By J. Mesa
A text arrives: you owe $12.51 in unpaid tolls, and a $50 late fee applies unless you pay today. A link follows. You have not driven a toll road in months, but the amount is small and the deadline is close. That is the design. On April 12, the FBI’s Internet Crime Complaint Center warned that it had received more than 2,000 complaints since early March about texts posing as road toll collection services in at least three states.
What is smishing?
Smishing is phishing by text message. The word combines SMS and phishing. The message poses as a company or an agency you trust and pushes you to tap a link, call a number, or reply with personal details.
How does the toll text scam work?
- The scammer sends the same message to thousands of phone numbers, without knowing who drives where.
- The text names a toll service and claims a small unpaid balance.
- It threatens a late fee to create urgency.
- The link leads to a website that copies the look of the real toll agency.
- The site asks for your name, address, and card number to “settle” the balance. Some versions ask for a driver’s license number as well.
- The scammer uses or sells the card and the personal details.
The FBI notes that the texts use nearly identical wording, and that the link changes to imitate the toll service of whichever state the message claims to come from. The small dollar amount is deliberate. People argue with a $900 bill. They pay $12 to make a problem go away.
What other smishing texts are common?
- Package delivery. “Your package could not be delivered. Confirm your address.” These pose as the Postal Service, UPS, or FedEx.
- Bank fraud alerts. “Did you attempt a $1,200 purchase? Reply YES or NO.” A reply triggers a call from a fake fraud department.
- Account problems. Messages that pose as Amazon, Apple, Netflix, or PayPal and claim a locked account or a failed payment.
- The boss. A text from an unknown number opening with “Hi, it’s owner’s name]. Are you free?” This leads to a [gift card request.
- Wrong number. A friendly “Is this Sarah?” that turns into a long conversation and, weeks later, an investment pitch.
- Job offers. Unsolicited offers of remote work with high pay for little effort.
- Verification codes. A text or call asking you to read back a code you just received. The scammer is logging in to your account at that moment.
- Prizes and refunds. You won, or you are owed money. Tap here.
Why do text scams work so well?
- People open nearly every text, and most within minutes.
- A phone shows little of a web address, which hides a fake domain.
- Email has spam filters built over decades. Text messaging has far fewer.
- A text feels personal and urgent in a way email does not.
- Legitimate companies do send texts about deliveries and fraud, so the fake ones fit an expected pattern.
How do I spot a fake text?
- You did not expect it. You ordered no package, drove no toll road, and made no purchase.
- It creates urgency. A fee, a deadline, a locked account.
- The sender looks wrong. A full ten-digit number, an email address, or an international number, where a real company would use a short code.
- The link looks wrong. Odd endings, extra words, hyphens, or a shortened link that hides the destination.
- It asks for payment or personal details through the link.
- It tells you to reply “Y” and reopen the message to activate the link. That instruction exists to get around a phone’s link protections.
What should I do if I get a toll text?
The FBI’s advice is direct.
- Do not tap the link.
- Check your account through the toll service’s real website, which you type in yourself, or call the customer service number printed on your statement or transponder.
- Report the text at ic3.gov, and include the phone number it came from and the website in the link.
- Delete the text.
How do I report and block scam texts?
- Forward the message to 7726, which spells SPAM. This reports it to your carrier at no charge.
- Use the report option in your messaging app: “Report Junk” on an iPhone, “Block and report spam” on Android.
- Block the number.
- Report to the FTC at ReportFraud.ftc.gov.
- Do not reply, not even with “STOP.” A reply confirms that a person reads the number.
Turn on the filters your phone already has. On an iPhone, enable “Filter Unknown Senders” in the Messages settings. On Android, enable spam protection in the Messages app.
What should I do if I tapped the link?
It depends on how far you went.
- You tapped and entered nothing. Close the page. Clear your browser history and site data. Keep the phone’s software updated. You are almost certainly fine.
- You entered card details. Call your card issuer now, dispute any charges, and ask for a new card number.
- You entered a password. Change it right away, and change it anywhere else you used it. Turn on multi-factor authentication.
- You entered personal details such as a driver’s license or Social Security number. Freeze your credit and watch your accounts.
- You installed something. Remove the app, update the phone, and if the phone holds work email, tell your IT contact.
How does smishing threaten a business?
Your employees carry work email, files, and authentication apps on the same phone that receives these texts.
- Stolen work logins. A text that poses as IT or as Microsoft sends an employee to a fake sign-in page. The phone sits outside your office firewall and web filter.
- Stolen verification codes. An attacker who has a password texts or calls the employee and asks for the six-digit code.
- Fake executives. Texts that pose as the owner ask for gift cards, a wire, or a quick call.
- Payroll diversion. A text that poses as an employee asks HR to change a direct deposit account.
How do I protect my business?
- Add texts to your training. Most programs cover email and stop there. Show staff real examples of smishing. Our cybersecurity training includes them.
- Set a rule: IT and leadership never ask for passwords or codes by text.
- Verify by voice. Any request for money, gift cards, or a change to payroll or bank details gets a call to a known number.
- Use stronger multi-factor methods. An authenticator app with number matching or a security key resists code theft better than a text message.
- Set minimum standards for phones that hold work data: a screen lock, current software, and no unknown apps.
- Make reporting simple. Tell staff to screenshot a suspicious text and send it to one named person.
How can I tell whether a text from a company is real?
Assume it is not, and check another way. Open the company’s app or type its web address. Call the number on your card or your bill. Legitimate banks, carriers, and agencies will have the same alert waiting in your account if it is genuine. No real company loses patience because you chose to verify.
Does my business text its own customers?
If you send appointment reminders, invoices, or delivery notices by text, scammers can imitate you. Tell customers what you will and will not send. Use a consistent number or short code. Keep links on your own domain, and never ask for card details or passwords by text. In the United States, carriers now require businesses that send texts from standard ten-digit numbers to register their brand and their messaging campaigns. Unregistered traffic gets blocked.
Your next step
Show the toll text to your staff and your family this week, and make sure each person knows the number 7726. For training that covers text, phone, and email scams together, see our services or contact Cerberus Cybersecurity.