A text says my package is stuck and my toll is unpaid :: Gemini

MONTH 2 :: POST 3 :: A.I. Prompts :: Gemini

A young woman in round glasses and a varsity jacket at a crowded desk, her phone set down beside her, pointing to one line on a long printed sheet as a small wide-eyed robot looks on. Curious, focused, checking before doing anything.

charades.net · prompt post

Gemini · assembled from its drafts

How this post was put together. Gemini wrote this post, but not in one go. Its first two drafts did not meet the standards every post here is held to, so we asked it to try again, twice. The third draft fixed most of what we raised but slipped on two things the second draft had got right. So we chose the best complete pieces from its second and third drafts and put them together, without changing Gemini’s wording. The label on each card says which draft it came from. On two cards the prompt comes from the second draft and the explanation under it from the third, which Gemini wrote for a slightly different version of that prompt; a separate AI review compared each explanation with the prompt above it before we used the pairing. Before publishing, we ran every prompt once, on Claude, not on Gemini; what came back appears beneath each card, unedited, with its run conditions. The parts we set aside, and why they could mislead a reader, are explained in “Five things we left out of a post — and why they could steer you wrong”.

Directions given to the A.I.

This is the topic brief sent to all three A.I.s, published so you can judge the answer against the ask. It was built 2026-09-28. Two standing instruction files went with it and are not shown here (the brief calls them FILE A and FILE B): the required post structure, and the audience, standards and forbidden list. The words below are unchanged; line breaks and formatting marks were turned into paragraphs, headings, lists and bold for the web. The numbered research notes are our working notes, gathered 2026-09-18 from the sources they name and not updated since. They were written for the A.I., not as advice to you, and not to the rules our own published words follow.

You are writing one complete blog post for a new section of charades.net. Two files are attached: FILE A (the exact structure your post must follow) and FILE B (the audience, voice, standards, and forbidden list that bind everything you write). Read both before writing.

THIS POST'S TOPIC: "A text says my package is stuck and my toll is unpaid"

A text has arrived about a stuck package, an unpaid toll, or a traffic fine, and the reader has not tapped anything yet — or has, and is now uneasy. Write to the person HOLDING THE PHONE. Your post gives them copy-paste prompts that turn their AI assistant into a short working session: sort out what the message is actually asking for, decide how to check it without using anything inside it, and know what to do next.

Cover the ground a real reader stands on:

  • The first look: prompts that work from the reader's own description of the message — who it claims to be from, what it wants them to do, and how fast — to lay out what kind of request this is and what a legitimate version of it would look like.
  • The independent check: prompts that help the reader plan how to confirm the claim through a channel they already trust — the carrier's or toll agency's own website or app, a number they look up themselves — never anything taken from the message.
  • The reply trap: some of these texts ask for a reply before they send a link (see the findings below). Prompts that help the reader recognise any request to reply — even 'STOP' — as part of the ask.
  • Reporting and cleanup: prompts that turn 'what do I do with this text' into a short, ordered routine.
  • If they already tapped, typed or paid: prompts that organise the next hour — who to contact first, in what order, and what to have ready — with the reader making those contacts directly.
  • The family habit: at least one card that helps the reader set up a simple household habit of checking first, which they set up together, in person, with each family member at their own phone.

Where verification belongs, say so plainly: What the carrier or toll agency actually sends, what an account actually owes, and whether a charge is real are checked in the agency's or company's own site, app or phone line, reached independently. The AI conversation prepares that check; it does not replace it.

ANGLE: a calm triage, not a lecture. The reader already knows scam texts exist. What they have never had is a repeatable way to go from "I just got this" to "here is how I check it, and here is what I do if I already tapped" — with their assistant doing the structuring.

Examples fit both households and small businesses; mark the small-business card or cards clearly. Label illustrative examples as illustrative.

SOURCE FINDINGS FOR THIS TOPIC

The findings below come from primary public sources, each listed with its publisher, date and link. Treat them as your starting ground:

  • Rest your post's factual claims on these first. Add others only from sources that meet FILE B's "which sources count" standard, named inline with a date.
  • Cite inline by the body and the date (for example, "the FTC, January 2025").
  • Where two findings disagree, say so in one sentence and do not pick a side.
  • Keep every figure with its date and with who was counted. Complaint totals are undercounts; never present them as how often something happens.
  • Prefer the practical guidance to the statistics. The reader needs the next step more than the size of the problem.
  • Some of these sources carry no date because they are standing guidance that does not go out of date. Cite those by publisher and do not invent a date.
  • Do not describe any fact in your post as verified, checked or confirmed.

--- SOURCE MATERIAL BEGINS — facts to write from. Do not reproduce its headings, its numbering or its layout in your post. ---

The 30 research notes sent with it, with their sources

FINDINGS FOR THIS TOPIC — gathered 2026-09-18

What the texts look like right now

1. A toll text arrives unexpectedly, claims an unpaid balance, often shows a dollar amount, and links to a page that asks for bank or card details.

Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam

In their words: "says you have unpaid tolls and need to pay immediately" … "might show a dollar amount for how much you supposedly owe" … "include a link that takes you to a page to enter your bank or credit card info"

2. The texts borrow the names of real toll programs and threaten late fees or a suspended vehicle registration.

Source: FTC, "New trends in reports of imposter scams" (2026-05-07) — https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams

In their words: "These bogus messages might spoof real toll collection programs (like EZ-Pass, SunPass, FasTrak, and TxTag) to seem more credible." … "they threaten to charge you late fees or suspend your vehicle's registration if you don't pay right away"

3. A newer variant (April 2026): a 'traffic violation' text with a QR code, a fake state seal and a fake case number, threatening court action.

Source: FTC, "That text about a traffic violation is probably a scam" (2026-04-14) — https://consumer.ftc.gov/consumer-alerts/2026/04/text-about-traffic-violation-probably-scam

In their words: "The text might look official with a seal from whatever state it claims to be from and a (fake) case number" … "to pay for a traffic violation to avoid court"

4. Some fake toll texts ask you to reply 'Y' first, then send the link. They often come from international numbers.

Source: New York State (Governor's office), "Governor Hochul Warns Consumers of E-ZPass Text Message Scam" (2025-02-16) — https://www.governor.ny.gov/news/governor-hochul-warns-consumers-e-zpass-text-message-scam

In their words: "These fake texts are often sent from an international number and request the consumer to reply with 'Y' to receive a link and contain an unofficial website."

5. Package texts usually impersonate the U.S. Postal Service; victims reported paying fake 'redelivery' fees.

Source: FTC, "Top text scams of 2024 (Data Spotlight)" (2025-04) — https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024

In their words: "Messages about package deliveries, usually from someone pretending to be from the U.S. Postal Service, were the most reported text scam last year." … "many people reported paying a small "redelivery fee""

Note: "Last year" = 2024 (FTC spotlight published April 2025).

6. The sender's number may be faked to look like a toll company, or may be an international number.

Source: FCC, "How to Spot and Avoid Toll Road Payment Scam Texts" (undated on page) — https://www.fcc.gov/consumer-governmental-affairs/how-spot-and-avoid-toll-road-payment-scam-texts

In their words: "The sender's number may be spoofed to look like it's from a toll company." … "The sender's number may be an international number."

Note: The FCC page carries no date. The international-number point matches the dated New York notice (Feb 2025).

Who actually texts you — and who doesn't

7. USPS does not text or email you unless you first asked for tracking with a tracking number — and those messages do not contain a link.

Source: US Postal Inspection Service, "Smishing: Package Tracking Text Scams" (last updated 2025-05-19) — https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams

In their words: "USPS will not send customers text messages or e-mails without a customer first requesting the service with a tracking number, and it will NOT contain a link."

8. New York's E-ZPass and Tolls by Mail say they will never text or email asking for personal, sensitive information.

Source: New York State (Governor's office), "Governor Hochul Warns Consumers of E-ZPass Text Message Scam" (2025-02-16) — https://www.governor.ny.gov/news/governor-hochul-warns-consumers-e-zpass-text-message-scam

In their words: "Consumers should know that E-ZPass, or Tolls by Mail, will never send a text or email requesting personal, sensitive information."

9. E-ZPass Virginia DOES send texts — but only from two published numbers. Anything else claiming to be them is not.

Source: E-ZPass Virginia (state toll operator), "Active smishing scam" (2025 (year in page address; no date on page)) — https://www.ezpassva.com/news-resources/news/2025/active-smishing-scam.html

In their words: "If you receive a TXT/SMS message that is not from (844) 548-0707 or (844) 718-2368, it is not from E-ZPass Virginia"

Before you tap — the checking habit

10. Don't tap the link and don't reply. Check with the toll agency or company using a phone number or website you already know is real — never the one in the text.

Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam

In their words: "Reach out to the state's tolling agency using a phone number or website you know is real — not the info from the text."

11. A familiar company name in the text proves nothing.

Source: FTC, "Is that unexpected text a scam?" (2025-04-16) — https://consumer.ftc.gov/consumer-alerts/2025/04/unexpected-text-scam

In their words: "Don't assume a text from a known company or organization is legit."

12. Check the balance yourself by logging into your own toll account on the agency's real website.

Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412

In their words: "Check your account using the toll service's legitimate website"

Note: Use this PSA for its guidance only; its complaint counts are more than two years old.

13. Don't reply even to 'text STOP'.

Source: FCC, "Avoid the Temptation of Smishing Scams" (undated on page) — https://www.fcc.gov/avoid-temptation-smishing-scams

In their words: "Do not respond, even if the message requests that you 'text STOP' to end messages."

14. For the QR-code version: don't scan it. Check the court's own website or phone number, found independently.

Source: FTC, "That text about a traffic violation is probably a scam" (2026-04-14) — https://consumer.ftc.gov/consumer-alerts/2026/04/text-about-traffic-violation-probably-scam

In their words: "don't respond, and don't scan the QR code" … "use a website or phone number you know is correct, not info from the text message"

Reporting it (takes under a minute)

15. Forward the text to 7726 (SPAM) or use the phone's 'report junk' option, then delete it.

Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam

In their words: "forward them to 7726 (SPAM)"

16. USPS-themed texts can also go to the Postal Inspection Service at spam@uspis.gov, with a screenshot showing the sender number and date.

Source: US Postal Inspection Service, "Smishing: Package Tracking Text Scams" (last updated 2025-05-19) — https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams

In their words: "spam@uspis.gov"

17. Report to the FTC at ReportFraud.ftc.gov; the FBI's IC3 (ic3.gov) also takes these.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412

In their words: "ReportFraud.ftc.gov"

18. What 'report spam' does in Google Messages: the sender's number goes to Google, the last 10 messages from that sender can go too (the user may choose), and the report may also send the carrier the number plus the most recent message.

Source: Google (platform documentation), "Report spam in Google Messages" (current help page) — https://support.google.com/messages/answer/9061432?hl=en&co=GENIE.Platform%3DAndroid

In their words: "The last 10 incoming messages from the spammer are reported to Google to improve spam detection when reporting a conversation as spam." … "You may decide to report those messages or not" … "this will send a copy of the spammer's number plus the most recent text message to your mobile carrier"

Note: Platform documentation, cited for a fact about that platform only. Apple's equivalent page could not be read by the tool, so no iPhone claim is made.

If you already tapped, typed or paid — the next hour

19. Paid by credit card: call the issuer right away using the number on the back of the card, and ask for the money back. Debit card: same, with your bank or credit union.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

In their words: "Report it to the credit card issuer immediately. Use the number on the back of your card" … "you were tricked into paying a scammer with a debit card: Report it to your bank or credit union immediately"

20. Card-number-only theft: federal rules say you aren't responsible for unauthorized credit card charges when only the number was stolen.

Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/

In their words: "You are not responsible for unauthorized charges if someone stole only your credit card account number."

Note: Scope: CFPB words this for STOLEN numbers. Whether a charge the reader typed in themselves counts as 'unauthorized' is a question for the card issuer — the post must not promise a refund.

21. Debit card: report unauthorized charges within 60 days of the statement, or you may owe later charges.

Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/

In their words: "report it within 60 days after your account statement is available"

22. Watch for small, unfamiliar charges — thieves sometimes test a card with a small charge, then come back for more.

Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/

In their words: "sometimes thieves process a small debit or charge against your account and return to take more"

23. Gave your Social Security number: go to IdentityTheft.gov for a recovery plan.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

In their words: "IdentityTheft.gov"

24. Typed a password on the fake page: change it and turn on two-factor authentication.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

In their words: "Turn on two-factor authentication"

25. General: secure your accounts and dispute any unfamiliar charges.

Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412

In their words: "If you clicked any link or provided your information, take efforts to secure your personal information and financial accounts. Dispute any unfamiliar charges."

The second scam that follows the first

26. After a report, people get contacted by fake 'FBI / IC3' agents offering to recover money. IC3 says it never contacts people directly and never asks for payment to recover funds.

Source: FBI IC3, "PSA: FBI Warns of Scammers Impersonating the IC3" (2026-07-20) — https://www.ic3.gov/PSA/2026/PSA260720

In their words: "IC3 will never directly communicate with individuals via phone, email, social media, phone apps, online chat, or public forums." … "IC3 will never ask for payment to recover lost funds"

The family habit

27. The FTC's own advice: talking about scams with friends and family is one of the best defences.

Source: FTC, "Talk to your friends and family to fight fraud" (2026-07-30) — https://consumer.ftc.gov/consumer-alerts/2026/07/talk-your-friends-and-family-fight-fraud

In their words: "One of the best ways to fight fraud is to talk about it."

How big is this — with the caveats attached

28. People reported $470 million lost to scams that started with a text in 2024 — more than five times the 2020 figure. The FTC itself says this is only a fraction of the real harm.

Source: FTC, "Top text scams of 2024 (Data Spotlight)" (2025-04) — https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024

In their words: "in 2024, people reported $470 million in losses to these scams, more than five times the 2020 number" … "this number likely reflects only a fraction of the actual harm"

Note: Population: reports filed with the FTC. The 'top text scams' ranking came from hand-coding a random sample of 1,000 2024 reports.

29. Reports of government-imposter scams rose 40% in 2025, 'thanks in part to' toll texts.

Source: FTC, "New trends in reports of imposter scams" (2026-05-07) — https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams

In their words: "reports of government imposter scams were up 40%, thanks in part to messages about overdue tolls"

Note: Who was counted: reports filed with the FTC, which are undercounts — never read as how often this happens. The source says "up 40%"; the year 2025 is the reporting year of that alert, not wording the FTC used.

30. One vendor tracked 194,345 web addresses tied to one texting operation since January 2024. USPS was the most-copied single brand (28,045); toll services were the most-copied category (nearly 90,000). About 71% of the addresses were live for under a week.

Source: Palo Alto Networks Unit 42 (vendor threat research), "The Smishing Deluge: China-Based Campaign Flooding Global Text Messages" (2025-10-23) — https://unit42.paloaltonetworks.com/global-smishing-campaign/

In their words: "194,345" … "28,045" … "nearly 90,000 dedicated phishing FQDNs" … "71.3% of these domains were active for less than a week"

Note: Who was counted: web domains seen in Palo Alto Networks' own DNS data (Oct 2025). It counts WEBSITES, not texts received and not people harmed. Practical meaning: a link can be brand-new, so 'look it up to see if it's known-bad' is weak — go to the site you already know instead.

Where these sources disagree

  • Do toll agencies text you at all? The FCC says toll operators "typically don't use text messages to collect on overdue accounts". E-ZPass Virginia does send texts, from two published numbers. Both can be true. Suggested one-line treatment for the posts: some agencies text their own customers, so the check is not 'did I get a text' but 'does it match what my agency says it sends'.

--- SOURCE MATERIAL ENDS ---

BOUNDARY (states the pack's own rule — do not cross it)

Do not write prompts that demonstrate, simulate, or explain how an attack or a scam is performed. Every prompt helps the reader assess, harden, verify, respond, or recover — nothing else. Do not claim any prompt makes the reader, their family, or their business safe; certainty claims are forbidden per FILE B. Do not write anything that shames the reader for what already happened. And per FILE B item 10: no prompt or advice for working a security question on someone else's behalf, secondhand — helping another person is taught first-hand only: the affected person at their own device, doing the work themselves, with the helper beside them or guiding them from a distance while they stay at their own controls. Write the at-a-distance case only where this post cannot do its job without it, and when you do, name it in a REMOTE-HELP FLAG line at the top of your chat reply, as FILE B describes. For this topic specifically: Do not compose example scam texts, even as illustrations, and do not reproduce real ones. Do not tell the reader to open, reply to, or scan anything in the message to "see" where it goes, and do not suggest the AI can check a link by visiting it. Do not have the reader paste the message or any link or address from it into the AI; they describe it in their own words, with links, codes and account details left out, and check it outside the chat. FILE A's example placeholder mentions pasting a suspicious message; for this topic, use a placeholder for the reader's own description instead, for example [PASTE YOUR OWN DESCRIPTION OF THE MESSAGE HERE — no links, codes or account details].

STRUCTURAL CHECKLIST (mirrors FILE A Part I — self-verify before returning)

Your post must contain, in order, with these exact ## headings:

  • [ ] Title options — exactly 3, each ≤ 80 characters, reader-voice
  • [ ] The moment — 2–4 sentences, no statistics
  • [ ] What this post offers — one paragraph
  • [ ] The prompt cards — 6 to 9 cards, each with: Use this when: · the complete prompt in a fenced code block with a [PASTE …] placeholder or the literal token NO INPUT NEEDED · How the AI reads this prompt: (2–5 sentences) · What to do with the answer: (1–3 sentences)
  • [ ] Before you paste anything — one paragraph (remove personal details — real names, addresses, tracking or account numbers, the reader's own phone number)
  • [ ] When AI is the wrong tool — non-empty (e.g. money or card details already handed over → the card issuer or bank first, using the number on the card; a Social Security number given → the FTC's IdentityTheft.gov)
  • [ ] Where this leaves you — 1–3 sentences, no achieved-state claims
  • [ ] Global: 800–1,800 words excluding code blocks · every statistic sourced and dated inline or omitted · no sections beyond the seven

Do not include execution examples, sample AI responses, or an FAQ — those are added after your draft is received, from real runs of your prompts.

RETURN FORM

One complete post, in markdown, following FILE A exactly. Name your platform in your chat reply and in the file name you return — never as a byline inside the post, which FILE A does not allow. One shot: no follow-up questions — flag unresolvables inline.

The moment

You are looking at a text claiming a package is delayed, a toll is unpaid, or you owe a traffic fine. The message demands immediate action and usually contains a link or a request to reply. You need a fast way to evaluate the request and plan your next steps without interacting with the sender or their links.

What this post offers

This post provides copy-paste prompts that turn your AI assistant into a short working session. You will describe the message in your own words to lay out what it is asking for and build a plan to check it independently. The AI prepares you for the verification process; it does not replace the check you must do directly with the agency or company.

The prompt cards

Seven prompts, each with what came back when we ran it.

The route — seven cards, three moves

Look · what the text is asking

Check · confirm it your own way

Look · what the text is asking

Card 1: The first look

From Gemini’s third draft

Use this when: A text arrives demanding payment or action for a package, toll, or fine, and you want to assess its structure.

I received a suspicious text message. I will describe it, but I will not paste any links, phone numbers, or account details.

[PASTE YOUR OWN DESCRIPTION OF THE MESSAGE HERE — no links, codes or account details]

Based on my description, break down this message into two areas:
1. What specific action is this sender trying to get me to take?
2. What urgency or threat is being used to force that action?
Then, outline what elements are missing compared to a legitimate physical billing statement.

How the AI reads this prompt: This instructs the AI to evaluate the psychological levers in your summary. It separates the sender's goal from the emotional hook. The AI will also establish a baseline for how real organizations typically handle billing or delivery notifications.

What to do with the answer: Use the AI's breakdown to step back from the demands. The FTC (May 2026) notes these bogus messages might spoof real toll collection programs and threaten to charge you late fees or suspend your vehicle's registration if you don't pay right away. According to the FTC (April 2025), messages about package deliveries, usually from someone pretending to be from the U.S. Postal Service, were the most reported text scam in 2024, with many people reporting paying a small 'redelivery fee'.

A note from us, beside this card: the AI’s picture of how real organizations send billing or delivery notices comes from its general knowledge, which may be out of date. Your agency’s or carrier’s own site or app is the authority on what they actually send.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “It says it is from "Ridgeline Tollway". It says I have a small unpaid toll and that I will get a late fee and my vehicle registration could be suspended if I do not pay by tomorrow. It tells me to reply Y and then tap a link to pay. It came from a number I do not recognise, and I do not remember driving on a toll road lately. I have not tapped or replied to anything.”

The response, as received — unedited

What you describe matches a very common toll-payment phishing scam ("smishing"). You were right not to tap or reply.

1. The action the sender wants you to take

There are two steps, and each serves a purpose:

  • Reply "Y". This confirms your number is active and monitored, which makes it more valuable for future scams. On some phones, links from unknown senders are disabled until you reply, so the reply also makes the link tappable.
  • Tap the link and "pay". The link almost certainly leads to a fake payment page. The small toll is not the goal. The goal is to capture your card number, expiry date, security code, name, address, and possibly login or ID details, which can then be used for much larger fraud.

2. The urgency or threat being used

  • A very short deadline. "Pay by tomorrow" is meant to stop you from checking the claim independently.
  • A financial penalty. The late fee makes paying a small amount now feel like the sensible choice.
  • An exaggerated legal consequence. Registration suspension is a serious outcome attached to a trivial debt. Real agencies do not go from a small unpaid toll to suspension in one day by text.
  • A small amount. A low figure lowers your guard, because it feels easier to pay than to investigate.

3. What is missing compared to a legitimate billing statement

A real toll notice, which usually arrives by post, would typically include:

  • Your identifying details: your name, mailing address, and licence plate number.
  • An account, invoice, or notice number you can quote when you contact the agency.
  • Details of the toll event: the date, time, location or toll plaza, and often a photo of your plate.
  • An itemised amount: the toll and any fees listed separately.
  • A reasonable timeline: usually weeks to pay, with further notices before any escalation.
  • Verifiable agency information: an official name, postal address, and published customer service contacts.
  • Several payment options: by post, by phone, in person, or through a website you go to yourself.
  • A dispute process: instructions for contesting the charge.
  • A plausible delivery channel: post to the registered owner's address, not a text from an unknown number asking for a reply.

You also don't remember using a toll road, so there is no underlying event for the bill to refer to.

What to do now

  • Do not reply, tap the link, or call any number in the message.
  • If you want to be sure, look up the toll agency's official website or phone number yourself and check for any balance there.
  • Report the text as junk or spam through your phone's messaging app or your carrier, then delete it and block the number.

A note from us, beside this response: the AI wrote “Real agencies do not go from a small unpaid toll to suspension in one day by text.” The AI states this as settled, and treats not remembering a toll road as meaning no toll exists. It cannot know what every agency does or where you drove. Some agencies do text their own customers; E-ZPass Virginia (2025) says it does. Ask the agency, using a phone number or website you know is real, as the FTC (January 2025) advises.

What we found

It did the job: it split what the sender wants (a reply, then a tap and a payment) from the pressure behind it, then listed what a paper bill carries that this text lacks. It also opened with a near-verdict, saying the description "matches a very common toll-payment phishing scam." That is a match to a pattern, not a finding about your text. Wrong one way, a real toll goes unpaid and fees grow; wrong the other, someone pays a fake page. It also says the link "almost certainly leads to a fake payment page"; it never saw the link. And its line that a reply makes the link tappable is the AI's own claim; we have not confirmed it.

Check · confirm it your own way

Card 2: The reply trap

From Gemini’s third draft

Use this when: The text instructs you to reply with a letter, number, or even "STOP" to proceed.

NO INPUT NEEDED

I received a text that asks me to reply with 'Y' or 'STOP'. Outline a clear policy for me to follow regarding unexpected texts that demand a reply. Include the specific actions I should take to document and dismiss the message without engaging.

How the AI reads this prompt: The AI provides a response protocol focusing on documentation and non-engagement rather than analyzing the attacker's systems. It gives you a clear rule for handling demands for a reply.

What to do with the answer: Follow the policy to ignore the demand. Do not respond, even if the message requests that you 'text STOP' to end messages, according to standing guidance from the FCC. New York State (February 2025) notes that fake texts are often sent from an international number and request the consumer to reply with 'Y' to receive a link.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · no test data needed — the prompt was run exactly as written.

How to read what follows: we ran the complete prompt above, with nothing added, in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

The response, as received — unedited

Policy for Unexpected Texts That Demand a Reply

Core rule

If you did not initiate the conversation and do not recognize the sender, do not reply. Not "Y," not "STOP," not anything.

Any reply, including "STOP," confirms that your number is active and monitored. For a legitimate business you signed up with, "STOP" works as intended. For a scammer, it marks your number as live and can increase the volume of messages you receive or get your number sold to other lists.

Step 1: Do not engage

  • Do not reply with any word, letter, or emoji.
  • Do not tap any link, even to "see what it is."
  • Do not call any number in the message.
  • Do not open attachments.

Step 2: Assess (30 seconds, without interacting)

Ask yourself:

  • Did I sign up for texts from this company or recently do business with them?
  • Is the sender a short code (5 to 6 digits) I recognize, or a random full-length number or email address?
  • Does the message create urgency, mention a package, payment, account problem, or prize?

If you believe it may be legitimate: do not use the text to respond. Go to the company's official website or app, or call the number on your card or statement, and check your account there.

If you recognize it as a subscription you actually signed up for: replying "STOP" is safe and is the right way to opt out.

Otherwise, treat it as spam and continue below.

Step 3: Document

  1. Take a screenshot showing the full message, the sender's number, and the date and time.
  2. Note the number separately if it is cut off in the screenshot.
  3. Save the screenshot in a dedicated folder or album (for example, "Spam texts") in case of later fraud or a pattern you need to report.

Step 4: Report

  1. Forward the message to 7726 (SPAM). This works with major US carriers and is free. Your carrier may reply asking for the sender's number; that reply is safe to answer.
  2. Use the built-in report option:
    • iPhone: tap "Report Junk" under the message, or "Delete and Report Junk."
    • Android (Google Messages): press and hold the conversation, then choose Block and report spam.
  3. Optional, for fraud attempts: report at ReportFraud.ftc.gov. If the text impersonates a specific company or bank, forward it to that organization's fraud or abuse address as well.

Step 5: Block and delete

  1. Block the sender's number.
  2. Delete the conversation.
  3. Move on. No further action is needed unless you interacted with it.

Step 6: Reduce future messages

  • Turn on spam filtering: iPhone (Settings > Messages > Filter Unknown Senders) or Android (Messages > Settings > Spam protection).
  • Check whether your carrier offers a free spam-blocking app or service.
  • Avoid entering your mobile number in web forms, contests, and checkout pages unless it is required.

If you already replied or tapped a link

  • Replied only: no immediate harm is likely. Expect more spam; block and report as above.
  • Tapped a link but entered nothing: close the page, clear your browser data, and make sure your phone's software is up to date.
  • Entered a password, card number, or personal information: change that password immediately (and anywhere else you reuse it), turn on two-factor authentication, call your bank or card issuer using the number on your card, and monitor your accounts. Consider a fraud alert or credit freeze if you gave out your Social Security number.

Quick reference

Situation Action
Unknown sender, demands a reply Do not reply. Screenshot, forward to 7726, block, delete.
Claims to be a company you use Do not reply. Verify through the official site, app, or phone number.
Subscription you knowingly signed up for Reply "STOP" to opt out.
Already clicked or shared information Change passwords, contact your bank, monitor accounts.

A note from us, beside this response: the AI wrote “replying "STOP" is safe and is the right way to opt out.” The AI states this as settled. It cannot know that your text really comes from the service it names. The FCC's standing guidance is not to respond, even to a request to text STOP, and the FTC (April 2025) says not to assume a text from a known company is legitimate. If you want to leave a list, the company's own site, app or customer line is a route that does not depend on the text.

What we found

The core rule is plain and matches the card: "do not reply. Not "Y," not "STOP," not anything." It then covers the screenshot, reporting, blocking and deleting. It goes past the card in three places: an exception for subscriptions you recognize, a carrier reply it calls "safe to answer", and "No further action is needed". From the text alone you can't tell who sent it, and deleting it does not tell you whether you owe anything. Reply to a fake and you have answered the sender; skip a real STOP and you get a few more messages.

Card 3: The independent check

From Gemini’s third draft

Use this when: You need a plan to confirm if you actually owe a toll, have a package pending, or face a fine.

I need to verify a claim about [INSERT: an unpaid toll / a stuck package / a traffic fine]. Create a checklist for me to locate the official contact information using only physical documents I already own, such as the back of my payment card, or websites I have manually bookmarked. Do not provide any search instructions or URLs.

How the AI reads this prompt: The AI shifts to process planning. It maps out how to bypass the text entirely and locate trusted portals. By forbidding the AI from providing URLs or search instructions, the prompt grounds your next steps in authoritative materials you already possess.

What to do with the answer: Check with the toll agency or company using a phone number or website you already know is real — never the one in the text, as advised by the FTC (January 2025). Some toll agencies do text their own customers, so the check is whether the message matches what your agency says it sends. E-ZPass Virginia (2025) does send texts, but only from two published numbers, whereas New York State (February 2025) states that E-ZPass or Tolls by Mail will never send a text or email requesting personal, sensitive information.

A note from us, beside this card: the number on the back of a payment card reaches your bank or card issuer, not a toll agency or delivery company. For those, use a phone number or website you already know is real — not the information in the text. If you already paid with a credit or debit card, report it right away: call the number on the back of that card, or log in to your card account online or through the app, and ask for your money back, as the FTC advises.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · test data all synthetic — a made-up situation; no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “an unpaid toll”

The response, as received — unedited

Here's a checklist for verifying an unpaid toll claim using only sources you already have and trust.

Before you start

  • [ ] Set the message, letter, or call that made the claim aside. Do not use any phone number, link, or QR code it contains.
  • [ ] Note the details it claims: amount, date, location, licence plate, and any reference or notice number. You will check these against the official record, not the other way round.

Find official contact details from physical documents

  • [ ] Toll transponder or tag: look at the device itself and its mounting sleeve for a printed customer service number.
  • [ ] Transponder welcome kit or account agreement: the original paperwork usually lists the agency's phone number and mailing address.
  • [ ] Past toll statements or invoices: paper statements you received before this claim arrived will show the agency's contact details and your account number.
  • [ ] Payment card: call the number on the back of the card you use for tolls. The issuer can confirm whether a toll charge was attempted, declined, or already paid, and can tell you how the legitimate merchant appears on your statement.
  • [ ] Bank or card statements: find an earlier toll charge you know was real and note the merchant name. Some statements print a merchant phone number beside it.
  • [ ] Vehicle registration and renewal notices: these carry the contact details of your motor vehicle agency, which can tell you whether a toll hold or violation is attached to your plate.
  • [ ] Rental or lease agreement: if the vehicle was rented or leased, the contract lists the company's number and explains how tolls are billed, often through the company rather than directly to you.
  • [ ] Insurance card or policy documents: useful if you need to confirm which vehicle and plate were on your policy on the claimed date.

Find official contact details from your bookmarks

  • [ ] Open your browser's bookmark list directly and select the toll agency or motor vehicle agency site you saved earlier.
  • [ ] Confirm the bookmark predates the claim. If you saved it recently, or cannot remember saving it, treat it as unverified.
  • [ ] Use the contact or account login page reached from that bookmark only. Do not follow any link from the message to get there.
  • [ ] If you have a bookmarked login for your bank or card issuer, use its secure messaging or listed phone number as a second route.

Cross-check before you call

  • [ ] Compare the number from at least two independent sources, such as the transponder and an old statement. Matching numbers are a good sign.
  • [ ] If the number or address in the claim differs from the ones on your documents, treat that as a warning sign.

When you make contact

  • [ ] Give your licence plate and account number, and ask whether any unpaid balance exists.
  • [ ] Ask them to confirm the notice or reference number from the claim.
  • [ ] If a balance is real, pay only through that call or your bookmarked account page.
  • [ ] Write down the date, the representative's name, and any confirmation number.

If the claim turns out to be false

  • [ ] Do not reply to the message or call the sender back.
  • [ ] Tell the agency you just spoke to, since they often track impersonation attempts.
  • [ ] If you already entered card details somewhere, call the number on the back of that card straight away.

If you have none of these documents for the relevant toll agency, the motor vehicle agency on your registration paperwork is the best fallback, since it can confirm whether anything is recorded against your plate.

What we found

It kept to the fence the prompt set: no web addresses, no search steps, only papers and bookmarks you already hold. Its useful addition is a test for bookmarks: "If you saved it recently, or cannot remember saving it, treat it as unverified." But it leans on toll paperwork many drivers lack, and we have not confirmed that its fallback, the motor vehicle agency, can answer a toll question everywhere. A dead end leaves a real toll unpaid; a list that works costs one phone call.

Act & keep · report, recover, make it a habit

Card 4: Reporting and cleanup

From Gemini’s third draft

Use this when: You have decided the text is suspicious and you want to clear it from your device while notifying the proper channels.

NO INPUT NEEDED

Provide a checklist for reporting a suspicious text message to a mobile carrier and to federal authorities, followed by instructions to delete the message from the device. Keep the steps ordered and direct.

How the AI reads this prompt: The AI organizes reporting mechanisms into a logical sequence. It translates your decision into a quick, repeatable workflow for logging the event and clearing the device.

What to do with the answer: Execute the routine. The FTC (January 2025) recommends you forward the text to 7726 (SPAM). For package texts, the US Postal Inspection Service (May 2025) advises sending a screenshot showing the sender number and date to spam@uspis.gov.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · no test data needed — the prompt was run exactly as written.

How to read what follows: we ran the complete prompt above, with nothing added, in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

The response, as received — unedited

Checklist: Reporting a Suspicious Text Message (U.S.)

Before you start

  1. Do not reply, click any links, or call any numbers in the message.
  2. Take a screenshot showing the full message, the sender's number or email, and the date and time.

Report to your mobile carrier

  1. Press and hold the message, then choose the option to forward it (on iPhone: More, then the forward arrow; on Android: the three-dot menu, then Forward).
  2. Forward it to 7726 (spells SPAM). This works for AT&T, Verizon, T-Mobile, and most other U.S. carriers, and it is free.
  3. When the carrier replies asking for the sender's number, send it back.
  4. If your messaging app offers it, also tap Report Junk (iPhone) or Block & report spam (Android / Google Messages).

Report to federal authorities

  1. File a report with the Federal Trade Commission at ReportFraud.ftc.gov. Include the sender's number, the message text, and the date received.
  2. If the message attempted fraud, impersonated a business or agency, or you lost money or shared personal information, also file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov.
  3. Optional: file an unwanted-text complaint with the FCC at consumercomplaints.fcc.gov.
  4. If the message impersonated a specific organization (your bank, the IRS, USPS, etc.), report it to that organization through the contact details on its official website, not anything listed in the text.

Block the sender and delete the message

  1. Block the number: open the conversation, tap the sender's name or number at the top, and select Block (iPhone: Info, then Block Caller; Android: three-dot menu, then Block).
  2. Delete the conversation:
    • iPhone: In the Messages list, swipe left on the conversation and tap the trash icon, then confirm. Then go to Filters (or Edit) > Recently Deleted, select it, and tap Delete to remove it permanently.
    • Android: In the Messages list, press and hold the conversation, tap the trash icon, and confirm.
  3. Keep your screenshot until your reports are submitted and confirmed, then delete it if you no longer need it.

If you already clicked a link or shared information

  • Change the passwords for any affected accounts and turn on two-factor authentication.
  • Contact your bank or card issuer right away if financial details were involved.
  • Visit IdentityTheft.gov for a recovery plan if you shared personal information such as your Social Security number.

What we found

Ordered and direct, as asked: screenshot, forward to 7726, report to the FTC, then block and delete. Its phone menu steps are general knowledge as of the run date, 2026-10-03, and menus move; option names last longer than paths. It leaves out something the post covers: after a report, anyone offering to recover your money is a new warning sign. The cost sits mostly on one side: deleting a text before asking the agency, which matters if the bill was real.

Card 5: Small business triage

Prompt from Gemini’s second draft · explanation from its third

Use this when: A text about a package or toll arrives on a company phone or references a business fleet vehicle. (Illustrative example for small business).

I am looking at a text claiming a package is delayed or a fleet vehicle has an unpaid toll for this service:

[PASTE THE VENDOR OR FLEET SERVICE NAME HERE — remove all tracking or account details first]

Provide a checklist for a small business to verify this claim through our existing vendor portals or fleet management accounts. Include a step for establishing this specific verification workflow with the team.

How the AI reads this prompt: The AI approaches the verification through a business operations lens. It emphasizes standardizing an internal check using established vendor relationships and fleet accounts rather than consumer methods.

What to do with the answer: Run the check through your actual vendor or fleet accounts. A familiar company name in the text proves nothing, per the FTC (April 2025). Palo Alto Networks Unit 42 (October 2025), analyzing web domains seen in their DNS data, tracked 194,345 web addresses tied to one texting operation and noted that 71.3% of these domains were active for less than a week. Because links are often brand-new, relying on security filters to catch them is insufficient; go straight to the vendor portal you already know.

A note from us, beside this card: the Unit 42 research counted how long these web addresses stayed live; it did not measure how often security filters catch them. The advice to go straight to the vendor portal you already know stands on its own.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · test data all synthetic — it names a made-up fleet vendor (“Harborline Fleet Services”); no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “Harborline Fleet Services”

The response, as received — unedited

Texts about unpaid tolls or delayed packages are one of the most common phishing ("smishing") formats, so treat this one as unverified until your own records confirm it. I can't confirm whether "Harborline Fleet Services" is a real company or one you do business with, so the checklist starts there.

Before anything else

  • Don't tap the link, reply, or call any number in the text. Replying "STOP" also confirms your number is active.
  • Take a screenshot showing the sender's number, the full message, and the time received.
  • Note who received it and whether it came to a company phone or a personal one.

Verification checklist

  1. Check whether the vendor exists in your records. Search your accounts payable system, vendor master list, and contracts for "Harborline Fleet Services." If you have never onboarded them, the claim is almost certainly fraudulent.
  2. Log in to the portal the way you normally do. Use a saved bookmark or type the address yourself, never the link in the text. Check for open invoices, notices, or messages matching the claim.
  3. Check your fleet management account. Look for a toll transaction, violation, or alert tied to a specific vehicle, plate, date, and location. A real toll claim will name these; a vague one is a red flag.
  4. Check the toll authority directly. Log in to your transponder account (E-ZPass, SunPass, FasTrak, or your regional equivalent) and search by plate for unpaid tolls or violations.
  5. Cross-check trip data. Confirm from telematics or GPS logs and driver assignments that the vehicle was actually on that road at that time.
  6. For a package claim, use your own tracking numbers. Pull them from your purchase orders or shipping account and check them on the carrier's official site.
  7. Call a known contact. Use the phone number from your contract or a past invoice, not the text, and ask whether they sent the message.
  8. Review the payment request itself. Urgent deadlines, threats of late fees, requests for card details by link, gift cards, or new bank details all point to fraud.

Decide and close out

  • If nothing matches: do not pay. Forward the text to 7726 (SPAM), report it at reportfraud.ftc.gov or ic3.gov, then block the number and delete the message.
  • If it matches a real charge: pay only through the portal or your normal accounts payable process, with the usual approvals.
  • If anyone clicked the link or entered information: tell IT immediately, change any affected passwords, and call your bank or card issuer if payment details were entered.

Set this up as a team workflow

  1. Name an owner. One person, with a backup, receives all suspicious payment or delivery messages, typically the fleet manager or accounts payable lead.
  2. Create one reporting channel. Use a shared inbox or chat channel where staff forward screenshots instead of acting on them.
  3. Write the rule down in one page. No payments or credentials from a text or email link, verification only through bookmarked portals and known contacts, and a second approver for any unscheduled payment or change to vendor payment details.
  4. Keep a verified contact list. List the official portal addresses and phone numbers for each vendor, toll authority, and carrier, and store it where the team can find it.
  5. Brief the team. Spend 15 minutes walking drivers, dispatch, and office staff through the rule, using this text as the example.
  6. Log each incident. Record the date, sender, claim, and outcome so you can spot repeat patterns.
  7. Review quarterly. Update the contact list and re-brief new hires.

A note from us, beside this response: the AI wrote “A real toll claim will name these; a vague one is a red flag.” Detail is not proof, and the AI cannot know what a fake text will leave out. The FTC (January 2025 and April 2026) describes fake texts that show a dollar amount, an official-looking seal and a case number. A text that names a plate, a date or a place still goes through your own accounts before anyone pays.

What we found

It began with the right admission: "I can't confirm whether "Harborline Fleet Services" is a real company or one you do business with." Every step after that runs through records the business already holds, and the team step is concrete: one owner, one place for screenshots, a one-page rule. It is long for a small shop. Wrong one way, a real toll on a company van sits unpaid; wrong the other, a technician pays from a link. It also calls a claim from a vendor not in your records "almost certainly fraudulent"; a name missing from your vendor list does not tell you whether a toll is owed on one of your vans.

Card 6: If you already tapped or typed

Prompt from Gemini’s second draft · explanation from its third

Use this when: You clicked a link or entered information before realizing the message was suspicious.

I interacted with a suspicious link in a text message. I may have entered the following type of information:

[PASTE THE CATEGORY OF INFORMATION YOU ENTERED HERE, e.g., "credit card number" or "password" — DO NOT paste the actual number or password]

Give me a prioritized, step-by-step checklist for the next hour to address this specific exposure. Focus on the immediate actions required for the type of data I provided.

How the AI reads this prompt: The AI builds a fast-action recovery sequence based on the data type exposed. It prioritizes time-sensitive actions over general advice, keeping you focused on the immediate aftermath.

What to do with the answer: Use the list to organize your immediate next steps. If you typed a password on the fake page, the FTC (standing guidance) advises you to change it and turn on two-factor authentication. The CFPB (standing guidance) states you are not responsible for unauthorized charges if someone stole only your credit card account number — though whether a charge you typed in yourself counts as unauthorized is a question for the card issuer. For a debit card, report unauthorized charges within 60 days after your account statement is available.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · test data all synthetic — a made-up situation; no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “credit card number”

The response, as received — unedited

Here's what to do in the next hour, in order of priority. The goal is to cut off the card before it can be used, then check for damage.

Minutes 0-10: Shut the card down

  1. Lock or freeze the card now. Open your bank or card issuer's official app (or log in by typing the address yourself) and use the "lock card" or "freeze card" option. This takes seconds and blocks most new charges while you do the rest.
  2. Call the issuer's fraud line. Use the number on the back of the card, not any number from the text message. Tell them: "I entered my card number on a phishing site." Ask them to:
    • Cancel the card and issue a new one with a new number.
    • Review recent and pending transactions with you.
    • Dispute anything you don't recognize.
    • Add a fraud alert or extra monitoring to the account.

Don't wait to see whether fraud appears. Report it now, because stolen card numbers are often tested or sold within minutes.

Minutes 10-25: Check for damage

  1. Review recent and pending transactions yourself. Look for small "test" charges ($1-$5), which often come before larger ones. Report anything unfamiliar to the issuer.
  2. Turn on transaction alerts. Set push or text alerts for all charges, or the lowest threshold available, on this account.
  3. Work out what else you entered. This changes what you need to do:
    • CVV, expiration date, or billing ZIP: the card can be used online, so replacing it (step 2) is essential.
    • Debit card PIN: tell the bank and change the PIN immediately. A debit card draws directly from your account and has weaker protections, so treat it as more urgent.
    • Online banking username or password: change the password now from a different, trusted device and enable two-factor authentication.
    • Social Security number, date of birth, or other identity details: place a free credit freeze with Equifax, Experian, and TransUnion.

Minutes 25-40: Secure the device and the message

  1. Don't interact with the message again. Don't reply or click anything else.
  2. Check your phone. If the link prompted you to download or install anything (an app, a profile, a file), delete it. On iPhone, look under Settings > General > VPN & Device Management for unknown profiles. On Android, check for recently installed apps. Then update the operating system.
  3. Close the browser tab and clear your browser's history and website data.
  4. Take a screenshot of the text (sender number, message, link) for your records, then report and delete it:
    • Forward it to 7726 (SPAM), which works for major US carriers.
    • Use "Report Junk" or "Block and report spam" in your messaging app.

Minutes 40-60: Close the loop

  1. Update automatic payments. List the subscriptions and bills tied to the old card so you can switch them when the new number arrives. Some issuers provide a virtual card number right away.
  2. Remove the old card from saved wallets and sites if the issuer doesn't update them automatically.
  3. File reports (optional, but useful if fraud occurs):
    • reportfraud.ftc.gov
    • ic3.gov (FBI Internet Crime Complaint Center)
  4. Write down what happened. Note when you clicked, what you entered, when you called the issuer, who you spoke with, and any case or reference number.

After the first hour

  • Check your statements every day for the next couple of weeks, then weekly for a few months.
  • Expect follow-up scams. People who entered data on a phishing page often get calls or texts from someone posing as the bank's fraud department. Your bank will never ask for your full PIN, password, or a one-time code. If someone contacts you, hang up and call the number on your card.
  • If you gave identity information beyond the card, check your credit reports for free at annualcreditreport.com.

In the US, credit card liability for fraud is capped at $50 by law, and most issuers waive it entirely. Debit card protection depends on how quickly you report, which is why the call in step 2 comes first.

If you tell me whether it was a credit or debit card and what else you entered (CVV, PIN, login details), I can narrow this down to your situation.

A note from us, beside this response: the AI wrote “In the US, credit card liability for fraud is capped at $50 by law, and most issuers waive it entirely.” This is the AI's own statement about the law, given without a source, and it is not a promise about your card. The CFPB's standing guidance is narrower: you are not responsible for unauthorized charges if someone stole only your credit card account number. Whether a number you typed in yourself counts is your issuer's decision. Ask on that first call.

What we found

It built the hour around what was typed in and put the right call first: the card issuer, on "the number on the back of the card, not any number from the text message." It overreaches at the end, on what the law will do for you. Relax because of that line and you could call late; read it as a promise and the issuer's answer could surprise you. It also scripts you to say you used "a phishing site"; it never saw the page. Tell the issuer what you typed and why you doubt the page. And it says your bank "will never ask" for a one-time code. It cannot know your bank's practice; its point is about people who contact you, so hang up and call the number on your card.

Card 7: The family habit

From Gemini’s third draft

Use this when: You want to establish a household routine where family members review suspicious texts together.

NO INPUT NEEDED

Provide a short framework for a household to use when someone receives an unexpected text about a fine or bill. The steps must include each person describing the text aloud without tapping anything, and then logging into their own account on their own device to check the status independently.

How the AI reads this prompt: The AI drafts a collaborative, in-person routine. It codifies the process of pausing and verifying into a shared family rule, ensuring each person manages their own device independently.

What to do with the answer: Practice the framework together. The FTC (July 2026) states that one of the best ways to fight fraud is to talk about it with friends and family.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by Gemini, run on Claude · no test data needed — the prompt was run exactly as written.

How to read what follows: we ran the complete prompt above, with nothing added, in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

The response, as received — unedited

The "Stop, Say, Check" Framework for Unexpected Fine or Bill Texts

The household rule: no one acts on a text about money alone, and no one acts from inside the text.

1. Stop: hands off the message

  • Do not tap links, call numbers in the text, reply, or scan any QR code.
  • Urgency ("pay within 24 hours," "final notice," "avoid suspension") is treated as a warning sign, not a reason to hurry.

2. Say: describe it aloud

The person who received it reads or describes the text aloud to another household member without tapping anything. Cover:

  • Who it claims to be from (toll agency, court, utility, bank, delivery service)
  • What it says you owe and why
  • The deadline or threat
  • What it wants you to do (click, call, pay, "confirm" details)

Saying it aloud slows things down, and a second person often spots what the first missed. If no one is home, call or tell a household member before doing anything else.

3. Check: verify independently, on your own device

The person whose name or account is involved logs into their own account on their own device to check the status.

  • Get there yourself: type the official web address, use the official app, or call the number on a real statement or the back of your card.
  • Never use a link, number, or login page supplied by the text.
  • Each person checks only their own account. No one shares passwords or logs in on someone else's phone.
  • No account with that organisation? Find its official contact details independently and ask.

4. Decide together

  • Nothing owed in the account: the text is fake. Go to step 5.
  • Something genuinely owed: pay it only through the official account or app you just logged into, never through the text.
  • Still unsure: wait. A real bill will still be there tomorrow, and it will also arrive by mail or appear in your account.

5. Report and delete

  • Forward the text to 7726 (SPAM) in the US, or use your phone's "Report Junk" option.
  • Block the sender and delete the message.
  • Tell the rest of the household so they recognise it if they get the same one.

If someone already tapped or paid

There is no blame, but tell the household immediately, because speed matters.

  • Call the bank or card issuer using the number on the card.
  • Change the password for any account whose details were entered, from a different device if possible.
  • Watch statements for the next few weeks.

Fridge version: Don't tap. Say it out loud. Check your own account, your own way. Decide together.

A note from us, beside this response: the AI wrote “Nothing owed in the account: the text is fake.” The AI cannot know this. An empty account screen tells you about that account only; a real charge may not show there, for instance if you have no account with that organization. If you are still unsure, ask the agency or company directly, using a phone number or website you already know is real, as the FTC (January 2025) advises.

What we found

Short enough to remember: stop, say it aloud, check, decide together. Both required steps are there, and so is the line that keeps a household habit alive: "There is no blame." The weak point is the decision step, which turns one empty account screen into a verdict. If that verdict is wrong, a real bill is deleted along with the text; its rule to pay only from your own account is aimed at the opposite error, paying a fake. It also says a real bill "will still be there tomorrow". It cannot know that: a real notice carries whatever due date the agency set.

Before you paste anything

Do not paste the text message, any links, or any addresses from it into your AI assistant. You must describe the message in your own words. Strip out any real names, addresses, tracking codes, or account numbers before writing your description.

When AI is the wrong tool

If you already entered your debit or credit card number, contact your bank or issuer immediately using the number on the back of your card. If you gave your Social Security number, go directly to IdentityTheft.gov. Beware of any follow-up messages claiming to be from investigators offering to recover your money; the FBI IC3 (July 2026) states that IC3 will never directly communicate with individuals via phone, email, or apps, and will never ask for payment to recover lost funds.

Where this leaves you

You are now better prepared to ask questions and plan your response before acting on an unexpected text. By setting up your verification steps in advance, you have a repeatable way to confirm claims using official, trusted channels.

Questions you might still have

The notes and the questions and answers on this page were drafted with AI and reviewed by the site’s owner before publishing. No reader sent the questions in, and neither the questions nor the answers are part of any AI response shown above. The answers describe the runs published above, as of 2026-10-03.

Your answer will differ — differ how?

We don't know yet; one run is one sample. Each example here was run once, as of 2026-10-03, on one product (Claude, model identifier claude-fable-5-1), in a fresh session that did not use the web, using made-up organization names. None was run on Gemini itself, though Gemini wrote the prompts, and none with a real agency's name. So expect differences from your product, from web access if yours has it, and from your own description. What this can't settle is how much an answer moves between two tries. We have no re-runs to compare.

Card 2 tells me not to reply, not even STOP. Then the example answer under it says replying STOP is 'safe and is the right way to opt out' for something I signed up for. Which one do I follow?

Follow the card: do not reply, not even STOP. That is the FCC's standing guidance, and the FTC (April 2025) says not to assume a text from a known company is legitimate. The example's exception only works if you can tell the text really comes from the service you signed up for, and from the text alone you can't; a fake can carry that name. If you want to leave a list, the company's own site, app or customer line is a route that does not depend on the text. What this can't settle: what happens after a STOP reply to any particular text. We have no measure of that.

Card 3's prompt bans searching and offers the back of my payment card as the place to find the number. Your own note says that number gets my bank, not the toll agency. I have no transponder and no old toll paperwork — so how do I actually find the agency's real number?

With no toll paperwork and no site you already know, this card does not get you there. You are right about the prompt: its one named example reaches your card issuer, not a toll agency. The example's fallback is the motor vehicle agency on your registration papers; we have not confirmed that every such agency can answer a toll question. What this can't settle: how to find an agency you have never dealt with. Our sources say to use a number or website you know is real, and they stop there.

The top of the post says two drafts failed your standards and the third slipped on things the second got right, and that on cards 5 and 6 the explanation was written for a different version of the prompt. Why is this good enough to publish — and what is different about the prompt I'm actually copying?

Because this site's only claim is that it shows how to talk to an AI about a security problem, and we judged that the pieces we kept do that. We don't claim the post is right. On cards 5 and 6 the prompt you copy is Gemini's second-draft wording, unedited, and those are the words we ran. The explanation under each was written for the third draft's version. Here are the main differences. In the third draft, card 5's prompt had no place for you to name the service, told the AI to use nothing from the text, and did not ask for a team step. Card 6's third-draft prompt asked for "the exact phone calls I need to make and settings I need to change"; the one you copy asks for "the immediate actions required for the type of data I provided". The explanations describe what both versions ask the AI to do, and a separate AI review compared each one with the prompt above it. The parts set aside are explained in “Five things we left out of a post — and why they could steer you wrong”.

Card 6 has me ask the AI for a checklist for the next hour after I typed my card number in. Further down you say that is exactly when AI is the wrong tool and I should call the bank immediately. So do I run card 6 or not?

Call first. If a card number went into that page, the issuer comes before any chat, using the number on the back of the card; the example's own first steps are to lock the card and call the issuer. Card 6 is for after that call, to organize the rest of the hour: what else you typed, what to watch, what to write down. Type the kind of detail only, never the detail. The line about a legal cap on losses is the AI's own statement; see the note beside card 6. What this can't settle is whether you get money back. That is your issuer's decision.

The examples keep landing on 'it's a scam' — card 1 says my text 'matches a very common' scam, card 7 says nothing owed in the account means 'the text is fake'. What if I really do owe the toll and it just isn't showing where I looked?

Then following the examples would cost you: an unpaid toll, and whatever fees your agency adds. Card 1's "matches" is a match to a pattern, not a finding about your text, and card 7's empty account screen tells you about that one account. The way to find out is the agency itself, through a phone number or website you already know is real, as the FTC (January 2025) advises. Do that before card 4's delete step, and keep the screenshot. What this can't settle: whether you owe anything. No answer on this page knows where you drove.

Built from our brief by Gemini, over three drafts. Its prompts and wording are published unedited; this post was assembled from its second and third drafts, as explained at the top. We never edit a prompt.

Previous
Previous

A text says my package is stuck and my toll is unpaid :: Claude

Next
Next

What happens to a post before you read it