 62.4% in a single year, from 77,365 to 29,058, which the National Anti-Scam Centre attributes to disruption work across the ecosystem. Losses through the same channel rose, from A$14.0 million to A$18.0 million. In the United States the FTC logged 246,784 fraud reports where the contact was by text, with $470 million in losses and a $1,000 median — higher than email, lower than phone.

How it actually works

  1. A tiny outstanding amount

    An unpaid toll, a redelivery fee, a customs charge, a small account adjustment. Chosen to be beneath the threshold at which anyone investigates anything.

  2. It is probably true

    You did drive somewhere. You are expecting a parcel. Most people, most weeks, have a plausible reason for this message to be real. The scheme does not need to be believed so much as to be unremarkable.

  3. On a phone the domain is truncated and the sender is a name rather than an address. Spoofed sender IDs mean the message may arrive inside a genuine thread from the real organisation.

  4. A payment page that looks right

    Correct branding, correct amount, a card form. Modern kits proxy the genuine site, so it behaves exactly as it should.

    Where it could have stopped

    Never resolve a charge through a link in a message — even when the charge is real. Go to the operator’s own website or app the way you normally would, and the debt either exists in your account or it does not. This costs a minute and makes the entire category ineffective.

  5. The card is captured

    Sometimes with a one-time code request, which hands over the very protection the code exists to provide.

  6. The follow-up call

    Days later, a “fraud team” rings about the suspicious transaction you just made. This is often where the real money goes — see the safe account scam. The text was groundwork.

Why it works

The premise is usually true. Unlike a lottery you never entered, an unpaid toll is entirely plausible. The message does not have to be convincing, only unremarkable.

The amount removes deliberation. People apply scrutiny in proportion to stakes. £2.40 gets none, which is precisely why that figure and not £240.

Phones defeat inspection. Truncated URLs, name-based senders, and a few seconds of attention while doing something else.

Spoofed sender IDs put scams in real threads. A message appearing directly beneath genuine texts from the postal service defeats one of the few checks people actually perform.

Volume costs nothing. Millions of messages, a fraction of a percent conversion, and the economics work. There is no targeting to get wrong.

And the aftermath is invisible. A stolen card number is used weeks later, somewhere else, in a way the victim never connects to a £2 toll payment they have forgotten making.

Where it comes from

Large-scale smishing infrastructure aimed at Western countries has been repeatedly attributed to Chinese-language criminal groups operating phishing-as-a-service platforms — subscription products supplying templates for hundreds of postal services, tolling authorities, banks and tax agencies, with hosting, domain rotation and a dashboard of harvested cards.

That structure explains the pattern people notice: the same message wording appearing against Royal Mail, USPS, Australia Post and Canada Post within days, and toll templates appearing region by region as electronic tolling schemes are introduced.

The victims’ side is entirely domestic — stolen card details are used or sold wherever they work — but the production is industrial, remote, and rented rather than owned.

Real cases

A sticker over the parking meter's QR code

2026 US Ongoing

On 3 September 2026 the FTC warned consumers that people have reported scammers covering up legitimate QR codes on parking meters with codes of their own. Scanning the substituted code leads to a fake site built to take payment details, personal information, or both. It is the physical version of a phishing link, and it defeats every habit people have learned about checking where a link goes.

Read the case file · 2 sources

Phishing reports fell while losses rose elevenfold

2025 US · AU Ongoing $215.8m

US phishing and spoofing complaints fell from 298,878 in 2023 to 191,561 in 2025, while reported losses rose from $18.7 million to $215.8 million — roughly eleven times. Australia saw the same divergence in a single year: Scamwatch phishing reports fell 33.2%, while combined national phishing losses rose 15.5%. Phishing is becoming a smaller, far more expensive crime.

Read the case file · 2 sources

Text scam reports collapsed 62% while losses went up

2025 AU · US Ongoing $11.6m

Australian text-message scam reports fell from 77,365 in 2024 to 29,058 in 2025 — a 62.4% collapse that the National Anti-Scam Centre attributes to disruption across the ecosystem. Losses through the same channel went the other way, rising from A$14.0 million to A$17.9 million, driven by high-value losses in job, investment and phishing scams. Blocking is working on volume and not on harm.

Read the case file · 3 sources

Red flags

  • A small charge with a link to pay it. The genre in one line.
  • Urgency out of all proportion — a £2 toll that must be settled within 12 hours or penalties apply.
  • A delivery you are not expecting, or one you are, which is exactly what makes it work.
  • A domain that is nearly right — an extra word, a hyphen, an unusual ending.
  • A payment page asking for more than a payment needs: date of birth, full address, account login.
  • A request for a one-time code to complete the payment.
  • Your password manager does not offer to fill the page.
  • A message that arrives in the same thread as genuine ones. Thread position proves nothing.
  • A follow-up call about the transaction you just made.

If it’s happening to you

If you received one and did nothing. Forward it to 7726 where that service exists — free in the UK, Australia, Canada, the US and elsewhere — then delete and block. Do not reply STOP; replying confirms the number is live.

If you entered card details.

  1. Cancel the card now. Do not wait to see whether a charge appears. The details are the theft.
  2. Expect a call. A “fraud team” ringing about the transaction is a common sequence and leads directly to the safe-account script. Your bank will not call and ask you to move money.
  3. Check for a small test charge and treat it as confirmation rather than as the extent of it.
  4. Report it. See where to report.

If you entered a login rather than a card. Change that password immediately from your own app or bookmark, change it anywhere else you used it, and revoke active sessions.

If the charge might be real. Check it at the source. Go to the tolling operator or the postal service the way you normally would and look at your account. Almost every one of these organisations now publishes a page saying explicitly that they do not request payment by text link — because they are tired of being impersonated.

Where the money goes

The £2 goes to a payment processor that will be abandoned within weeks, and it barely matters. The card number is the product.

Stolen card details are validated with a small transaction — which is often the charge the victim actually made — then bundled and sold, or used to buy goods that can be resold. The gap between capture and use is deliberate: by the time a fraudulent purchase appears, the victim has long stopped connecting it to a toll message.

Where the page harvested a login instead, the credential goes into the same market as any other phished credential, and is used by someone with no connection to whoever sent the text.

The other half of this story

Our sibling site Clean on Paper explains what happens to a stolen card number — how card data is tested, resold and converted into goods that can be moved.

By the numbers

No agency publishes a line item for most of the schemes on this site, so these charts show the official categories that contain this scheme. Each series is labelled with the agency's own category name. See how the mapping works.

Reported losses over timeLine chart of reported losses from 2021 to 2025 for the agency categories that cover this scheme: Phishing/Spoofing (US); Phishing (AU); Phishing scams (AU); Phishing (CA).Reported losses over timeEach line is one agency category that covers this scheme. Agency categories are usually broader than the scheme itself.$0$50m$100m$150m$200mPhishing/Spoofing (US), 2023: $19mPhishing/Spoofing (US), 2024: $70mPhishing/Spoofing (US), 2025: $216mPhishing (AU), 2024: $56mPhishing (AU), 2025: $63mPhishing scams (AU), 2025: $20mPhishing (CA), 2021: $0Phishing (CA), 2022: $0Phishing (CA), 2023: $0Phishing (CA), 2024: $0Phishing (CA), 2025: $020212022202320242025Phishing/Spoofing (US)Phishing (AU)Phishing scams (AU)Phishing (CA)Categories are the publishers’ own and are broader than this scheme, so these lines bound it rather than measure it exactly. Lines are notcomparable to each other: different countries, different reporting systems.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP; FBI Internet Crime Complaint Center (IC3); National Anti-Scam Centre (ACCC), Australia(transcribed from the published report). Pulled 2026-09-06.
Full dataset, methodology and downloads

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: Text scam reports falling from 77,365 to 29,058, losses rising to A$17,977,491, and the attribution of both movements.
  2. Consumer Sentinel Network Data Book 2024. US Federal Trade Commission. Accessed 2026-09-06. Supports: 246,784 US fraud reports with text as the contact method, $470m in losses, a $1,000 median, and 164,634 unsolicited text reports.
  3. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: US phishing and spoofing complaint and loss totals, the category recording toll and delivery texts.
  4. Reporting fraud. UK Government, Stop! Think Fraud campaign. Accessed 2026-09-06. Supports: The 7726 text-forwarding route.
  5. See a QR code parked somewhere? Don't scan it…yet!. US Federal Trade Commission, Consumer Alerts. Accessed 2026-09-06. Supports: The physical QR variant of the same small-payment capture technique.

Common questions

Why is the amount always so small?

Because a £2.40 charge does not feel like a decision. Anything large enough to make you stop and think would defeat the purpose. The payment is not the theft — it is the mechanism for capturing the card details, which are worth far more than the charge.

The text appeared in the same thread as real messages from the postal service.

Sender IDs can be spoofed, which places a scam message inside a legitimate thread. Thread position tells you nothing about who sent something. It is one of the most effective tricks in this category precisely because it defeats a check that feels sensible.

I do actually have an unpaid toll. How do I check?

Go to the tolling operator's own website or app the way you normally would, and look at your account. The debt either exists there or it does not. Never resolve a charge through a link in a message, even when the charge turns out to be real.

I paid £2. Should I worry about such a small amount?

Yes — treat it as seriously as a large one. The small charge is a test transaction, and the card details will be used or resold afterwards. Cancel the card, do not simply watch the account.

What is the follow-up call?

Frequently the expensive part. Days later, a 'fraud team' rings about the suspicious transaction you made, and the safe-account script begins. If you have entered card details on a phishing page, expect that call and refuse it.

Should I reply STOP?

No. Replying confirms the number is live and in use, which increases what it is worth. Forward the message to 7726 where that service exists, then delete and block.

Where the £2 goes, and where the card number goesWhere the £2 goes, and where the card number goes. The fee barely matters. The card number is the product. Where the £2 goes, and where the card number goesThe fee barely matters. The card number is the product.A small toll orredelivery feeSmall enough not to bequeried, and it is notthe objectiveA processor abandonedin weeksThe charge the victimmade is often the testthat the card worksThe card, validated bythat chargeThe gap before use isdeliberate — by thennobody connects it toa textBundled, sold, orspent on resaleablegoodsReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.What happens to stolen card details — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/money-mules/Where the page harvested a login instead, the credential goes into the same market as any other phished credential, and is used by someone with no connection to whoever sent the text.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.