A text says my package is stuck and my toll is unpaid :: Claude
MONTH 2 :: POST 1 :: A.I. Prompts :: Claude
A bearded man in a heavy jacket at a cluttered workbench, hand on his chin, reading down a long printed slip while a robot with glowing blue eyes stands at his elbow, looking on. Thoughtful, unhurried, nothing decided yet.
charades.net · prompt post
written by Claude · prompts uneditedThis post was written by Claude from our standing brief. We never edit a platform’s prompts — a defect gets a public note or a re-request, never a quiet fix. Before publishing, we ran every prompt once, on Claude; what came back appears beneath each card, unedited, with its run conditions.
Directions given to the A.I.
This is the topic brief sent to all three A.I.s, published so you can judge the answer against the ask. It was built 2026-09-28. Two standing instruction files went with it and are not shown here (the brief calls them FILE A and FILE B): the required post structure, and the audience, standards and forbidden list. The words below are unchanged; line breaks and formatting marks were turned into paragraphs, headings, lists and bold for the web. The numbered research notes are our working notes, gathered 2026-09-18 from the sources they name and not updated since. They were written for the A.I., not as advice to you, and not to the rules our own published words follow.
You are writing one complete blog post for a new section of charades.net. Two files are attached: FILE A (the exact structure your post must follow) and FILE B (the audience, voice, standards, and forbidden list that bind everything you write). Read both before writing.
THIS POST'S TOPIC: "A text says my package is stuck and my toll is unpaid"
A text has arrived about a stuck package, an unpaid toll, or a traffic fine, and the reader has not tapped anything yet — or has, and is now uneasy. Write to the person HOLDING THE PHONE. Your post gives them copy-paste prompts that turn their AI assistant into a short working session: sort out what the message is actually asking for, decide how to check it without using anything inside it, and know what to do next.
Cover the ground a real reader stands on:
- The first look: prompts that work from the reader's own description of the message — who it claims to be from, what it wants them to do, and how fast — to lay out what kind of request this is and what a legitimate version of it would look like.
- The independent check: prompts that help the reader plan how to confirm the claim through a channel they already trust — the carrier's or toll agency's own website or app, a number they look up themselves — never anything taken from the message.
- The reply trap: some of these texts ask for a reply before they send a link (see the findings below). Prompts that help the reader recognise any request to reply — even 'STOP' — as part of the ask.
- Reporting and cleanup: prompts that turn 'what do I do with this text' into a short, ordered routine.
- If they already tapped, typed or paid: prompts that organise the next hour — who to contact first, in what order, and what to have ready — with the reader making those contacts directly.
- The family habit: at least one card that helps the reader set up a simple household habit of checking first, which they set up together, in person, with each family member at their own phone.
Where verification belongs, say so plainly: What the carrier or toll agency actually sends, what an account actually owes, and whether a charge is real are checked in the agency's or company's own site, app or phone line, reached independently. The AI conversation prepares that check; it does not replace it.
ANGLE: a calm triage, not a lecture. The reader already knows scam texts exist. What they have never had is a repeatable way to go from "I just got this" to "here is how I check it, and here is what I do if I already tapped" — with their assistant doing the structuring.
Examples fit both households and small businesses; mark the small-business card or cards clearly. Label illustrative examples as illustrative.
SOURCE FINDINGS FOR THIS TOPIC
The findings below come from primary public sources, each listed with its publisher, date and link. Treat them as your starting ground:
- Rest your post's factual claims on these first. Add others only from sources that meet FILE B's "which sources count" standard, named inline with a date.
- Cite inline by the body and the date (for example, "the FTC, January 2025").
- Where two findings disagree, say so in one sentence and do not pick a side.
- Keep every figure with its date and with who was counted. Complaint totals are undercounts; never present them as how often something happens.
- Prefer the practical guidance to the statistics. The reader needs the next step more than the size of the problem.
- Some of these sources carry no date because they are standing guidance that does not go out of date. Cite those by publisher and do not invent a date.
- Do not describe any fact in your post as verified, checked or confirmed.
--- SOURCE MATERIAL BEGINS — facts to write from. Do not reproduce its headings, its numbering or its layout in your post. ---
The 30 research notes sent with it, with their sources
FINDINGS FOR THIS TOPIC — gathered 2026-09-18
What the texts look like right now
1. A toll text arrives unexpectedly, claims an unpaid balance, often shows a dollar amount, and links to a page that asks for bank or card details.
Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam
In their words: "says you have unpaid tolls and need to pay immediately" … "might show a dollar amount for how much you supposedly owe" … "include a link that takes you to a page to enter your bank or credit card info"
2. The texts borrow the names of real toll programs and threaten late fees or a suspended vehicle registration.
Source: FTC, "New trends in reports of imposter scams" (2026-05-07) — https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams
In their words: "These bogus messages might spoof real toll collection programs (like EZ-Pass, SunPass, FasTrak, and TxTag) to seem more credible." … "they threaten to charge you late fees or suspend your vehicle's registration if you don't pay right away"
3. A newer variant (April 2026): a 'traffic violation' text with a QR code, a fake state seal and a fake case number, threatening court action.
Source: FTC, "That text about a traffic violation is probably a scam" (2026-04-14) — https://consumer.ftc.gov/consumer-alerts/2026/04/text-about-traffic-violation-probably-scam
In their words: "The text might look official with a seal from whatever state it claims to be from and a (fake) case number" … "to pay for a traffic violation to avoid court"
4. Some fake toll texts ask you to reply 'Y' first, then send the link. They often come from international numbers.
Source: New York State (Governor's office), "Governor Hochul Warns Consumers of E-ZPass Text Message Scam" (2025-02-16) — https://www.governor.ny.gov/news/governor-hochul-warns-consumers-e-zpass-text-message-scam
In their words: "These fake texts are often sent from an international number and request the consumer to reply with 'Y' to receive a link and contain an unofficial website."
5. Package texts usually impersonate the U.S. Postal Service; victims reported paying fake 'redelivery' fees.
Source: FTC, "Top text scams of 2024 (Data Spotlight)" (2025-04) — https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024
In their words: "Messages about package deliveries, usually from someone pretending to be from the U.S. Postal Service, were the most reported text scam last year." … "many people reported paying a small "redelivery fee""
Note: "Last year" = 2024 (FTC spotlight published April 2025).
6. The sender's number may be faked to look like a toll company, or may be an international number.
Source: FCC, "How to Spot and Avoid Toll Road Payment Scam Texts" (undated on page) — https://www.fcc.gov/consumer-governmental-affairs/how-spot-and-avoid-toll-road-payment-scam-texts
In their words: "The sender's number may be spoofed to look like it's from a toll company." … "The sender's number may be an international number."
Note: The FCC page carries no date. The international-number point matches the dated New York notice (Feb 2025).
Who actually texts you — and who doesn't
7. USPS does not text or email you unless you first asked for tracking with a tracking number — and those messages do not contain a link.
Source: US Postal Inspection Service, "Smishing: Package Tracking Text Scams" (last updated 2025-05-19) — https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams
In their words: "USPS will not send customers text messages or e-mails without a customer first requesting the service with a tracking number, and it will NOT contain a link."
8. New York's E-ZPass and Tolls by Mail say they will never text or email asking for personal, sensitive information.
Source: New York State (Governor's office), "Governor Hochul Warns Consumers of E-ZPass Text Message Scam" (2025-02-16) — https://www.governor.ny.gov/news/governor-hochul-warns-consumers-e-zpass-text-message-scam
In their words: "Consumers should know that E-ZPass, or Tolls by Mail, will never send a text or email requesting personal, sensitive information."
9. E-ZPass Virginia DOES send texts — but only from two published numbers. Anything else claiming to be them is not.
Source: E-ZPass Virginia (state toll operator), "Active smishing scam" (2025 (year in page address; no date on page)) — https://www.ezpassva.com/news-resources/news/2025/active-smishing-scam.html
In their words: "If you receive a TXT/SMS message that is not from (844) 548-0707 or (844) 718-2368, it is not from E-ZPass Virginia"
Before you tap — the checking habit
10. Don't tap the link and don't reply. Check with the toll agency or company using a phone number or website you already know is real — never the one in the text.
Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam
In their words: "Reach out to the state's tolling agency using a phone number or website you know is real — not the info from the text."
11. A familiar company name in the text proves nothing.
Source: FTC, "Is that unexpected text a scam?" (2025-04-16) — https://consumer.ftc.gov/consumer-alerts/2025/04/unexpected-text-scam
In their words: "Don't assume a text from a known company or organization is legit."
12. Check the balance yourself by logging into your own toll account on the agency's real website.
Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412
In their words: "Check your account using the toll service's legitimate website"
Note: Use this PSA for its guidance only; its complaint counts are more than two years old.
13. Don't reply even to 'text STOP'.
Source: FCC, "Avoid the Temptation of Smishing Scams" (undated on page) — https://www.fcc.gov/avoid-temptation-smishing-scams
In their words: "Do not respond, even if the message requests that you 'text STOP' to end messages."
14. For the QR-code version: don't scan it. Check the court's own website or phone number, found independently.
Source: FTC, "That text about a traffic violation is probably a scam" (2026-04-14) — https://consumer.ftc.gov/consumer-alerts/2026/04/text-about-traffic-violation-probably-scam
In their words: "don't respond, and don't scan the QR code" … "use a website or phone number you know is correct, not info from the text message"
Reporting it (takes under a minute)
15. Forward the text to 7726 (SPAM) or use the phone's 'report junk' option, then delete it.
Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam
In their words: "forward them to 7726 (SPAM)"
16. USPS-themed texts can also go to the Postal Inspection Service at spam@uspis.gov, with a screenshot showing the sender number and date.
Source: US Postal Inspection Service, "Smishing: Package Tracking Text Scams" (last updated 2025-05-19) — https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams
In their words: "spam@uspis.gov"
17. Report to the FTC at ReportFraud.ftc.gov; the FBI's IC3 (ic3.gov) also takes these.
Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412
In their words: "ReportFraud.ftc.gov"
18. What 'report spam' does in Google Messages: the sender's number goes to Google, the last 10 messages from that sender can go too (the user may choose), and the report may also send the carrier the number plus the most recent message.
Source: Google (platform documentation), "Report spam in Google Messages" (current help page) — https://support.google.com/messages/answer/9061432?hl=en&co=GENIE.Platform%3DAndroid
In their words: "The last 10 incoming messages from the spammer are reported to Google to improve spam detection when reporting a conversation as spam." … "You may decide to report those messages or not" … "this will send a copy of the spammer's number plus the most recent text message to your mobile carrier"
Note: Platform documentation, cited for a fact about that platform only. Apple's equivalent page could not be read by the tool, so no iPhone claim is made.
If you already tapped, typed or paid — the next hour
19. Paid by credit card: call the issuer right away using the number on the back of the card, and ask for the money back. Debit card: same, with your bank or credit union.
Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
In their words: "Report it to the credit card issuer immediately. Use the number on the back of your card" … "you were tricked into paying a scammer with a debit card: Report it to your bank or credit union immediately"
20. Card-number-only theft: federal rules say you aren't responsible for unauthorized credit card charges when only the number was stolen.
Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/
In their words: "You are not responsible for unauthorized charges if someone stole only your credit card account number."
Note: Scope: CFPB words this for STOLEN numbers. Whether a charge the reader typed in themselves counts as 'unauthorized' is a question for the card issuer — the post must not promise a refund.
21. Debit card: report unauthorized charges within 60 days of the statement, or you may owe later charges.
Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/
In their words: "report it within 60 days after your account statement is available"
22. Watch for small, unfamiliar charges — thieves sometimes test a card with a small charge, then come back for more.
Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/
In their words: "sometimes thieves process a small debit or charge against your account and return to take more"
23. Gave your Social Security number: go to IdentityTheft.gov for a recovery plan.
Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
In their words: "IdentityTheft.gov"
24. Typed a password on the fake page: change it and turn on two-factor authentication.
Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
In their words: "Turn on two-factor authentication"
25. General: secure your accounts and dispute any unfamiliar charges.
Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412
In their words: "If you clicked any link or provided your information, take efforts to secure your personal information and financial accounts. Dispute any unfamiliar charges."
The second scam that follows the first
26. After a report, people get contacted by fake 'FBI / IC3' agents offering to recover money. IC3 says it never contacts people directly and never asks for payment to recover funds.
Source: FBI IC3, "PSA: FBI Warns of Scammers Impersonating the IC3" (2026-07-20) — https://www.ic3.gov/PSA/2026/PSA260720
In their words: "IC3 will never directly communicate with individuals via phone, email, social media, phone apps, online chat, or public forums." … "IC3 will never ask for payment to recover lost funds"
The family habit
27. The FTC's own advice: talking about scams with friends and family is one of the best defences.
Source: FTC, "Talk to your friends and family to fight fraud" (2026-07-30) — https://consumer.ftc.gov/consumer-alerts/2026/07/talk-your-friends-and-family-fight-fraud
In their words: "One of the best ways to fight fraud is to talk about it."
How big is this — with the caveats attached
28. People reported $470 million lost to scams that started with a text in 2024 — more than five times the 2020 figure. The FTC itself says this is only a fraction of the real harm.
Source: FTC, "Top text scams of 2024 (Data Spotlight)" (2025-04) — https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024
In their words: "in 2024, people reported $470 million in losses to these scams, more than five times the 2020 number" … "this number likely reflects only a fraction of the actual harm"
Note: Population: reports filed with the FTC. The 'top text scams' ranking came from hand-coding a random sample of 1,000 2024 reports.
29. Reports of government-imposter scams rose 40% in 2025, 'thanks in part to' toll texts.
Source: FTC, "New trends in reports of imposter scams" (2026-05-07) — https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams
In their words: "reports of government imposter scams were up 40%, thanks in part to messages about overdue tolls"
Note: Who was counted: reports filed with the FTC, which are undercounts — never read as how often this happens. The source says "up 40%"; the year 2025 is the reporting year of that alert, not wording the FTC used.
30. One vendor tracked 194,345 web addresses tied to one texting operation since January 2024. USPS was the most-copied single brand (28,045); toll services were the most-copied category (nearly 90,000). About 71% of the addresses were live for under a week.
Source: Palo Alto Networks Unit 42 (vendor threat research), "The Smishing Deluge: China-Based Campaign Flooding Global Text Messages" (2025-10-23) — https://unit42.paloaltonetworks.com/global-smishing-campaign/
In their words: "194,345" … "28,045" … "nearly 90,000 dedicated phishing FQDNs" … "71.3% of these domains were active for less than a week"
Note: Who was counted: web domains seen in Palo Alto Networks' own DNS data (Oct 2025). It counts WEBSITES, not texts received and not people harmed. Practical meaning: a link can be brand-new, so 'look it up to see if it's known-bad' is weak — go to the site you already know instead.
Where these sources disagree
- Do toll agencies text you at all? The FCC says toll operators "typically don't use text messages to collect on overdue accounts". E-ZPass Virginia does send texts, from two published numbers. Both can be true. Suggested one-line treatment for the posts: some agencies text their own customers, so the check is not 'did I get a text' but 'does it match what my agency says it sends'.
--- SOURCE MATERIAL ENDS ---
BOUNDARY (states the pack's own rule — do not cross it)
Do not write prompts that demonstrate, simulate, or explain how an attack or a scam is performed. Every prompt helps the reader assess, harden, verify, respond, or recover — nothing else. Do not claim any prompt makes the reader, their family, or their business safe; certainty claims are forbidden per FILE B. Do not write anything that shames the reader for what already happened. And per FILE B item 10: no prompt or advice for working a security question on someone else's behalf, secondhand — helping another person is taught first-hand only: the affected person at their own device, doing the work themselves, with the helper beside them or guiding them from a distance while they stay at their own controls. Write the at-a-distance case only where this post cannot do its job without it, and when you do, name it in a REMOTE-HELP FLAG line at the top of your chat reply, as FILE B describes. For this topic specifically: Do not compose example scam texts, even as illustrations, and do not reproduce real ones. Do not tell the reader to open, reply to, or scan anything in the message to "see" where it goes, and do not suggest the AI can check a link by visiting it. Do not have the reader paste the message or any link or address from it into the AI; they describe it in their own words, with links, codes and account details left out, and check it outside the chat. FILE A's example placeholder mentions pasting a suspicious message; for this topic, use a placeholder for the reader's own description instead, for example [PASTE YOUR OWN DESCRIPTION OF THE MESSAGE HERE — no links, codes or account details].
STRUCTURAL CHECKLIST (mirrors FILE A Part I — self-verify before returning)
Your post must contain, in order, with these exact ## headings:
- [ ] Title options — exactly 3, each ≤ 80 characters, reader-voice
- [ ] The moment — 2–4 sentences, no statistics
- [ ] What this post offers — one paragraph
- [ ] The prompt cards — 6 to 9 cards, each with: Use this when: · the complete prompt in a fenced code block with a [PASTE …] placeholder or the literal token NO INPUT NEEDED · How the AI reads this prompt: (2–5 sentences) · What to do with the answer: (1–3 sentences)
- [ ] Before you paste anything — one paragraph (remove personal details — real names, addresses, tracking or account numbers, the reader's own phone number)
- [ ] When AI is the wrong tool — non-empty (e.g. money or card details already handed over → the card issuer or bank first, using the number on the card; a Social Security number given → the FTC's IdentityTheft.gov)
- [ ] Where this leaves you — 1–3 sentences, no achieved-state claims
- [ ] Global: 800–1,800 words excluding code blocks · every statistic sourced and dated inline or omitted · no sections beyond the seven
Do not include execution examples, sample AI responses, or an FAQ — those are added after your draft is received, from real runs of your prompts.
RETURN FORM
One complete post, in markdown, following FILE A exactly. Name your platform in your chat reply and in the file name you return — never as a byline inside the post, which FILE A does not allow. One shot: no follow-up questions — flag unresolvables inline.
The moment
A text just landed saying a package is held, a toll is overdue, or a traffic fine needs paying before a deadline. Maybe you haven't touched it; maybe you tapped, typed something, and the page didn't sit right. You know texts like this exist. What you need is a clear way to check this one and decide what's next.
What this post offers
Below are eight copy-paste prompts that turn your AI assistant into a short working session on this text: what it asks for, how to check it through a channel you already trust, what to do about a request to reply, how to report it, and what to do in the next hour if you already acted. Each card explains how the AI reads the prompt and what its answer can't settle. You describe the message in your own words; the message and its link stay out of the chat, and the checking happens outside it.
The prompt cards
Eight prompts, each with what came back when we ran it.
The route — eight cards, three moves
Look · what the text is asking
Check · confirm it your own way
Act & keep · report, recover, make it a habit
Look · what the text is asking
Card 1: The first look
Use this when: A text about a package, toll or fine just arrived and you want to lay out what it is asking you to do before you do anything.
I received an unexpected text message. I am describing it in my own words instead of pasting it. I have left out any links, codes, phone numbers from inside the message, and personal details. My description: [PASTE YOUR OWN DESCRIPTION OF THE MESSAGE HERE — who it claims to be from, what it wants you to do, how fast, and whether it mentions an amount, a QR code, a case number or a reply. No links, codes or account details.] Working only from my description, please: 1. Summarise in one or two sentences what the message is asking me to do. 2. List each action it asks for or pushes toward (for example: tap, scan, reply, pay, enter details), and note any deadline or penalty it uses to create pressure. 3. Describe how a legitimate notice of this kind would usually reach me and what it would usually ask for, and say where my description differs. 4. Tell me plainly that you cannot determine from a description whether this message is genuine, and list what I would need to check directly with the organisation it names. Do not ask me to paste the message, a link, or any account information.
How the AI reads this prompt: The opening tells the AI it's working from a description, so it has no reason to ask for the link. Step 2 separates the actions from the pressure. Step 3's picture of a real notice comes from the AI's general knowledge, not your agency's current practice. Step 4 builds the limit in so the answer can't drift into a verdict.
What to do with the answer: Treat the list of actions as things you won't do from inside the text; the answer can't tell you whether you owe anything or whether a package is really held. The US Postal Inspection Service (updated May 2025) says USPS texts only customers who first requested tracking with a tracking number, and those texts contain no link. The FTC describes toll texts that borrow real program names and threaten late fees or a suspended registration (May 2026), and a newer fine version with a QR code, a state seal and a case number (April 2026).
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); no real agency, company or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “It says it is from "Ridgeline Tollway". It says I have a small unpaid toll and that I will get a late fee and my vehicle registration could be suspended if I do not pay by tomorrow. It tells me to reply Y and then tap a link to pay. It came from a number I do not recognise, and I do not remember driving on a toll road lately. I have not tapped or replied to anything.”
The response, as received — unedited
1. What the message is asking
It claims you owe a small unpaid toll to "Ridgeline Tollway" and tells you to reply Y and then tap a link to pay by tomorrow, or face a late fee and possible suspension of your vehicle registration.
2. Actions it pushes and the pressure it uses
- Reply "Y". Replying confirms your number is active and, on some phones, makes a link from an unknown sender tappable.
- Tap a link. This takes you to a page chosen by the sender, not one you looked up yourself.
- Pay. The payment page would ask for card or bank details, and probably personal details as well.
- Deadline: pay by tomorrow.
- Penalties: a late fee and possible suspension of your registration.
A trivial amount paired with a severe consequence and a very short deadline is a pressure pattern.
3. How a legitimate toll notice usually works, and where yours differs
Typical legitimate practice:
- Unpaid tolls are usually billed by post to the registered owner's address, using the number plate.
- If you have a toll account or transponder, notices come through that account or to the contact details you registered.
- A real notice normally identifies the vehicle and plate, the date, time and location of the toll, and an invoice or notice number.
- It usually gives weeks to pay or dispute, not a day.
- Registration consequences, where they exist, come only after repeated formal notices and are handled by the vehicle licensing authority.
- Toll agencies that do send texts generally send them only to people who signed up for them, and many state that they never request payment by text.
Where your description differs:
- It arrived as an unsolicited text from a number you don't recognise.
- You don't recall using a toll road recently.
- The deadline is one day, with an escalated threat straight away.
- It asks you to reply first and then tap a link, rather than directing you to an account or a mailed invoice.
- As you describe it, it gives no vehicle, date or location details.
These features closely match a widespread toll-payment text scam ("smishing").
4. What I can't determine, and what to check
I cannot determine from a description whether this message is genuine. What you describe has several hallmarks of a scam, but only the organisation itself can confirm whether you owe anything.
To check, find contact details yourself (an official website you search for, or a posted or printed customer service number), not anything in the text. Then verify:
- Whether a toll operator by that name exists and covers roads you could have driven on.
- Whether there is any unpaid toll against your number plate or toll account.
- If so, the date, location, amount, and notice or invoice number.
- Whether they send payment requests by text at all, and from what number.
- The real due date, any late fees, and the official ways to pay.
- Whether there is any hold or flag on your registration, which you can confirm with your vehicle licensing authority.
In the meantime, you've done the right thing by not replying or tapping. You can also block the number and report the text as spam through your phone or carrier; that's safe to do whether it turns out to be genuine or not.
A note from us, beside this response: the AI wrote “that's safe to do whether it turns out to be genuine or not”. The AI states this as settled. It can't know it for your phone or your sender: reporting sends details of the message to your carrier or the app maker, and blocking a sender that turns out to be real stops its later messages. Both are reasonable steps. Neither tells you whether anything is owed; the independent check does that.
What we found
It kept the limit the card builds in: "I cannot determine from a description whether this message is genuine." Just before that it leans hard ("These features closely match a widespread toll-payment text scam"), and most readers will hear the lean as the answer. Wrong one way, you set aside a real notice; wrong the other, you relax about a fake one. Its list of things to ask the agency covers both, so act on that. Its line that a reply makes the link tappable is the AI's own claim; we have not confirmed it, and none of the sources we read says it.
Check · confirm it your own way
Card 2: Plan the independent check
Use this when: You want to confirm the claim through a channel you already trust, using nothing from the message.
I got a text claiming to be from an organisation I may have an account with. I will NOT use any link, number, QR code or address from the text. Help me plan how to check the claim through channels I already trust. What the text claims, in my own words: [PASTE YOUR OWN DESCRIPTION HERE — which carrier, toll program or court it names and what it says you owe or must do. No links, codes or account details.] Please: 1. List the ways I could reach this organisation that do not depend on the text at all (for example: an app I already have, a bookmarked site, a statement or card I already hold, an address I type in myself), ordered from most to least independent of the text. 2. For each, tell me what to look for once I am there (account balance, notices, tracking status, case lookup). 3. Suggest the questions I should ask if I phone them. 4. Remind me that any official address or number you mention comes from your general knowledge and may be out of date, so I should confirm it from something I already trust. Do not tell me whether the text is genuine.
How the AI reads this prompt: The opening commits the session to channels outside the message. Step 1 ranks routes by distance from the text, putting what you already hold (an installed app, a card, a statement) ahead of anything you'd search for. Step 4 matters because an address the AI suggests is still secondhand.
What to do with the answer: Make the check yourself; the FTC (January 2025) says to contact the tolling agency by a number or website you know is real, and the FBI's IC3 (April 2024) says to check your account on the toll service's legitimate site. The FCC says toll operators typically don't text about overdue accounts, while E-ZPass Virginia (2025 notice) texts only from two published numbers — so the question is whether the text matches what your own agency says it sends. A familiar company name proves nothing (FTC, April 2025).
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); no real agency, company or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “It names a toll program called "Ridgeline Tollway" and says I owe a small unpaid toll, with a late fee and a possible registration suspension if I do not pay by tomorrow.”
The response, as received — unedited
Here is a plan for checking the claim without touching anything in the text.
1. Ways to reach them, most to least independent of the text
- Things you already hold. These are a toll transponder or its packaging, a past statement or invoice, a welcome letter, or an older email from when you opened an account. The website and phone number printed on these predate the text entirely.
- An app or bookmark you already have. Use a toll app installed before the text arrived, or a bookmark you saved yourself. Open it directly, not through any prompt or notification linked to the text.
- Your bank or card statement. If you have ever paid this toll program, the merchant name on past transactions shows who you actually deal with.
- Your state's vehicle registration agency (DMV or equivalent). Since the text mentions registration suspension, the agency that would do the suspending can tell you whether any hold exists. Reach it through a renewal notice or registration card you already have, or by typing the state government's address yourself.
- The state transportation department or toll authority's site, typed in yourself. Government sites list the toll programs that operate in the state and link to their official payment pages. This is slightly less independent because you are relying on typing the right address.
- A search engine, used carefully. This is the least independent option because ads and lookalike sites can sit at the top of results. Skip the sponsored results and cross-check the address against one of the sources above.
- In person. A toll authority customer service centre or DMV office works if one is near you.
2. What to look for at each
- Statement, transponder or letter: the exact name of the toll program you are enrolled in, and whether "Ridgeline Tollway" matches it. Also check your account number and the official contact details.
- App or bookmarked site: after logging in, check your account balance, unpaid tolls or violations, and any notices or messages. Check whether your plate and payment method are current. Many toll sites also have a "pay by plate" or violation lookup where you enter your plate number.
- Bank or card statement: check recent toll charges, any failed or declined payment, and the exact merchant name.
- DMV or registration agency: check your registration status and any holds, flags or pending suspensions on your vehicle.
- State toll authority site: check whether a program by that name exists in a state you have driven in, how it says it contacts customers about unpaid tolls, and any posted fraud alerts.
- Your own records: check whether you actually drove a toll road recently, and where.
3. Questions to ask if you phone
- "Is there any unpaid toll or violation tied to my licence plate [plate] or account [number]?"
- "If so, what are the date, location and amount, and what is the real due date?"
- "Have you sent me any notice recently, and by what method?"
- "Do you ever send payment requests by text message?"
- "What is your actual process and timeline before late fees or a registration hold apply?"
- "Is there any hold or pending action on my registration right now?"
- "What are the official ways to pay, if anything is owed?"
- "Where can I report a message I received that claims to be from you?"
Give them only what they need to look you up, such as your plate or account number. Since you placed the call to a number you trust, that is fine, but you should not need to read out full card details just to check a balance.
4. A caution about contact details
I do not recognise "Ridgeline Tollway" as a toll program, so I am not giving you an address or number for it. Anything I did offer would come from my general knowledge and could be outdated or wrong. Take any official address or phone number from something you already trust, such as a statement, your transponder, your registration paperwork or a government site you reach yourself.
As you asked, I am not offering a view on whether the text is genuine. The deadline in the text does not change the plan, because your account and registration status will show whether anything is owed.
A note from us, beside this response: the AI wrote “your account and registration status will show whether anything is owed.” The AI states this as settled. It can't know that: an account shows what has posted so far, and a toll billed by plate or held by another agency may not appear yet. Ask the agency directly, by a route you found yourself, whether anything is pending.
What we found
It ranked the routes as the card said it would: what you already hold first, a search engine near the bottom. It gave no address at all ("I am not giving you an address or number for it"), because our test name is invented. With a real program yours may offer one, and the card's own warning then applies. A wrong address typed by hand is how this plan fails one way; a long plan nobody finishes is how it fails the other. Start with the first route you have.
Card 3: The reply trap
Use this when: The text asks you to reply first — "Y", a keyword, even STOP — and you want to see that request for what it is.
A text I received asks me to reply before it does anything else. Here is my own description of what it asks me to send back and what it says will happen next, and whether I have already replied: [PASTE YOUR OWN DESCRIPTION OF THE REPLY REQUEST HERE — no links, codes or account details.] Please: 1. Explain, in general terms, why the sensible default is to treat any requested reply to an unexpected message as part of what the message is asking for, whatever the word, including STOP. 2. Tell me what I can do instead of replying: how to reach the organisation it names on my own, and how to report and remove the message without responding. 3. If my description says I already replied, list what to watch for next (for example, follow-up messages or calls) without assuming anything bad has happened. Keep to what the person receiving the message should do. Do not explain how such messages are built or sent.
How the AI reads this prompt: Step 1 reframes the reply as part of the ask, not a neutral first step. Step 2 swaps the reply for actions that route around the sender. Step 3 handles the already-replied case calmly, and the last line keeps the answer on your side of the message.
What to do with the answer: New York's Governor's office (February 2025) warned of fake E-ZPass texts, often from international numbers, that ask for a "Y" reply before sending a link, and the FCC advises not responding even when a message says to text STOP. If you already replied, treat anything further from that sender as part of the same request and go to Card 4.
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — a made-up situation; no real agency, company or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “The text says to reply Y to activate the payment link. It also says I can reply STOP to stop getting messages.”
The response, as received — unedited
From what you've described, the text asks you to reply Y to "activate the payment link" and offers STOP to opt out. You haven't said whether you've replied yet, so I've covered both cases.
1. Why any reply, including STOP, is part of what the message wants
- Any reply confirms your number is live. Whether you send Y, STOP, or anything else, the sender learns that a real person reads messages on this number. That alone can lead to more messages and calls.
- The offered words are the sender's choices, not yours. When a message is unexpected, both options were written by the same unknown sender. STOP only works as a real opt-out when the sender is a legitimate organisation honouring it, and you can't tell that from the message itself.
- A reply can be a step in a process. Here, the message itself says a reply "activates" a link. Replying is what moves you to the next stage, which is the stage where you would be asked to tap something or enter payment details.
- Not replying costs you nothing. If the message is genuine, the organisation has other ways to reach you and you can contact them yourself. If it isn't, silence gives the sender nothing.
So the sensible default is not to reply at all, and not to tap the link.
2. What to do instead
Reach the organisation on your own:
- Don't use any number, link, or reply option in the text.
- Find their contact details from a source you already trust: the back of your bank card, a bill or statement, their official app, or their website typed into your browser yourself.
- Ask them whether they sent the message and whether any payment is actually due on your account.
Report it without responding:
- In the US: forward the text to 7726 (SPAM), which goes to your carrier and not the sender. You can also report it at reportfraud.ftc.gov.
- In the UK: forward it to 7726 as well. Other countries have similar carrier or regulator reporting routes.
- On iPhone: use "Report Junk" under the message, or open the message options and report it.
- On Android (Google Messages): press and hold the conversation, then choose Block and report spam.
- The named organisation: many have a dedicated address or page for reporting suspicious messages, and they'll often want to know.
Remove it:
- Block the sender's number through your messaging app.
- Delete the conversation once you've reported it. A screenshot beforehand is useful if you want a record.
3. If you have already replied
A reply on its own usually doesn't expose your money or accounts, so there's no need to assume the worst. Just be more alert for a while:
- More texts. These may include the "activated" link or new messages on a different theme. Don't tap links or reply further.
- Phone calls. Someone may claim to be from the named organisation, your bank, or a fraud team, possibly referring to the text. Hang up and call back on a number you find yourself.
- Requests for codes or details. Never share one-time passcodes, PINs, passwords, or card numbers with anyone who contacts you.
- Urgency. Deadlines, threats of fees, or warnings that an account will be suspended are a cue to slow down and check independently.
- Your accounts. Glance over bank and card statements for the next few weeks. Check your phone bill too, since some replies can incur charges.
If you went further than replying (tapped the link, entered card or login details, or made a payment), contact your bank or card provider straight away using the number on your card. Then change the password on any account whose details you entered.
A note from us, beside this response: the AI wrote “Not replying costs you nothing.” The AI says this as a fact. It can't know what silence costs in your case: a real notice left alone can still carry a real due date. The FCC's standing guidance is not to respond, even to STOP, so don't reply. Then confirm the claim yourself through a channel you already trust.
What we found
It treated any reply as part of the ask, STOP included. It went past the prompt with menu steps for iPhone and Google Messages and a UK reporting number; we have not confirmed those, and menu steps drift. One slip: "the back of your bank card" reaches your bank, not a toll agency or a carrier. If the text is fake, staying silent costs little. If it is real, silence without the independent check leaves a notice unanswered.
Act & keep · report, recover, make it a habit
Card 4: Report it and clear it
Use this when: You've decided not to act on the text and want a short, ordered routine for reporting and deleting it.
I have decided not to act on a text I received. Give me a short, ordered routine for reporting it and clearing it off my phone. Work from my description only. Who the text claimed to be, and what phone and messaging app I use: [PASTE YOUR OWN DESCRIPTION HERE — for example, "claims to be a toll agency; Android phone, Google Messages." No links, codes or account details.] Please give me a numbered routine of no more than six steps covering: - reporting it to my mobile carrier and through my messaging app, if it offers a report option; - any additional place to report it based on who the text claims to be (for example, a postal or government body); - what to capture before deleting, and why; - deleting it. For any reporting address or number, tell me to confirm it on that organisation's own site, because your information may be outdated. If you are unsure what my messaging app does when I report something, say so and point me to the app maker's own help page instead of guessing at menu steps.
How the AI reads this prompt: The first line tells the AI the decision is made, so it spends the answer on the routine. The six-step cap keeps it finishable. Tying extra reporting to who the text claimed to be fits the answer to this message, and the last lines stop it from inventing menu paths.
What to do with the answer: The FTC (January 2025) says to forward these texts to 7726 (SPAM); the Postal Inspection Service (updated May 2025) takes USPS-themed texts at spam@uspis.gov with a screenshot showing sender number and date; ReportFraud.ftc.gov (FTC standing guidance) and ic3.gov (FBI IC3, April 2024) also take reports. Google's own help page says reporting spam in Google Messages sends the sender's number to Google, can include the last 10 messages from that sender (you choose), and may send your carrier the number plus the most recent message.
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); the phone and messaging app named are real products, given as the reader’s own device; no real agency or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “Claims to be a toll agency called "Ridgeline Tollway"; Android phone, Google Messages.”
The response, as received — unedited
Here is a routine, ordered so you capture the evidence before anything removes the message.
-
Capture it first. Without tapping any link, take a screenshot showing the sender's number or email address, the date and time, and the full message text including the link. The reports below ask for these details, reporting or blocking may move the message out of your inbox, and you will want a record if a related charge or follow-up scam appears later.
-
Report it to your mobile carrier. In many countries, including the US and UK, carriers accept spam texts forwarded to 7726 ("SPAM"). Confirm on your carrier's own website that this is the right number for them before forwarding.
-
Report it in Google Messages. The app has a report-spam option, usually offered together with blocking the sender. I'm not certain of the current menu steps or exactly what is sent to Google and your carrier when you use it. Rather than guess, follow the Google Messages Help page on reporting spam at support.google.com/messages.
-
Report it based on who it claims to be. I can't verify that "Ridgeline Tollway" is a real agency. If it is, find its official website through your own search (never through the link in the text) and use its fraud or contact page. If you can't find it, report to the toll or transport authority for your area instead.
-
Report it to the government fraud body. In the US, that is the FTC (ReportFraud.ftc.gov) and the FBI's Internet Crime Complaint Center (ic3.gov), which has handled toll-text scams. Elsewhere, use your national fraud or consumer-protection reporting service. Confirm the current address on that organisation's own site, as my information may be outdated.
-
Delete it. Once the reports are sent, delete the conversation from your inbox and from the "Spam & blocked" folder if it was moved there. Keep the screenshot for a few months in case you need to refer to it.
What we found
Six steps, capture first and delete last, and it declined to guess where the prompt told it to: "I'm not certain of the current menu steps". Then it names a "Spam & blocked" folder anyway; look for that on your own phone. The screenshot it asks for shows the link, so keep it out of any AI chat. Reporting a text that turns out to be real costs little; deleting one leaves you without its details. Make the independent check before step six.
Card 5: You already tapped, typed or paid
Use this when: You tapped the link, entered details or paid, and want the next hour laid out in order.
I responded to a text I now think was not genuine, and I want an ordered plan for the next hour. I will make every contact myself. I have not included any card numbers, account numbers, passwords, codes or ID numbers, and I will not share them here. What I did, in my own words (for example: only tapped the link / typed my name and address / typed card details / paid by credit card / paid by debit card / typed a password / gave my Social Security number / replied): [PASTE YOUR OWN DESCRIPTION OF WHAT YOU DID HERE — no card numbers, passwords, codes or ID numbers.] Please: 1. Put the contacts I need to make in priority order, based only on what I did, and say who each one is (for example: my card issuer, my bank, the account whose password I typed). 2. For each contact, tell me how to reach them without using anything from the text (for example, the number printed on my card, or a site I type in myself). 3. List what to have ready before each call (dates, amounts, what I typed) without asking me to share any of it with you. 4. List what to watch for over the following weeks. 5. Do not promise any refund or outcome; tell me which questions only my card issuer or bank can answer.
How the AI reads this prompt: The opening says you do the contacting and sensitive numbers stay out of the chat. Step 1 ties the order to what you did, so a tapped-only case doesn't get a payment plan. Step 3 prepares each call without pulling your details in. Step 5 keeps the AI from promising what only your issuer decides.
What to do with the answer: The FTC's standing guidance: a credit card payment goes to the issuer immediately, on the number on the back of the card (debit: your bank or credit union); a typed password gets changed with two-factor authentication on; a Social Security number goes to IdentityTheft.gov. The CFPB says you aren't responsible for unauthorized credit card charges when only the number was stolen — whether a payment you typed yourself counts is your issuer's call — and says to report debit card charges within 60 days of the statement. It also notes thieves sometimes run a small charge first, so watch for small unfamiliar ones.
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — a made-up situation; no real agency, company or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “About 30 minutes ago I tapped the link in a text about an unpaid toll, typed my name and home address on the page it opened, and typed in my credit card details. I did not enter any password. I have not replied to the text.”
The response, as received — unedited
Plan for the next hour
Based on what you did, the exposed items are your credit card details and your name and home address. No password was entered, so no account password needs changing.
1. Your credit card issuer (do this now)
This is the only urgent call, because the card details are the one thing that can be used right away.
How to reach them:
- Call the number printed on the back of the physical card.
- Or open the issuer's app you already have installed, or type the issuer's web address yourself, and use the lock/freeze card feature while you wait on hold.
Have ready:
- The card itself.
- The approximate time you entered the details (about 30 minutes before you wrote this).
- Exactly what you typed: name, home address, card number, and whether you entered the expiry date and security code.
- Whether the page showed a payment amount, and how much.
- Your last few genuine purchases, so you can tell real charges from unfamiliar ones.
- Pen and paper for the representative's name, the time of the call and any reference number.
What to say: "I entered my card details on a fraudulent website after a phishing text. I want the card blocked and replaced, and I want to review recent and pending transactions."
If a one-time code arrived by text or in your app around that time: tell them, and say whether you typed it into the page. A code can be used to add your card to a digital wallet, so ask whether the card was added to any wallet or device.
2. Your phone (5 minutes, after the call)
- Close the tab and do not reopen the link.
- Do not reply to the text. Take a screenshot before deleting it, in case the issuer wants it.
- If the page asked you to download or install anything, or to allow a profile or notifications, remove it and mention it to the issuer. If it didn't, tapping the link alone is usually low risk.
3. Reporting (this hour or later today)
These assume you are in the US.
- Your mobile carrier: forward the text to 7726 (SPAM), then use your messaging app's "report junk" option.
- FTC: type reportfraud.ftc.gov yourself.
- FBI Internet Crime Complaint Center: type ic3.gov yourself. It asks for the sender's number and the web address in the text, which you can read off the screenshot without tapping.
Have ready the date and time of the text, the number it came from, and what you entered.
4. The real toll agency (optional, not urgent)
Only if you want to confirm whether you actually owe a toll. Type the official website of your state's toll agency yourself, or use the number on a past statement or your transponder paperwork.
5. Credit bureaus (optional, this week)
A name, address and card number are usually not enough to open new accounts, so this is a precaution. You can place a free fraud alert by contacting one bureau, which notifies the others. A free credit freeze must be placed with each of Equifax, Experian and TransUnion separately. Type each bureau's web address yourself.
What to watch for over the following weeks
- Card statements: check every charge, including very small "test" amounts, on this statement and the next two or three.
- Recurring payments: update the card number with merchants you actually use once the new card arrives.
- Follow-up scams: these are likely, because the scammers have your name, address and phone number. Watch for calls or texts claiming to be your bank's "fraud department", a toll agency, a delivery company or a "refund recovery" service.
- Codes and passwords: your real issuer will not ask you to read out a one-time code or password, or to move money to a "safe account". If anyone calls, hang up and call the number on your card.
- Mail: watch for cards, bills or account letters you did not request, or a change-of-address confirmation.
- Credit reports: check them at annualcreditreport.com (type it yourself) for accounts or inquiries you do not recognize.
- More toll texts: treat them the same way, and do not tap.
Questions only your card issuer can answer
- Whether any charge has been attempted, is pending or has posted.
- Whether a charge will be reversed, and how long any dispute takes.
- Whether you will be responsible for any amount.
- Whether the card will be replaced with a new number, and when it arrives.
- Whether the card was added to a digital wallet.
- Whether they need anything in writing from you, and by what deadline.
- Whether they will add extra monitoring to the account.
I cannot predict any of those outcomes. Ask them directly and write down the answers.
A note from us, beside this response: the AI wrote “I entered my card details on a fraudulent website after a phishing text.” The AI wrote this line for you to say, as if the page were known to be fraudulent. It can't know that; it has only your suspicion. Call the issuer on the number on your card, as the FTC's standing guidance says to do after paying a scammer. Say what you did and why you doubt the page; let the issuer judge.
What we found
It ordered the contacts by what was done: the card issuer first, on "the number printed on the back of the physical card", and no password step because none was typed. If you call and the page was real, you have a replaced card and a toll still to pay. If you wait and it was fake, the cost is whatever gets charged meanwhile. Side statements such as "tapping the link alone is usually low risk" are the AI's own, and we have no source for them. It also says your issuer "will not ask" for a one-time code. It cannot know your issuer's practice; its point is about people who call you, so hang up and call the number on your card.
Card 6: Someone offers to get your money back
Use this when: After you report a text or lose money, someone contacts you offering to help recover it.
After I reported a scam text (or lost money to one), someone contacted me. I have not paid them or given them any information. Here is my own description of who they say they are, how they reached me, and what they want: [PASTE YOUR OWN DESCRIPTION OF THE CONTACT HERE — no names, links, codes or account details.] Please: 1. List what this contact is asking me to do or provide. 2. Tell me how to reach the organisation they claim to represent through a channel I find myself, not one they gave me. 3. List the questions I should ask that organisation to find out whether this contact is theirs. Do not tell me whether the contact is genuine; you cannot settle that from my description.
How the AI reads this prompt: It treats the new contact like the first text: asks to list, and a claim to check elsewhere. Step 2 keeps you off any number the contact supplied. The last line stops a verdict it has no basis for.
What to do with the answer: The FBI's IC3 (July 2026) warns of scammers impersonating IC3 after people report, and says IC3 never contacts individuals directly or asks for payment to recover funds. Don't pay or share anything while you check.
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — a made-up situation; no real agency, company or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “Someone phoned me saying they work for a recovery service and can get back the money I lost after I paid through a toll text. They want a fee up front and asked me to confirm my card details over the phone.”
The response, as received — unedited
1. What this contact is asking you to do or provide
- Pay a fee up front, before any money has been recovered.
- Confirm your card details over the phone, on a call they started, not one you made.
- Accept their identity on their word: they say they work for "a recovery service", but from your description you have no company name, registration, or written confirmation you have checked yourself.
- Accept that they know about your loss: they contacted you already knowing you paid through a toll text, without explaining how they got that information.
2. How to reach the organisation through a channel you find yourself
Do not use any phone number, link, email address or website the caller gave you, and do not call back the number that rang you.
- Get the exact name first. If they call again, ask for the full legal company name, registration or licence number, and the caller's name, then hang up without giving anything else. If they will not give a name, there is no organisation to check, and you can move straight to the next points.
- Look the company up independently. Search the official business register for your country or state and, if they claim to be regulated, the regulator's own register. Use the contact details listed there, not those on a site the caller pointed you to.
- Call your bank or card issuer on the number printed on the back of your card or on a statement. They are the ones who can actually dispute or reverse a card payment, and they can tell you whether any recovery firm is acting on their behalf.
- Contact the real toll operator using the website or number on an old paper bill, your account statement, or the official government transport page. Ask whether they use any recovery service.
- Contact the body you reported the scam to (police, national fraud reporting centre, consumer protection agency) through its official website, which you type in or find yourself. Ask whether they pass reports to outside companies.
3. Questions to ask
To the recovery company (via the contact details you found yourself):
- Does a person by this name work for you?
- Did your company call my number on this date and time?
- Do you have a case or reference for me, and how did you get my details?
- Do you charge an upfront fee, and do you ever ask for card details on an outbound call?
- What is your registration or licence number, and which regulator oversees you?
To your bank or card issuer:
- Have you instructed or do you work with any third-party recovery service on my case?
- Can I dispute the original toll-text payment directly with you, and what does that cost?
- Given that I gave my card details to the original text, should my card be cancelled and reissued?
- Is there any recent or pending activity on my account I should know about?
To the organisation you reported to:
- Do you share reports with private recovery companies?
- Would anyone ever phone me on your behalf asking for a fee or card details?
- Do you want me to report this call, and what details do you need?
To the regulator or business register:
- Is this company registered or authorised to offer money recovery services?
- Are there any warnings or complaints recorded against that name?
Until you have answers through those channels, keep doing what you have done so far: no payment and no card or personal details to the caller. Make a note of the number they called from, the date and time, and what was said, as the organisations above may ask for it.
A note from us, beside this response: the AI wrote “Look the company up independently.” It treats a register entry, and the company's own word about its caller, as checks. They cannot carry that much: whoever phoned you can also be behind the company and the listing you find. A company that exists and says the caller is theirs has not shown that your money comes back. The step that stands is the bank: call the number on your card, and pay no one a fee while you do.
What we found
It gave no verdict, as the prompt requires, and its most useful line points at your bank: "They are the ones who can actually dispute or reverse a card payment". Where it falls short: it lists the upfront fee without saying what such a fee can signal, and it sends you to ask the recovery company whether the caller is theirs. Read as too reassuring, this costs a second loss; read as too alarming, a call to your bank that you needed anyway.
Card 7 (small business): A payment rule for texts
Use this when: You run a small business, handle your own IT, and want a callback-and-approval rule for toll, fine or delivery-fee texts reaching company phones.
I run a small business and handle our own IT and payments. Help me write a short internal rule for texts that ask the business to pay a toll, fine, delivery fee or other charge. About our setup, in general terms: [PASTE YOUR OWN DESCRIPTION HERE — how many vehicles or company phones, who can approve payments, which toll or shipping accounts the business holds, how bills normally arrive. No names, links, codes, phone numbers or account details.] Draft a rule of no more than eight lines that: 1. Says no one pays, taps, scans or replies to anything from a text, whatever the amount or deadline. 2. Names who checks the claim and how: logging into the business's own toll or carrier account, or calling a number already on file, never one from the message. 3. Requires a second person's approval before any payment prompted by an unexpected message. 4. Says how staff report the text and who they tell. 5. Says what to do first if someone already paid or entered details. Write it in plain language staff can follow without training.
How the AI reads this prompt: Your setup description fits the rule to your approval chain and accounts. Steps 2 and 3 carry the core controls: a callback to a number already on file, and a second approver. The eight-line cap keeps it pinnable.
What to do with the answer: Add real names and numbers yourself, outside the chat, and walk the rule through with whoever holds a company phone. Whether a toll or fine is owed is settled only in the business's own account.
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); no real agency, company or person was named by us.
How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
What we typed in place of the brackets: “6 vans and 4 company phones. The owner and the office manager can approve payments. We use one toll program, called "Ridgeline Tollway", with a single fleet account that the office manager looks after.”
The response, as received — unedited
Rule: Texts asking the business to pay a toll, fine, delivery fee or other charge
- Never pay, tap a link, scan a code or reply to any text asking for money, whatever the amount or deadline.
- Do not delete the text. Take a screenshot and send it to the office manager the same day, then tell them in person or by phone; if they are away, tell the owner.
- The office manager checks the claim by logging into our own Ridgeline Tollway fleet account or the carrier's account, or by calling a number we already have on file.
- Never use a phone number, link or code from the message itself to check or pay.
- If the charge turns out to be real, a second approver (the owner or the office manager, whoever did not check it) must agree before any payment is made.
- Payments are only made through our own account or the number on file, never through the text.
- If you already paid or entered any details, call the office manager or owner straight away. Speed matters more than blame.
- They will first call the bank or card provider, using the number on the card or statement, to stop the payment and block the card, then change any password that was entered.
Two things to settle before you issue it:
- Cover for absence: if the owner and office manager are both unavailable, the rule should say payment simply waits. A real toll or fine can always wait a day.
- Numbers on file: keep a short list of the bank's, Ridgeline Tollway's and your carriers' phone numbers somewhere staff can find it, so lines 3 and 8 work under pressure.
A note from us, beside this response: the AI wrote “A real toll or fine can always wait a day.” The AI can't know that. A real notice carries whatever due date the agency or court set, and only the business's own account, or the agency reached on a number already on file, can say what it is. Keep the second approval, and look in the account the same day so the wait stays short.
What we found
Eight lines a van crew can follow, fitted to the setup we described. It added cover for when both approvers are away and a list of numbers on file; both are worth having. It never says where the business reports the text outside the company, and whether a payment can be stopped is the card provider's answer, not the rule's. A rule this strict will sometimes delay a real bill; a looser one lets a fake one through.
Card 8: A household check-first habit
Use this when: You want your household to share one simple habit, set up together in person, with each person at their own phone.
NO INPUT NEEDED I want to set up a simple household habit for unexpected texts about packages, tolls, fines or payments. We are sitting together, and each person will set things up on their own phone. Please give us: 1. A check-first habit of no more than four short steps that anyone in the household can remember, built around: don't tap, scan or reply; check through an app or site we already use; report and delete. 2. A short list of things each person can do on their own phone today (for example, bookmarking the real sites or installing the official apps for the toll accounts and carriers we use, and finding the phone's report-junk option), described generally rather than as menu steps. 3. One question each of us can ask ourselves before acting on any text. 4. A simple way for us to talk about these messages with each other when they arrive. Keep it plain and short. Do not claim this habit will stop every scam.
How the AI reads this prompt: Saying you are together, each at your own phone, points the answer at things each person does for themselves. The four-step cap keeps the habit memorable, and step 2 turns it into setup you finish in one sitting. The last line keeps the output honest about what a habit can do.
What to do with the answer: The FTC (July 2026) says talking about scams with friends and family is one of the best ways to fight fraud. Do the setup while everyone is in the room, each at their own controls, using each app maker's help page to see what a setting does.
Actual execution example — what came back when we ran this prompt
Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · no test data needed — the prompt was run exactly as written.
How to read what follows: we ran the complete prompt above, with nothing added, in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.
The response, as received — unedited
The household check-first habit
1. The habit: Stop, Check, Report, Delete
- Stop. Don't tap the link, scan the code, or reply, not even "STOP".
- Check. Open the app or bookmarked site you already use for that company and look at your account there. If nothing shows up, there is nothing to pay.
- Report. Use your phone's report-junk option on the message.
- Delete. Remove it so nobody taps it later by mistake.
2. What each person can do on their own phone today
- Install the official apps for the toll accounts, carriers, banks and payment services you use, and sign in once so they are ready.
- Bookmark the real sites for anything without an app, typing the address yourself or copying it from a bill or card.
- Find the report-junk option in your messaging app, so you know where it is before you need it. In many countries you can also forward scam texts to a reporting number; in the US it is 7726 (SPAM).
- Turn on your phone's filter for unknown senders or spam, if it has one.
- Save the real phone numbers for your bank and card issuer in your contacts, taken from the back of the card or a statement.
- Turn on delivery and payment notifications inside the official apps, so real alerts arrive there and not by a surprise text.
3. The one question
"Was I expecting this, and can I see it in my own account?"
If either answer is no, treat the text as junk.
4. How to talk about them
- Say it out loud or in the group chat. "Got a toll text, checking the app" is enough. Scammers often send the same message to several people, so one warning helps everyone.
- Share a screenshot, never a forward. A screenshot can't be tapped by accident.
- Ask before paying. Anyone can say "Can you look at this with me?" before acting on a message that asks for money or personal details.
- No blame. If someone tapped, replied or paid, they should say so straight away and nobody gives them a hard time. Speed matters more than embarrassment: call the bank on its real number and change any password you entered.
This habit won't catch every scam, and some messages will look very convincing. What it does is give you a pause and a second route to check, which is where most of these texts fall apart.
A note from us, beside this response: the AI wrote “If nothing shows up, there is nothing to pay.” The AI states this as a ruling. It can't know that nothing is owed: an app shows only what that one account holds, not a charge from an agency you have no account with, and a new notice may not appear at once. If the screen is empty and you're unsure, ask the agency on a number or site you already know is real.
What we found
Four steps a household can say out loud ("Stop, Check, Report, Delete"), setup that each person does on their own phone, and it closed as the prompt told it to: "This habit won't catch every scam". Its one-line rulings go further than a habit can. Lean on them and a real notice can get treated as junk; drop the habit and you are back to the tap it was meant to stop. Also: a shared screenshot can't be tapped, but a QR code in it can still be scanned.
Before you paste anything
Describe the message; don't paste it. Leave out the text's links, QR codes, phone numbers and case numbers, and remove personal details before anything goes into any AI: real names, addresses, tracking and account numbers, your own phone number, card numbers, one-time codes, passwords and government ID numbers. "A toll agency" and "my credit card" give the AI enough to help you plan.
When AI is the wrong tool
- Money or card details already handed over: call your card issuer or bank first, on the number printed on your card.
- A password typed on the page: change it at the real site, typed in yourself, and turn on two-factor authentication.
- A Social Security number given: go to the FTC's IdentityTheft.gov.
- A text threatening court: don't scan the QR code; the FTC (April 2026) says to use the court's own website or phone number, found independently. Only the court can say whether a case exists.
- Wanting to "check the link": don't open or paste it. Vendor research from Palo Alto Networks' Unit 42 (October 2025), counting web domains in its own DNS data rather than texts or victims, found most addresses tied to one large texting operation were live under a week, so a known-bad lookup often comes up empty. Go to the site you already know.
A note from us, beside this section: the Unit 42 research measured how briefly these web addresses stayed live, not what a lookup returns, so “often comes up empty” is the post’s own inference. Its advice, to go to the site you already know, stands either way.
Where this leaves you
You now have a repeatable way to go from "I just got this" to a plan for checking it, and who to call first if you already acted. Whether you owe anything is still answered in your own account, reached on your own — and you're better prepared to ask the right questions there.
Questions you might still have
The notes and the questions and answers on this page were drafted with AI and reviewed by the site’s owner before publishing. No reader sent the questions in, and neither the questions nor the answers are part of any AI response shown above. The answers describe the runs published above, as of 2026-10-03.
Your answer will differ — differ how?
We don't know yet in any measured way: each prompt was run once, and one run is one sample. Each was run on 2026-10-03, on Claude, without using the web. We can name where difference comes from: the product you use and its settings, whether it can look things up on the web, and what you describe. One difference we expect: our test agency is invented, so Card 2's example gave no address, and with a real name yours may. What each prompt asks for stays the same, because the prompt does. Whether your answer delivers it, we have not tested. What this can't settle is how far answers move; we have no re-runs.
Your examples use a toll agency you made up, so the AI had nothing to get wrong and politely declined to give an address. Mine will say E-ZPass or USPS and the AI will hand me a web address. Did you run that case, and what happened?
No. We did not run it, so we can't tell you what happened. Every example here was run once, on 2026-10-03, with made-up details (where an agency is named, it is invented) and without using the web, so that no real agency is described by an answer we publish. The price is the one you name: these examples never show the AI offering an agency's address. Yours may. Step 4 of Card 2's prompt is there for that moment: treat any address or number the AI gives as secondhand, and confirm it from something you already hold. What this can't settle is whether an address your AI gives is the right one.
"When AI is the wrong tool" says if I've handed over card details, call the bank first. Card 5 is a prompt for exactly that moment, and its example runs to seven sections. Which is it: do I open the chat or pick up the phone?
Pick up the phone. If card details or money have gone, the call to your issuer or bank, on the number printed on your card, comes before any chat; the FTC's standing guidance says to report it immediately, and Card 5's own example calls it "the only urgent call". The prompt earns its place after that call, or when you tapped or typed something else and can't tell what comes first. The example is long, and only its first section is urgent. What the chat can't settle is anything about the money; that answer belongs to your issuer.
In Card 6's example a caller wants a fee up front and my card details to 'recover' my money, and the AI's answer is to look the company up and ask them if the caller is theirs. The line under the card says the FBI's IC3 never asks for payment to recover funds. Why did you write a prompt that stops the AI from saying the obvious?
We didn't write it, and we don't edit it: the prompt is Claude's, published as received. The shortfall is real, though, and it is why our note sits under that card. The instruction to give no verdict held so firmly that the example lists the upfront fee, never says what such a fee can signal, and then sends you to ask the recovery company about its own caller. One run is one sample; yours may say more. Whatever it says: pay nothing, give no card details, and call your bank first, on the number on your card. The chat can't settle who the caller is.
I drove through another state once and I have no account, no app and no old statement with that toll agency. Every route in Card 2 starts with something I already hold, and Card 8's example says "if nothing shows up, there is nothing to pay." What do I do when I have nothing to open?
You are left with the less independent routes, and Card 2's example names them: your vehicle registration agency, reached from a renewal notice or registration card you do hold; that state's transportation or toll authority site, with the address typed in yourself; a search, used with care; or going in person. Treat an address from a search or from an AI as a claim, and compare it against a second source before you enter anything. Card 8's line about an empty screen does not fit your case; the note beside it says why. What this can't settle is whether you owe a toll.
Built the way every prompt post here is built: we brief, a platform writes, and its prompts and wording are published unedited — with a public note wherever we found it fell short. We never edit a prompt.

