Texts demanding a small ‘redelivery’ or toll fee are a fast-growing way thieves steal card numbers

a man in a yellow hard hat looking at a phone

The amount in the message is deliberately small: a few dollars for a package redelivery or an overdue toll. That low figure makes payment feel easier than investigation, while the urgent threat of a fee, suspended registration, or lost parcel pushes the recipient toward a link. The real target is often not the small payment but the card number, security code, login, address, or Social Security number entered on the fake site.

The loss data show why the tiny-fee script keeps spreading

Text messages reach a phone with fewer barriers than email and are often opened quickly. A scammer can send enormous volumes of messages without knowing whether a recipient recently drove on a toll road or expects a package. Ordinary coincidence makes the message feel personalized.

Federal Trade Commission data put reported 2024 losses from scams that began by text at $470 million, five times the 2020 amount even though the number of reports declined. The FTC’s text-scam analysis identified fake package-delivery problems as the most commonly reported type and bogus toll notices among the other leading scripts.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

A convincing page can be cheaper than stealing a card

The link commonly opens a mobile site copied from a postal carrier or state toll agency. Logos, colors, tracking fields, and customer-service language can be reproduced closely enough to pass a quick glance. The address bar, however, leads to a domain unrelated to the real agency.

The form may begin with a name and mailing address, then ask for a card to pay the fee. Some versions continue to a bank login or identity-verification screen. Each field adds information that can be used for unauthorized purchases, account takeover, or identity theft. A declined payment message may simply encourage entry of a second card, giving the criminals another credential.

The U.S. Postal Inspection Service’s package-smishing warning says USPS tracking texts are sent only when a customer has requested them and do not contain unfamiliar links demanding a response. A delivery issue can be checked through the retailer’s order history or a tracking number entered manually at the carrier’s known website.

Toll impersonation has become a national script

Fake toll messages borrow the names of regional systems, which means a recipient may recognize a real local brand. The text threatens a late charge or registration consequence and directs payment to a page outside the official toll domain. Someone who recently traveled can mistake timing for proof.

The trend did not end with the 2024 data. In a May 2026 review, the FTC said reports of government-imposter scams rose 40% during 2025, partly because of messages about overdue tolls. The agency advised contacting the toll program through a phone number or site independently known to be genuine, never through the message.

Entering a card requires a rapid containment response

A recipient who typed card details into the fake page should contact the card issuer through the number on the physical card or official app. The issuer can block the card, replace it, review transactions, and explain the dispute process. Waiting for a fraudulent charge to appear gives the information more time to circulate.

If bank credentials were entered, the bank needs to know that login information may be compromised. The password should be changed from a clean device, multifactor authentication enabled, and connected payment services reviewed. Reused passwords on email or retail accounts need separate changes because access to email can help a thief reset other accounts.

A Social Security number or broader identity information raises a different risk. A security freeze at the three national credit bureaus can make new-account fraud harder, while IdentityTheft.gov provides a recovery plan and documentation trail. Existing account statements still require close review because a credit freeze does not block misuse of an already-open card or bank account.

The safest payment path starts outside the text

Legitimate package and toll obligations can be resolved without touching an embedded link. The recipient can open the carrier’s saved app, type the agency’s known address, consult a mailed bill, or call an official number. Searching the exact message wording can also expose warnings, but search advertisements should not be trusted as the payment destination.

Spam texts can be forwarded to 7726 and reported through the phone’s junk control. Reports to the FTC and, for postal impersonation, the Postal Inspection Service help investigators identify domains and phone numbers. Screenshots should preserve the sender, wording, link, and time before deletion.

The fee is bait, not a measure of the danger

A demand for $2 or $4 does not deserve less scrutiny than a demand for $2,000. Its small size is part of the social engineering, lowering resistance while the fake checkout collects credentials with much greater resale value.

The FTC’s fivefold loss growth and 2026 toll-imposter update establish that these messages are not isolated annoyances. Package and toll scripts have become repeatable ways to move a recipient from an unexpected text to a counterfeit payment page. Breaking that path at the link—and moving every verification step to an independently reached official channel—protects both the small fee and the far larger accounts behind the card.

This article was created with AI assistance and was reviewed, edited, and fact-checked by The Financial Wire editorial team.

More Financial Reading