A text says my package is stuck and my toll is unpaid :: ChatGPT

MONTH 2 :: POST 2 :: A.I. Prompts :: ChatGPT

A woman at a desk in a dim room, under a desk lamp, running her hands down a long paper printout while a small round robot leans in beside her to read the same page. Quiet, careful, one line at a time.

charades.net · prompt post

written by ChatGPT · prompts unedited

This post was written by ChatGPT from our standing brief. We never edit a platform’s prompts — a defect gets a public note or a re-request, never a quiet fix. Before publishing, we ran every prompt once, on Claude, not on ChatGPT; what came back appears beneath each card, unedited, with its run conditions.

Directions given to the A.I.

This is the topic brief sent to all three A.I.s, published so you can judge the answer against the ask. It was built 2026-09-28. Two standing instruction files went with it and are not shown here (the brief calls them FILE A and FILE B): the required post structure, and the audience, standards and forbidden list. The words below are unchanged; line breaks and formatting marks were turned into paragraphs, headings, lists and bold for the web. The numbered research notes are our working notes, gathered 2026-09-18 from the sources they name and not updated since. They were written for the A.I., not as advice to you, and not to the rules our own published words follow.

You are writing one complete blog post for a new section of charades.net. Two files are attached: FILE A (the exact structure your post must follow) and FILE B (the audience, voice, standards, and forbidden list that bind everything you write). Read both before writing.

THIS POST'S TOPIC: "A text says my package is stuck and my toll is unpaid"

A text has arrived about a stuck package, an unpaid toll, or a traffic fine, and the reader has not tapped anything yet — or has, and is now uneasy. Write to the person HOLDING THE PHONE. Your post gives them copy-paste prompts that turn their AI assistant into a short working session: sort out what the message is actually asking for, decide how to check it without using anything inside it, and know what to do next.

Cover the ground a real reader stands on:

  • The first look: prompts that work from the reader's own description of the message — who it claims to be from, what it wants them to do, and how fast — to lay out what kind of request this is and what a legitimate version of it would look like.
  • The independent check: prompts that help the reader plan how to confirm the claim through a channel they already trust — the carrier's or toll agency's own website or app, a number they look up themselves — never anything taken from the message.
  • The reply trap: some of these texts ask for a reply before they send a link (see the findings below). Prompts that help the reader recognise any request to reply — even 'STOP' — as part of the ask.
  • Reporting and cleanup: prompts that turn 'what do I do with this text' into a short, ordered routine.
  • If they already tapped, typed or paid: prompts that organise the next hour — who to contact first, in what order, and what to have ready — with the reader making those contacts directly.
  • The family habit: at least one card that helps the reader set up a simple household habit of checking first, which they set up together, in person, with each family member at their own phone.

Where verification belongs, say so plainly: What the carrier or toll agency actually sends, what an account actually owes, and whether a charge is real are checked in the agency's or company's own site, app or phone line, reached independently. The AI conversation prepares that check; it does not replace it.

ANGLE: a calm triage, not a lecture. The reader already knows scam texts exist. What they have never had is a repeatable way to go from "I just got this" to "here is how I check it, and here is what I do if I already tapped" — with their assistant doing the structuring.

Examples fit both households and small businesses; mark the small-business card or cards clearly. Label illustrative examples as illustrative.

SOURCE FINDINGS FOR THIS TOPIC

The findings below come from primary public sources, each listed with its publisher, date and link. Treat them as your starting ground:

  • Rest your post's factual claims on these first. Add others only from sources that meet FILE B's "which sources count" standard, named inline with a date.
  • Cite inline by the body and the date (for example, "the FTC, January 2025").
  • Where two findings disagree, say so in one sentence and do not pick a side.
  • Keep every figure with its date and with who was counted. Complaint totals are undercounts; never present them as how often something happens.
  • Prefer the practical guidance to the statistics. The reader needs the next step more than the size of the problem.
  • Some of these sources carry no date because they are standing guidance that does not go out of date. Cite those by publisher and do not invent a date.
  • Do not describe any fact in your post as verified, checked or confirmed.

--- SOURCE MATERIAL BEGINS — facts to write from. Do not reproduce its headings, its numbering or its layout in your post. ---

The 30 research notes sent with it, with their sources

FINDINGS FOR THIS TOPIC — gathered 2026-09-18

What the texts look like right now

1. A toll text arrives unexpectedly, claims an unpaid balance, often shows a dollar amount, and links to a page that asks for bank or card details.

Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam

In their words: "says you have unpaid tolls and need to pay immediately" … "might show a dollar amount for how much you supposedly owe" … "include a link that takes you to a page to enter your bank or credit card info"

2. The texts borrow the names of real toll programs and threaten late fees or a suspended vehicle registration.

Source: FTC, "New trends in reports of imposter scams" (2026-05-07) — https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams

In their words: "These bogus messages might spoof real toll collection programs (like EZ-Pass, SunPass, FasTrak, and TxTag) to seem more credible." … "they threaten to charge you late fees or suspend your vehicle's registration if you don't pay right away"

3. A newer variant (April 2026): a 'traffic violation' text with a QR code, a fake state seal and a fake case number, threatening court action.

Source: FTC, "That text about a traffic violation is probably a scam" (2026-04-14) — https://consumer.ftc.gov/consumer-alerts/2026/04/text-about-traffic-violation-probably-scam

In their words: "The text might look official with a seal from whatever state it claims to be from and a (fake) case number" … "to pay for a traffic violation to avoid court"

4. Some fake toll texts ask you to reply 'Y' first, then send the link. They often come from international numbers.

Source: New York State (Governor's office), "Governor Hochul Warns Consumers of E-ZPass Text Message Scam" (2025-02-16) — https://www.governor.ny.gov/news/governor-hochul-warns-consumers-e-zpass-text-message-scam

In their words: "These fake texts are often sent from an international number and request the consumer to reply with 'Y' to receive a link and contain an unofficial website."

5. Package texts usually impersonate the U.S. Postal Service; victims reported paying fake 'redelivery' fees.

Source: FTC, "Top text scams of 2024 (Data Spotlight)" (2025-04) — https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024

In their words: "Messages about package deliveries, usually from someone pretending to be from the U.S. Postal Service, were the most reported text scam last year." … "many people reported paying a small "redelivery fee""

Note: "Last year" = 2024 (FTC spotlight published April 2025).

6. The sender's number may be faked to look like a toll company, or may be an international number.

Source: FCC, "How to Spot and Avoid Toll Road Payment Scam Texts" (undated on page) — https://www.fcc.gov/consumer-governmental-affairs/how-spot-and-avoid-toll-road-payment-scam-texts

In their words: "The sender's number may be spoofed to look like it's from a toll company." … "The sender's number may be an international number."

Note: The FCC page carries no date. The international-number point matches the dated New York notice (Feb 2025).

Who actually texts you — and who doesn't

7. USPS does not text or email you unless you first asked for tracking with a tracking number — and those messages do not contain a link.

Source: US Postal Inspection Service, "Smishing: Package Tracking Text Scams" (last updated 2025-05-19) — https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams

In their words: "USPS will not send customers text messages or e-mails without a customer first requesting the service with a tracking number, and it will NOT contain a link."

8. New York's E-ZPass and Tolls by Mail say they will never text or email asking for personal, sensitive information.

Source: New York State (Governor's office), "Governor Hochul Warns Consumers of E-ZPass Text Message Scam" (2025-02-16) — https://www.governor.ny.gov/news/governor-hochul-warns-consumers-e-zpass-text-message-scam

In their words: "Consumers should know that E-ZPass, or Tolls by Mail, will never send a text or email requesting personal, sensitive information."

9. E-ZPass Virginia DOES send texts — but only from two published numbers. Anything else claiming to be them is not.

Source: E-ZPass Virginia (state toll operator), "Active smishing scam" (2025 (year in page address; no date on page)) — https://www.ezpassva.com/news-resources/news/2025/active-smishing-scam.html

In their words: "If you receive a TXT/SMS message that is not from (844) 548-0707 or (844) 718-2368, it is not from E-ZPass Virginia"

Before you tap — the checking habit

10. Don't tap the link and don't reply. Check with the toll agency or company using a phone number or website you already know is real — never the one in the text.

Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam

In their words: "Reach out to the state's tolling agency using a phone number or website you know is real — not the info from the text."

11. A familiar company name in the text proves nothing.

Source: FTC, "Is that unexpected text a scam?" (2025-04-16) — https://consumer.ftc.gov/consumer-alerts/2025/04/unexpected-text-scam

In their words: "Don't assume a text from a known company or organization is legit."

12. Check the balance yourself by logging into your own toll account on the agency's real website.

Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412

In their words: "Check your account using the toll service's legitimate website"

Note: Use this PSA for its guidance only; its complaint counts are more than two years old.

13. Don't reply even to 'text STOP'.

Source: FCC, "Avoid the Temptation of Smishing Scams" (undated on page) — https://www.fcc.gov/avoid-temptation-smishing-scams

In their words: "Do not respond, even if the message requests that you 'text STOP' to end messages."

14. For the QR-code version: don't scan it. Check the court's own website or phone number, found independently.

Source: FTC, "That text about a traffic violation is probably a scam" (2026-04-14) — https://consumer.ftc.gov/consumer-alerts/2026/04/text-about-traffic-violation-probably-scam

In their words: "don't respond, and don't scan the QR code" … "use a website or phone number you know is correct, not info from the text message"

Reporting it (takes under a minute)

15. Forward the text to 7726 (SPAM) or use the phone's 'report junk' option, then delete it.

Source: FTC, "Got a text about unpaid tolls? It's probably a scam" (2025-01-17) — https://consumer.ftc.gov/consumer-alerts/2025/01/got-text-about-unpaid-tolls-its-probably-scam

In their words: "forward them to 7726 (SPAM)"

16. USPS-themed texts can also go to the Postal Inspection Service at spam@uspis.gov, with a screenshot showing the sender number and date.

Source: US Postal Inspection Service, "Smishing: Package Tracking Text Scams" (last updated 2025-05-19) — https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams

In their words: "spam@uspis.gov"

17. Report to the FTC at ReportFraud.ftc.gov; the FBI's IC3 (ic3.gov) also takes these.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412

In their words: "ReportFraud.ftc.gov"

18. What 'report spam' does in Google Messages: the sender's number goes to Google, the last 10 messages from that sender can go too (the user may choose), and the report may also send the carrier the number plus the most recent message.

Source: Google (platform documentation), "Report spam in Google Messages" (current help page) — https://support.google.com/messages/answer/9061432?hl=en&co=GENIE.Platform%3DAndroid

In their words: "The last 10 incoming messages from the spammer are reported to Google to improve spam detection when reporting a conversation as spam." … "You may decide to report those messages or not" … "this will send a copy of the spammer's number plus the most recent text message to your mobile carrier"

Note: Platform documentation, cited for a fact about that platform only. Apple's equivalent page could not be read by the tool, so no iPhone claim is made.

If you already tapped, typed or paid — the next hour

19. Paid by credit card: call the issuer right away using the number on the back of the card, and ask for the money back. Debit card: same, with your bank or credit union.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

In their words: "Report it to the credit card issuer immediately. Use the number on the back of your card" … "you were tricked into paying a scammer with a debit card: Report it to your bank or credit union immediately"

20. Card-number-only theft: federal rules say you aren't responsible for unauthorized credit card charges when only the number was stolen.

Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/

In their words: "You are not responsible for unauthorized charges if someone stole only your credit card account number."

Note: Scope: CFPB words this for STOLEN numbers. Whether a charge the reader typed in themselves counts as 'unauthorized' is a question for the card issuer — the post must not promise a refund.

21. Debit card: report unauthorized charges within 60 days of the statement, or you may owe later charges.

Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/

In their words: "report it within 60 days after your account statement is available"

22. Watch for small, unfamiliar charges — thieves sometimes test a card with a small charge, then come back for more.

Source: CFPB, "Watch accounts closely when card data is hacked" (undated guidance) — https://www.consumerfinance.gov/consumer-tools/bank-accounts/watch-accounts-closely-when-card-data-is-hacked/

In their words: "sometimes thieves process a small debit or charge against your account and return to take more"

23. Gave your Social Security number: go to IdentityTheft.gov for a recovery plan.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

In their words: "IdentityTheft.gov"

24. Typed a password on the fake page: change it and turn on two-factor authentication.

Source: FTC, "What To Do if You Were Scammed" (undated guidance) — https://consumer.ftc.gov/articles/what-do-if-you-were-scammed

In their words: "Turn on two-factor authentication"

25. General: secure your accounts and dispute any unfamiliar charges.

Source: FBI IC3, "PSA: Smishing Scam Regarding Debt for Road Toll Services" (2024-04-12) — https://www.ic3.gov/PSA/2024/PSA240412

In their words: "If you clicked any link or provided your information, take efforts to secure your personal information and financial accounts. Dispute any unfamiliar charges."

The second scam that follows the first

26. After a report, people get contacted by fake 'FBI / IC3' agents offering to recover money. IC3 says it never contacts people directly and never asks for payment to recover funds.

Source: FBI IC3, "PSA: FBI Warns of Scammers Impersonating the IC3" (2026-07-20) — https://www.ic3.gov/PSA/2026/PSA260720

In their words: "IC3 will never directly communicate with individuals via phone, email, social media, phone apps, online chat, or public forums." … "IC3 will never ask for payment to recover lost funds"

The family habit

27. The FTC's own advice: talking about scams with friends and family is one of the best defences.

Source: FTC, "Talk to your friends and family to fight fraud" (2026-07-30) — https://consumer.ftc.gov/consumer-alerts/2026/07/talk-your-friends-and-family-fight-fraud

In their words: "One of the best ways to fight fraud is to talk about it."

How big is this — with the caveats attached

28. People reported $470 million lost to scams that started with a text in 2024 — more than five times the 2020 figure. The FTC itself says this is only a fraction of the real harm.

Source: FTC, "Top text scams of 2024 (Data Spotlight)" (2025-04) — https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024

In their words: "in 2024, people reported $470 million in losses to these scams, more than five times the 2020 number" … "this number likely reflects only a fraction of the actual harm"

Note: Population: reports filed with the FTC. The 'top text scams' ranking came from hand-coding a random sample of 1,000 2024 reports.

29. Reports of government-imposter scams rose 40% in 2025, 'thanks in part to' toll texts.

Source: FTC, "New trends in reports of imposter scams" (2026-05-07) — https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams

In their words: "reports of government imposter scams were up 40%, thanks in part to messages about overdue tolls"

Note: Who was counted: reports filed with the FTC, which are undercounts — never read as how often this happens. The source says "up 40%"; the year 2025 is the reporting year of that alert, not wording the FTC used.

30. One vendor tracked 194,345 web addresses tied to one texting operation since January 2024. USPS was the most-copied single brand (28,045); toll services were the most-copied category (nearly 90,000). About 71% of the addresses were live for under a week.

Source: Palo Alto Networks Unit 42 (vendor threat research), "The Smishing Deluge: China-Based Campaign Flooding Global Text Messages" (2025-10-23) — https://unit42.paloaltonetworks.com/global-smishing-campaign/

In their words: "194,345" … "28,045" … "nearly 90,000 dedicated phishing FQDNs" … "71.3% of these domains were active for less than a week"

Note: Who was counted: web domains seen in Palo Alto Networks' own DNS data (Oct 2025). It counts WEBSITES, not texts received and not people harmed. Practical meaning: a link can be brand-new, so 'look it up to see if it's known-bad' is weak — go to the site you already know instead.

Where these sources disagree

  • Do toll agencies text you at all? The FCC says toll operators "typically don't use text messages to collect on overdue accounts". E-ZPass Virginia does send texts, from two published numbers. Both can be true. Suggested one-line treatment for the posts: some agencies text their own customers, so the check is not 'did I get a text' but 'does it match what my agency says it sends'.

--- SOURCE MATERIAL ENDS ---

BOUNDARY (states the pack's own rule — do not cross it)

Do not write prompts that demonstrate, simulate, or explain how an attack or a scam is performed. Every prompt helps the reader assess, harden, verify, respond, or recover — nothing else. Do not claim any prompt makes the reader, their family, or their business safe; certainty claims are forbidden per FILE B. Do not write anything that shames the reader for what already happened. And per FILE B item 10: no prompt or advice for working a security question on someone else's behalf, secondhand — helping another person is taught first-hand only: the affected person at their own device, doing the work themselves, with the helper beside them or guiding them from a distance while they stay at their own controls. Write the at-a-distance case only where this post cannot do its job without it, and when you do, name it in a REMOTE-HELP FLAG line at the top of your chat reply, as FILE B describes. For this topic specifically: Do not compose example scam texts, even as illustrations, and do not reproduce real ones. Do not tell the reader to open, reply to, or scan anything in the message to "see" where it goes, and do not suggest the AI can check a link by visiting it. Do not have the reader paste the message or any link or address from it into the AI; they describe it in their own words, with links, codes and account details left out, and check it outside the chat. FILE A's example placeholder mentions pasting a suspicious message; for this topic, use a placeholder for the reader's own description instead, for example [PASTE YOUR OWN DESCRIPTION OF THE MESSAGE HERE — no links, codes or account details].

STRUCTURAL CHECKLIST (mirrors FILE A Part I — self-verify before returning)

Your post must contain, in order, with these exact ## headings:

  • [ ] Title options — exactly 3, each ≤ 80 characters, reader-voice
  • [ ] The moment — 2–4 sentences, no statistics
  • [ ] What this post offers — one paragraph
  • [ ] The prompt cards — 6 to 9 cards, each with: Use this when: · the complete prompt in a fenced code block with a [PASTE …] placeholder or the literal token NO INPUT NEEDED · How the AI reads this prompt: (2–5 sentences) · What to do with the answer: (1–3 sentences)
  • [ ] Before you paste anything — one paragraph (remove personal details — real names, addresses, tracking or account numbers, the reader's own phone number)
  • [ ] When AI is the wrong tool — non-empty (e.g. money or card details already handed over → the card issuer or bank first, using the number on the card; a Social Security number given → the FTC's IdentityTheft.gov)
  • [ ] Where this leaves you — 1–3 sentences, no achieved-state claims
  • [ ] Global: 800–1,800 words excluding code blocks · every statistic sourced and dated inline or omitted · no sections beyond the seven

Do not include execution examples, sample AI responses, or an FAQ — those are added after your draft is received, from real runs of your prompts.

RETURN FORM

One complete post, in markdown, following FILE A exactly. Name your platform in your chat reply and in the file name you return — never as a byline inside the post, which FILE A does not allow. One shot: no follow-up questions — flag unresolvables inline.

The moment

A text says your package is stuck, your toll is unpaid, or a traffic fine needs attention. Maybe you have not touched it, or maybe you already tapped, typed something, or paid and now want a clean plan. The useful question is not “Does this look scammy?” but “How do I check the claim without trusting the message itself?”

What this post offers

Below are copy-paste prompts that turn an AI assistant into a short triage session: describe what the text is asking, plan an independent check, handle reply requests, organize reporting, and decide what to do next if you already interacted with it. The AI helps structure the work; the carrier, toll agency, court, bank, card issuer, or other real organization settles the facts through a channel you reach independently.

The prompt cards

Eight prompts, each with what came back when we ran it.

Look · what the text is asking

Card 1: Sort out what the text is asking

Use this when: You have the text in front of you and want to separate its claims, demands, and pressure tactics without opening anything inside it.

I received a text about a package, toll, or traffic-related payment. Help me analyze only what I describe here.

Do not ask me to paste the message, a link, a QR code, a phone number, a tracking number, an account number, or any other identifier from it. Do not tell me to open, reply to, scan, or test anything in the message.

From my description, give me:
1. Who the text claims to be from.
2. What it says happened.
3. What it wants me to do.
4. What deadline, threat, fee, or consequence it uses.
5. What information or payment it appears to be trying to collect.
6. What a legitimate version of this situation would normally require me to verify outside the text.
7. A short list of things I should check independently before deciding what the message means.

Do not declare the message genuine or fraudulent. Work only from the description I give you.

[PASTE YOUR OWN DESCRIPTION OF THE MESSAGE HERE — no links, codes, phone numbers, tracking numbers, account details, or personal information]

How the AI reads this prompt: The first lines keep the analysis on your description rather than the message itself. The numbered steps make the AI separate the claim from the requested action and the pressure around it. The final instruction prevents a confident authenticity verdict from replacing the real-world check.

What to do with the answer: Use it as a checklist for what needs outside verification. Whether the package problem, toll balance, or traffic charge is real has to be checked with the organization itself through a site, app, or phone number you reach independently.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “It says it is from "Ridgeline Tollway". It says I have a small unpaid toll and that I will get a late fee and my vehicle registration could be suspended if I do not pay by tomorrow. It tells me to reply Y and then tap a link to pay. It came from a number I do not recognise, and I do not remember driving on a toll road lately. I have not tapped or replied to anything.”

The response, as received — unedited

Here is the breakdown, working only from what you described.

1. Who the text claims to be from

It claims to be from "Ridgeline Tollway", presented as a toll road operator or toll authority. It arrived from a number you do not recognise.

2. What it says happened

It says you have a small unpaid toll.

3. What it wants you to do

It asks for two steps: reply "Y", then tap a link to pay.

4. Deadline, threat, fee, or consequence

  • Deadline: you must pay by tomorrow.
  • Fee: a late fee will be added if you do not.
  • Consequence: your vehicle registration could be suspended.

The amount is small, while the consequence is large and the window is very short.

5. What information or payment it appears to be trying to collect

  • A reply: replying "Y" would confirm that your number is active and that someone reads its messages. On some phones, replying also makes a link in the message tappable when it was not before.
  • A payment: the link leads to a payment step, which would normally ask for card details, a billing name and address, and possibly vehicle or licence plate details.

You have not described the payment page itself, so the second point is what a "pay by link" step typically collects, not something you observed.

6. What a legitimate version would normally require you to verify outside the text

  • The operator: that a toll operator by that name exists and covers roads where you or your vehicle have been.
  • The toll record: that there is a specific toll, with a date, time, location and plate, recorded against your vehicle.
  • The notice method: how that operator sends unpaid toll notices. Many send them by post to the registered owner or through an existing toll account, so it is worth checking whether it uses text messages at all.
  • The registration consequence: registration suspensions are normally handled by the vehicle licensing authority through its own formal notices and timelines.

7. Things to check independently before deciding what the message means

  • Operator's official contact: find the website or phone number for that operator yourself (search engine, official government site, or a past paper statement) and look up any balance there using your plate or account.
  • Your toll account: if you have a transponder or toll account, log in the way you normally do and check for unpaid items.
  • Your own travel: you do not recall using a toll road lately. Check whether anyone else has driven your vehicle, or whether you used a rental car.
  • Licensing authority: check with your vehicle registration authority, through its official channels, whether there is any hold or pending action on your registration.
  • Postal mail: look for any paper notice about a toll.
  • Known alerts: see whether the operator or your local consumer protection agency has published guidance about text messages that use its name.

Several things you described do not match each other yet: an unrecognised number, no memory of a toll road, a one-day deadline, and a reply-then-tap sequence. The checks above are what would settle what the message is, and none of them require touching the text.

What we found

It answered in order and gave no verdict, as the card's last line asks. Hold two things loosely: that replying can make a link tappable is the AI's own claim, which we have not confirmed, and a search engine is a shakier route to the operator than a statement or app you already have. Trust the text wrongly and you may hand over card details; dismiss a real toll and late fees can grow. The agency's own records settle both.

Check · confirm it your own way

Card 2: Build the independent check

Use this when: You want a clean way to check the claim without using any contact information supplied by the text.

Help me build an independent verification plan for a text that claims I have a package problem, unpaid toll, or traffic-related charge.

I will describe the situation in my own words. Do not use or ask for any link, QR code, phone number, email address, tracking number, account number, case number, or other identifier from the text.

Create a short plan that tells me:
1. Which real organization I should check with.
2. Which account, statement, shipment history, toll history, or court record I should look at if I already have access to it.
3. How to reach the organization using a website, app, statement, card, or phone number I obtained independently.
4. What question I should ask once I reach that trusted channel.
5. What result would mean I need to keep investigating rather than assuming the text was right.

If different organizations have different texting practices, say that clearly instead of giving me a universal rule.

[PASTE YOUR OWN DESCRIPTION OF THE SITUATION HERE — no links, codes or account details]

How the AI reads this prompt: This prompt makes the assistant design the route to the real source of truth instead of inspecting the suspicious route. That matters because the FTC advised in January 2025 to contact a toll agency through a number or website you already know is real, not information from the text. It also leaves room for differences between organizations: New York said in February 2025 that E-ZPass and Tolls by Mail will not request sensitive information by text or email, while E-ZPass Virginia published specific numbers it uses for texts in 2025.

What to do with the answer: Follow the independently sourced route, not the message. The AI can organize the check, but only the organization’s own records can establish what your account, shipment, or case actually shows.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · test data all synthetic — it names a made-up toll program (“Ridgeline Tollway”); no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “It says it is from "Ridgeline Tollway". It says I have a small unpaid toll and that I will get a late fee and my vehicle registration could be suspended if I do not pay by tomorrow. It tells me to reply Y and then tap a link to pay. It came from a number I do not recognise, and I do not remember driving on a toll road lately. I have not tapped or replied to anything.”

The response, as received — unedited

Good call not replying or tapping. A small amount, a next-day deadline, a registration threat, an unknown number, and "reply Y then tap a link" are the standard pattern of toll-scam texts. The "reply Y" step is often there because some phones disable links from unknown senders until you reply.

Here is a plan that does not use anything from the text.

1. Which real organization to check with

  • I can't confirm that "Ridgeline Tollway" is a real toll operator, so first establish whether it exists. Look on your state department of transportation's website (typed in yourself or found by search) for its list of toll roads and operators.
  • If it does exist, the organization to check with is that operator, or the tolling agency that bills for it.
  • If it doesn't exist, or it operates somewhere you and your vehicle haven't been, that largely answers the question.
  • The only body that can actually suspend a registration is your state's motor vehicle agency (DMV or equivalent), so it is your second check.

2. Which records to look at

  • Transponder account: if you have one (E-ZPass, SunPass, FasTrak, TxTag or similar), check its transaction history and balance.
  • Card and bank statements: look at the card linked to any toll account for recent toll charges or failed payments.
  • Your vehicle's whereabouts: consider whether anyone else drove it, or whether you used a rental car, in the past few months.
  • Paper mail: check for a toll invoice or notice addressed to the registered owner.
  • Registration status: check it in your DMV's online portal if you have access.

3. How to reach them independently

  • Use the toll agency's official app or website, reached from your own bookmark, the app store, or the state transportation site.
  • Or use the phone number printed on your transponder, a past paper statement, or the agency's official site.
  • For the DMV, use the state's official website or the number on your registration paperwork.

4. What to ask

  • Toll agency: "Are there any unpaid tolls or violations tied to my licence plate or my account? If so, what are the date, location and amount, and was a notice mailed?"
  • Toll agency: "Do you ever send text messages about unpaid tolls, and do they include payment links?"
  • DMV: "Is there any hold, flag or pending suspension on my registration?"

5. Results that mean you keep investigating

  • A real unpaid toll exists: the text may still be fake, because scammers send these in bulk and some land on people who owe tolls. Pay only through the official channel you reached yourself.
  • A toll exists that you don't recognise: ask for the plate image and details. It could be a misread plate, a cloned plate, or someone else driving your car, and you can dispute it.
  • "Nothing found", but you recently drove a rental or in another state: check with the rental company and that state's toll agency before closing it out.
  • The agency can't look you up by plate: ask how unbilled tolls are notified, and watch your mail for a few weeks.
  • Nothing anywhere: treat the text as fraudulent.

Texting practices differ
There is no universal rule. Many toll agencies say they never text about unpaid tolls and bill only by mail. Others do send texts or emails to account holders who opted in, usually as account alerts rather than payment demands. That is why the second toll-agency question in step 4 matters.

If it turns out to be fake
Don't reply. Use your phone's "report junk" option or forward the text to 7726 (the US carrier spam line), then delete it. In the US you can also report it to the FTC or the FBI's IC3.

A note from us, beside this response: the AI wrote “Nothing anywhere: treat the text as fraudulent.” The AI treats an empty search as an answer about the text. It cannot know that: finding nothing tells you only about the places you looked. A toll not yet billed, or held by another agency, would not show there. Ask the agency itself, by a route you found yourself, whether anything is pending and what it sends by text.

What we found

The plan arrived, and it caught something easy to miss: a real unpaid toll does not make the text real. But this card does not forbid an opinion, so the AI gave one. Its "Many toll agencies say they never text" is also firmer than what we read: the FCC's standing guidance says "typically", and E-ZPass Virginia (2025) does text its customers. Pay from the text and you may hand over card details; dismiss it too soon and a real toll keeps growing.

Card 3: Treat “reply first” as part of the request

Use this when: The text asks you to reply before it gives you more information, a link, or payment instructions.

I received a text that wants me to reply before it gives me the next step. Help me evaluate that request without replying.

Do not ask me to send the exact message or any number, link, code, or identifier from it.

From my description:
1. Identify what the reply is supposed to trigger.
2. Explain why the reply itself should be treated as part of the message's request, not as a harmless preliminary step.
3. Give me a no-reply way to check the underlying claim through the real organization.
4. Tell me what information I need to gather from my own records before I contact that organization.
5. End with a two-sentence decision rule I can reuse the next time a text asks me to reply first.

[PASTE YOUR OWN DESCRIPTION OF THE REPLY REQUEST HERE — no links, codes or account details]

How the AI reads this prompt: The prompt makes the requested reply part of the transaction you are evaluating, rather than a neutral step. New York warned in February 2025 about fake toll texts that asked people to reply “Y” before receiving a link, and the FCC’s standing smishing guidance says not to respond even when a message asks you to text “STOP.”

What to do with the answer: Use the no-reply path the AI lays out and check the underlying claim independently. Do not use the AI’s interpretation of the reply request as proof of who sent the text.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · test data all synthetic — a made-up situation; no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “The text says to reply Y to activate the payment link. It also says I can reply STOP to stop getting messages.”

The response, as received — unedited

Don't reply with Y, and don't reply STOP either. Here is how to evaluate the text without responding to it.

1. What the reply is supposed to trigger

  • Replying Y is framed as "activating" a payment link. In practice it confirms that your number is live and read by someone who follows instructions. It can also make a link in the conversation tappable, because some phones disable links from unknown senders until you reply. The next step is then a payment page that asks for card or bank login details.
  • Replying STOP looks like the safe exit, but to an illegitimate sender it does the same job as Y: it confirms the number is active. A sender that ignores the law has no reason to honor an opt-out.

Both options lead to the same outcome, which is a response from you.

2. Why the reply is part of the request

  • It gives the sender something of value. A confirmed, responsive number can be targeted again or sold, whether or not you ever pay.
  • It can remove a protection. Replying may switch off your phone's safeguards for unknown senders, such as disabled links.
  • It builds commitment. Once you have taken one small step, the next one feels like finishing something you started.
  • Legitimate billers don't work this way. A real payment doesn't need you to "activate" a link by text. The made-up step exists to get you to engage.

So the reply is the first thing the message is asking you for, and you should judge it as strictly as you would the payment itself.

3. A no-reply way to check the claim

  • Leave the thread alone: don't reply, tap, or call any number in it.
  • Decide which organization the text claims to be from. If it doesn't name one, or names one you have no account with, you can stop there.
  • Reach that organization through a channel you already have: its official app, a web address you type yourself or have bookmarked, or the phone number on a card, statement, or bill.
  • Log in and look for a balance due or a pending payment request, or ask an agent whether one exists and whether they sent you a text about it.
  • If nothing is there, the claim is false. Report the text as junk in your messaging app (in the US you can also forward it to 7726), then block the sender and delete it.

4. What to gather from your own records first

  • Whether you have an account or relationship with this organization at all.
  • Your account or customer number, taken from a statement, card, or the app rather than from the text.
  • Your most recent bill or statement: amount, due date, and whether it was paid.
  • Your last payment: date, amount, and method, plus any confirmation you received.
  • Whether autopay is set up, and whether you were expecting any charge, delivery, renewal, or refund.
  • Whether you ever signed up for text alerts from them, and what their genuine past texts looked like.
  • The date and time the text arrived and what it claimed, so you can describe it to them.

5. Decision rule

If a text asks me to reply before it will show or do something, the reply is the request, so I send nothing, including STOP. I check the claim only through a channel I already had before the text arrived, and if the claim isn't there, I report, block, and delete.

A note from us, beside this response: the AI wrote “If nothing is there, the claim is false.” The AI states this as settled, and also says "Legitimate billers don't work this way." It never saw your message and does not know your biller. An account shows what has posted so far, and organizations differ in how they text customers. Ask the organization directly whether anything is pending and whether it sent you a text.

What we found

All five parts came back, ending in a rule worth keeping: "I send nothing, including STOP." That matches the FCC's standing guidance. Where it overreaches is certainty: a few lines read like proof of who sent the text, which the card asks you not to take from it. If the AI is wrong that the text is fake, its plan costs you a few minutes; lean on its certainty after one look and a balance not yet posted gets missed. It also says you can stop if you have no account with the organization named; a toll operator can bill a plate with no account.

Card 4: Check a package claim against your own records

Use this when: The text says a package cannot be delivered, needs a fee, or requires updated information.

Help me compare a package-related text with records I already have, without using anything from the text itself.

Do not ask for or use the message, its link, sender number, tracking number, QR code, or any payment information.

Ask me only about information I can get from my own purchase history, shipment confirmation, carrier account, or carrier app. Then help me make a checklist covering:
1. Whether I am actually expecting a package.
2. Which carrier the seller or shipment record says is handling it.
3. Whether my own carrier account shows an exception, delivery problem, or fee.
4. Whether I previously requested text tracking for that shipment.
5. What I should check directly with the carrier if the records do not match.

Do not conclude that the text is legitimate or fraudulent.

[PASTE YOUR OWN DESCRIPTION OF THE PACKAGE SITUATION HERE — no links, codes, tracking numbers or personal details]

How the AI reads this prompt: The assistant is pushed toward evidence you already control: your order history, shipment confirmation, and carrier account. The U.S. Postal Inspection Service said in its May 19, 2025 update that USPS does not send tracking texts or emails unless the customer first requested tracking with a tracking number, and that those USPS messages do not contain a link.

What to do with the answer: Compare the AI’s checklist with your own order and carrier records. If anything remains unclear, contact the carrier through its independently reached site, app, or phone line.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · test data all synthetic — it names a made-up delivery company (“Bluefinch Parcel”); no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “It claims to be from a delivery company called "Bluefinch Parcel". It says a package for me is being held at their depot because the address is incomplete, and that I need to confirm my details and pay a small redelivery fee through a link within 24 hours or it will be returned. I am expecting one online order this week but I do not know which carrier has it. I have not tapped or replied to anything.”

The response, as received — unedited

Here is a way to check this entirely from your own records. I won't need anything from the text.

Questions for you

Answer these from your order history, confirmation emails, and carrier accounts or apps, reached the way you normally reach them (typed address, saved bookmark, or installed app):

  1. For the one order you are expecting, does the retailer's order page or shipping confirmation email show a status of shipped, and does it name a carrier?
  2. If no carrier is named yet, does the order page say "preparing", "label created", or similar?
  3. Do you have an account or app with any carrier, and does that shipment appear there?
  4. What delivery address is on the order confirmation, and is it complete (unit number, postcode)?
  5. When you placed the order or received the shipping confirmation, did you opt in to text updates from the retailer or the carrier?

Checklist

1. Am I actually expecting a package?

  • [ ] Open the retailer's site or app directly and find the order.
  • [ ] Note the order status and estimated delivery date.
  • [ ] Confirm this is the only open order, including anything someone else may have sent you.

2. Which carrier does my record say is handling it?

  • [ ] Find the carrier name on the order page or shipping confirmation.
  • [ ] If none is listed, check with the seller through their official help page or your order page.
  • [ ] Write down whether the carrier named there is the same as the company named in the text. A different name does not settle it, because some sellers hand off to regional or final-mile carriers, so ask the seller whether any partner carrier is involved.

3. Does my carrier account show an exception, delivery problem, or fee?

  • [ ] Use the tracking number from your order record, entered on the carrier's site or app that you opened yourself.
  • [ ] Look for any exception, address problem, hold at a depot, or return notice.
  • [ ] Look for any fee owing, and note whether the account shows a way to pay it there.
  • [ ] Compare the address on your order with what the carrier shows.

4. Did I request text tracking for this shipment?

  • [ ] Check the order's notification settings and your carrier account's notification preferences.
  • [ ] Check whether your phone number was given at checkout at all.
  • [ ] Note whether earlier updates for this order came by email, app, or text.

5. What to check directly with the carrier if records do not match

Contact the carrier named in your own records, using contact details from their official site or app, and ask:

  • [ ] Is there any hold, address issue, or fee on my shipment?
  • [ ] Do you send texts asking for payment or detail confirmation, and by what method?
  • [ ] Do you use a partner or subcontractor by the name in the text?
  • [ ] If there is a real fee or address correction, how do I handle it inside my account?
  • [ ] What is the actual return deadline, if any?

Recording the result

Item My records say Matches the text's claim?
Expecting a package
Carrier name
Address complete
Exception or hold
Fee owing
Text updates requested

This gives you a list of matches and mismatches, not a verdict. Any real problem with your shipment will be visible and fixable through the seller or carrier channels you opened yourself, so you can deal with it there whatever the text turns out to be.

If you share your answers to the five questions, I can help you fill in the table.

What we found

This one handed the work back to you: "a list of matches and mismatches, not a verdict." It also avoided a trap: a different carrier name "does not settle it", because sellers use partner carriers. One caution: it asks for the delivery address on your order and offers to continue if you share answers. Answer in general terms; keep the address and tracking number out of the chat. Wrong one way, you pay a fee nobody was owed; wrong the other, a real parcel goes back. Near the end it says any real problem "will be visible" in those channels; records can lag, so ask the carrier if it matters.

Act & keep · report, recover, make it a habit

Card 5: Report it and clear the queue

Use this when: You have finished the independent check and want a short reporting-and-cleanup routine for the text.

Help me make a short reporting and cleanup checklist for a suspicious package, toll, or traffic-related text.

I do not want to engage with the sender. Do not ask me to open, reply to, scan, or test anything in the message, and do not ask me to paste any link, code, account detail, or personal information.

Organize the checklist in this order:
1. Preserve only what I reasonably need for a report, without interacting with the message.
2. Use my phone or carrier's built-in spam-reporting option where appropriate.
3. Include forwarding the text to 7726 (SPAM) as an option.
4. If it is USPS-themed, include the Postal Inspection Service reporting route.
5. Include the FTC and FBI IC3 reporting options.
6. Delete the message after I have finished any reporting I choose to do.
7. End with a compact version I can save as a personal checklist.

NO INPUT NEEDED

How the AI reads this prompt: The sequence turns a vague “What do I do with this?” into an ordered closeout routine. The FTC said in January 2025 that scam texts can be forwarded to 7726 (SPAM); the Postal Inspection Service’s May 19, 2025 guidance lists spam@uspis.gov for USPS-themed smishing reports; and the FTC and FBI IC3 maintain fraud-reporting channels.

What to do with the answer: Use the reporting options that fit your situation. Reporting helps send information to the relevant organization, but it does not establish whether an account charge, toll, or shipment issue is real.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · no test data needed — the prompt was run exactly as written.

How to read what follows: we ran the complete prompt above, with nothing added, in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

The response, as received — unedited

Suspicious Package, Toll, or Traffic Text: Reporting and Cleanup Checklist

You can do everything below without opening, answering, or tapping anything inside the message.

1. Preserve only what you need

  • Take a screenshot of the message as it appears on your screen, showing the sender's number or email address and the date and time.
  • Note which organization the text claims to be from (USPS, a toll agency, a DMV or court, a delivery company).
  • That is enough for any report. You do not need to tap the link, call the number, or reply "STOP" to gather more.

2. Use built-in spam reporting

  • iPhone (Messages): use "Report Junk" under the message if it appears, or "Delete and Report Junk" from the conversation list.
  • Android (Google Messages): press and hold the conversation in the list, then choose Block and "Report spam".
  • If neither option is offered, skip to step 3.
  • Block the sender so nothing else arrives from that number.

3. Forward to 7726 (SPAM), optional

  • Press and hold the message bubble itself (not the link), choose Forward, and send it to 7726.
  • This works with the major U.S. carriers and is free.
  • Your carrier may text back asking for the sender's number. You can supply it from your screenshot.

4. If it is USPS-themed

  • Email your screenshot to the U.S. Postal Inspection Service at spam@uspis.gov.
  • Include the sender's number or address and the date you received it.
  • USPS only texts tracking updates you signed up for, and those texts do not contain links.

5. Federal reports, optional

  • FTC: go to ReportFraud.ftc.gov by typing the address into your browser yourself.
  • FBI IC3: file at ic3.gov, again typing the address yourself. The FBI has specifically asked for reports of toll-payment texts. Include the sender's number and the name of the agency being impersonated.
  • For toll or traffic texts, you can also tell the real agency through its official website or the phone number on a statement you already have.

6. Delete

  • Once you have finished whichever reports you chose, delete the message and the conversation.
  • Delete the screenshot too once you no longer need it, unless you want it for your records.
  • If you ever want to check for a real unpaid toll, ticket, or delivery, go to the official site or app yourself, never through a text.

Compact version to save

Suspicious text checklist

  1. Don't tap, reply, or call.
  2. Screenshot the message, sender, and date/time.
  3. Report Junk / Report spam in the messaging app, then block the sender.
  4. Forward the text to 7726.
  5. USPS-themed: email the screenshot to spam@uspis.gov.
  6. Report at ReportFraud.ftc.gov and ic3.gov (type the addresses yourself).
  7. Delete the message, then the screenshot.
  8. Check any real toll, ticket, or package only through the official site or app.

What we found

The checklist came back in the order the card set, and it ends by sending any real toll, ticket or package question to the official site or app. Hold the additions loosely: the iPhone and Android menu steps are the AI's general knowledge as of 2026-10-03, and we have confirmed neither against the makers' own pages. A wrong step costs a report that does not go through; reporting a real text costs a few minutes. Neither tells you whether you owe anything.

Card 6: If you already tapped, typed, or paid

Use this when: You interacted with the message and need to organize the next hour without losing time to a long investigation.

I interacted with a package, toll, or traffic-related text and want a prioritized recovery plan.

Do not ask me to paste the message, link, QR code, account number, card number, password, one-time code, Social Security number, or any other sensitive value.

I will tell you only which of these happened:
- I tapped or opened something.
- I typed a password.
- I entered card or bank information.
- I made a payment.
- I entered personal identity information.
- Something else.

Based on what I say, give me:
1. The first organization I should contact directly.
2. The next two or three actions in order.
3. What records or facts I should have ready for each contact.
4. Which accounts or statements I should watch afterward.
5. Which actions can wait until the urgent calls are done.
6. A short note reminding me not to rely on anyone who contacts me later claiming they can recover my money for a fee.

Do not promise that a payment can be reversed or that an account is now protected.

[PASTE ONLY WHICH ACTIONS YOU TOOK — no passwords, codes, account numbers, card numbers, government ID numbers, links or personal details]

How the AI reads this prompt: This prompt sorts recovery by what you actually did rather than by how suspicious the message looked. The FTC’s standing guidance says to contact a credit card issuer or bank immediately after a scam payment, change a password that was given away and turn on two-factor authentication, and use IdentityTheft.gov when a Social Security number was exposed. The FBI IC3 warned on July 20, 2026 that IC3 does not contact people directly and does not ask for payment to recover lost funds.

What to do with the answer: Treat the list as a call order, not as a substitute for the bank, card issuer, account provider, or identity-recovery service. If money or credentials were handed over, direct contact with those organizations comes first.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · test data all synthetic — a made-up situation; no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “About 30 minutes ago I tapped the link in a text about an unpaid toll, typed my name and home address on the page it opened, and typed in my credit card details. I did not enter any password. I have not replied to the text.”

The response, as received — unedited

Here is your plan, based on what happened: you tapped the link, entered your name and home address, and entered credit card details. No password, no reply to the text.

1. First contact: your credit card issuer

Call the number printed on the back of the physical card, or use the issuer's official app. Do not use any number or link from the text or the page it opened.

Tell them: "I entered my card details on a fraudulent website about 30 minutes ago." Ask them to:

  • block or cancel the card and issue a new one with a new number,
  • review recent and pending charges with you and dispute any you don't recognize,
  • say whether they can add extra monitoring or alerts to the account.

Have ready:

  • the card itself, which they will identify through their own verification
  • the approximate time you entered the details
  • whether the page showed a payment going through or a specific amount
  • that you also gave your name and home address

Entering card details on these pages sometimes produces a charge and sometimes just captures the card. The issuer can tell you which. I can't promise any charge will be reversed, but reporting this quickly gives you the strongest position.

2. Next actions, in order

  1. Turn on transaction alerts for that card account and any replacement, through the issuer's app or site. Set them to notify you of every charge, if that option exists.
  2. Preserve the evidence, then stop interacting with it. Take a screenshot of the text showing the sender's number and the date. Don't tap the link again, and don't reply, not even "STOP."
  3. Report the text. Forward it to 7726 (SPAM), which works with most US carriers, then use your phone's "Report Junk" or block option. This doesn't recover anything, but it's quick and helps get the number shut down.

3. What to have ready for other contacts

  • If you want to confirm whether you actually owe a toll: go to the toll agency's official website by typing the address yourself, or call the number on a past statement. Have your license plate number and any transponder account details handy.
  • For fraud reports (FTC at reportfraud.ftc.gov, FBI at ic3.gov): the screenshot, the sender's number, the date and time, what information you entered, and any charge amounts the issuer identified. Describe the card as "my Visa ending in...", not the full number.

4. What to watch afterward

  • That card account: check pending and posted transactions daily for the next couple of weeks, then every statement for a few months. Look for small "test" charges of a dollar or two, which often precede larger ones.
  • The replacement card: update only the recurring bills you recognize, and watch the first statements.
  • Your credit reports: check all three bureaus for free at annualcreditreport.com, looking for accounts or inquiries you don't recognize. Name, address and a card number alone are limited fuel for identity theft, but they are worth a periodic check.
  • Mail, calls, texts and email: expect more scam attempts, since your number is now known to be active and they have your name and address. Treat follow-ups referencing a toll, a "fraud department," or a delivery with suspicion.

5. What can wait until the card call is done

  • Filing the FTC and IC3 reports.
  • Checking with the real toll agency.
  • Considering a free fraud alert or credit freeze with Equifax, Experian and TransUnion. This is optional here, since you didn't enter a Social Security number, but it is a reasonable precaution.
  • Updating recurring payments once the new card arrives.
  • Clearing your browser history and site data for that page. You don't need to change passwords based on what you've described. If the page made you download or install anything, tell me, because that changes the plan.

6. About "recovery" offers

People who've been targeted by one scam are often contacted again by someone claiming they can get the money back for an upfront fee. They may pose as a recovery service, law firm, government agency, or your bank's fraud team. These are a second scam. Real recovery happens through your card issuer's dispute process, which is free, and no legitimate agency charges to return your money. If anyone contacts you about this, hang up and call your issuer using the number on your card.

If anything else happened, such as a charge that went through, a download, or details entered that you haven't listed, tell me which category and I'll adjust the plan.

A note from us, beside this response: the AI wrote “I entered my card details on a fraudulent website about 30 minutes ago.” The AI scripts you to call the page fraudulent. It never saw the page and cannot know what it was. Calling your card issuer at once is still what the FTC's standing guidance points to. Say what you did: you typed your card details into a page you reached from a text you did not expect, you think it may be a scam, and you want the card blocked. Let the issuer judge the page.

What we found

Card issuer first, and it kept the card's hardest instruction: "I can't promise any charge will be reversed". Hold one line loosely: it calls a name, address and card number "limited fuel for identity theft", which we can neither back up nor contradict. Watching statements for small unfamiliar charges is the part the CFPB's standing guidance supports. If the page was a scam and you wait, charges can land; if it was real, you have a replaced card and a toll still to settle.

Card 7: Small business — separate the message from the payment workflow

Use this when: A small business receives one of these texts on an owner or employee phone and you need to keep it out of normal approval and payment routines.

I run a small business and received a package, toll, or traffic-related payment text on a business-related phone.

Help me keep the text separate from our normal payment workflow. Do not ask me to paste the message, sender number, link, QR code, invoice number, account number, tracking number, or any other identifier from it.

Build a practical checklist that covers:
1. What business record should exist if the charge is real.
2. Which employee, account owner, vendor portal, carrier account, toll account, or fleet record should be checked first.
3. How to perform a callback or independent contact using a number or website already in our records.
4. What approval should be required before any payment is made.
5. What to document if the claim does not match our records.
6. What to do if an employee already entered credentials or payment information.

Keep the advice suitable for a very small business with no dedicated IT or security staff.

[PASTE YOUR OWN DESCRIPTION OF THE BUSINESS SITUATION HERE — no links, codes, invoice numbers, account details or personal information]

How the AI reads this prompt: The prompt turns the problem into an approval and records question rather than a text-message judgment call. It asks the AI to connect the claim to records the business already controls and to a callback path taken from those records, not from the message.

What to do with the answer: Compare the checklist with your actual payment and account workflow. The AI can help expose missing steps, but the carrier, toll operator, bank, vendor account, or fleet record is where the underlying claim has to be settled.

A note from us, beside this card: From the site owner’s own incident-response work: if anyone typed a password into a page reached from one of these texts, treat that account as compromised. Reset the password right away — at the real site or through whoever runs the account, never through a link in the text — and anywhere else that password was used, and make sure multi-factor authentication (sometimes called two-factor) is on, then restart the computer. Don’t wait for signs of misuse. The FTC’s standing advice for a password typed on a fake page points the same way on the password: change it and turn on two-factor authentication.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · test data all synthetic — a made-up situation; no real agency, company or person was named by us.

How to read what follows: we ran the complete prompt above in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. What you type is read by the AI as content and shapes its answer. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

What we typed in place of the brackets: “We are a small plumbing company with 6 vans and 4 company phones. A text arrived on one technician's company phone saying one of our vans has an unpaid toll and asking for payment through a link. Two people can approve payments: the owner and the office manager. We have one toll account for the whole fleet, which the office manager looks after.”

The response, as received — unedited

Unpaid-toll texts with a payment link are one of the most common scams going, and toll agencies generally bill through your existing account or by mail to the registered owner, not by a text link. Treat the text as unverified until your own records say otherwise. Nobody taps the link, replies, or pays from the text.

Immediate steps (today)

  • [ ] The technician stops interacting with the text: no tapping, no replying, no calling any number in it.
  • [ ] The technician takes a screenshot and tells the office manager, then leaves the text alone.
  • [ ] The office manager tells the other three phone holders that a toll text is going around and to report, not respond.

1. What record should exist if the charge is real

A genuine unpaid toll would leave at least one of these:

  • [ ] A transaction or violation in your fleet toll account, tied to one of your six plates or transponders.
  • [ ] A low-balance, failed-payment, or expired-card notice in that account.
  • [ ] A mailed notice to the address on the van's registration.
  • [ ] A job, dispatch, or mileage record putting that van on a toll road on the date claimed.

If none of these exists, there is nothing to pay.

2. Who checks first

  • [ ] Office manager: checks the toll account for open balances, violations, and whether the payment card on file is current.
  • [ ] Office manager: confirms all six vans and their current plates are listed on the account.
  • [ ] Technician: confirms which van they drove and whether they used a toll road recently.
  • [ ] Office manager: checks the schedule for the other vans if the text does not name one.

3. Independent contact

  • [ ] Log in to the toll account by typing the address from your own records (a saved bookmark, a past statement, or the transponder paperwork).
  • [ ] If you need to call, use the number printed on a past statement, the transponder, or the account's own site.
  • [ ] Do not use a search result reached in a hurry; scam sites often pay for ad spots that imitate toll agencies.
  • [ ] Ask the agency: "Is there any unpaid balance or violation on our account or these plates?" Let them tell you the details rather than reading the text to them.
  • [ ] Note the date, time, who you spoke to, and what they said.

4. Approval before any payment

  • [ ] No payment is ever made from a link in a text, by anyone, regardless of amount.
  • [ ] Toll payments are made only inside the existing toll account or by the agency's mailed-notice process.
  • [ ] The office manager verifies the charge against the account. The owner approves any payment outside the normal auto-replenishment.
  • [ ] Technicians never pay tolls or fines with personal or company cards from their phones.
  • [ ] If the owner or office manager is the one who received the text, the other does the verification.

5. If the claim does not match your records

Keep a short note (a shared folder or a paper file is fine) with:

  • [ ] The screenshot, and the date and time received.
  • [ ] Which phone and employee received it.
  • [ ] What was checked, who checked it, and the result.
  • [ ] Whether anyone tapped, replied, or entered anything.

Then:

  • [ ] Report it as junk through the phone's messaging app, and forward it to 7726 (SPAM), which works for most US carriers.
  • [ ] Optionally, report it to the FTC at reportfraud.ftc.gov and the FBI at ic3.gov.
  • [ ] Block the sender and delete the text once the screenshot is saved.

6. If someone already entered information

Act quickly; time matters more than fault.

If card or bank details were entered:

  • [ ] Call the number on the back of the card (or your bank's known number) right away. Report fraud, cancel the card, and dispute any charges.
  • [ ] Watch that account for the next few weeks, including for small test charges.

If a login or password was entered:

  • [ ] Change that password immediately from a different device, by going to the real site directly.
  • [ ] Change it anywhere else the same password is used.
  • [ ] Turn on two-step verification where available.
  • [ ] Check the toll account for changed contact details, added vehicles, or a swapped payment card.

If the link was tapped but nothing was entered:

  • [ ] Close the page, and decline any app, profile, or file it offered to install.
  • [ ] Update the phone's software, and remove anything unfamiliar that was installed.

In every case:

  • [ ] Add what happened to your note, with times.
  • [ ] Expect follow-up scam calls or texts posing as your bank or the toll agency; verify these the same way.
  • [ ] Do not punish the employee for reporting. Fast reporting is what limits the damage.

A simple standing rule for all four phones

"Any text asking for money or a login gets a screenshot and goes to the office manager. We don't tap, reply, or pay from texts."

A note from us, beside this response: the AI wrote “If none of these exists, there is nothing to pay.” The AI states this as settled. Your records cannot carry that much: an empty toll account and no letter mean nothing has shown up yet where you looked. A toll held by another agency, or a notice still in the post, would not appear. Ask the toll operator, using contact details already in your records, whether anything is outstanding.

What we found

The checklist fits the business as described: if the owner or office manager got the text, the other does the checking. Two lines we are glad to show: "Do not use a search result reached in a hurry", and "Do not punish the employee for reporting." One sentence goes too far, and our note sits beside it. Pay from the text and the cost is card details and money; wave off a real toll and the cost is late fees on a notice still in the post. One thing about our own test: we described a text that reached a technician's phone, which is secondhand. Use this card for a text on your own phone; if it reached someone else, they describe it themselves.

Card 8: Make “check first” a household habit

Use this when: You want a simple in-person family routine for handling unexpected payment, package, toll, or traffic texts.

Help me create a simple household routine for suspicious package, toll, traffic, or payment texts.

This will be set up together, in person, with each family member using their own phone and their own accounts. Do not create a system where one person copies another person's message into an AI chat.

Build a five-step routine that each person can follow on their own device:
1. Stop before interacting with the message.
2. Describe the situation in their own words without pasting links, codes, account numbers, addresses, phone numbers, or personal details.
3. Use an AI assistant only to organize what needs checking.
4. Check the claim through the company's or agency's real site, app, statement, or phone number reached independently.
5. Decide whether to report and delete the text, or act on the legitimate issue found through the independent channel.

Add one short family rule we can remember easily and one monthly five-minute practice we can do together.

NO INPUT NEEDED

How the AI reads this prompt: The prompt keeps every person first-hand at their own device and uses the AI only for structure. It also turns the lesson into a repeatable household routine. The FTC said on July 30, 2026 that talking about scams with friends and family is one of the useful ways to fight fraud.

What to do with the answer: Adapt the routine to the accounts and services your household actually uses. The habit is the independent check; the AI is there to help organize the questions before you make it.

Actual execution example — what came back when we ran this prompt

Run: Claude (model identifier claude-fable-5-1), through our own test setup, not the Claude app · fresh session · the web was not used · as of 2026-10-03 · one run per prompt · prompt written by ChatGPT, run on Claude · no test data needed — the prompt was run exactly as written.

How to read what follows: we ran the complete prompt above, with nothing added, in a fresh AI session before publishing. One run is one sample — your answer will differ. Your product, plan and settings are not ours. Treat the AI’s read as a first opinion, never a clearance, and check through a channel you already trust.

The response, as received — unedited

Household Routine for Suspicious Texts

Covers: package delivery, toll, traffic ticket, and payment texts.
Setup: done together in person, with each person on their own phone and their own accounts. Nobody forwards or copies their messages to anyone else.

The five steps

1. Stop.
Do not tap the link, reply, call the number in the text, or type "STOP." Put the phone down for ten seconds. Urgency ("pay within 12 hours," "final notice") is the main tool scammers use, so the pause comes first.

2. Describe it in your own words.
Say or write what the text claims, in general terms. For example: "A text says I owe a small toll and will be fined if I don't pay today."

Leave out links, codes, account numbers, addresses, phone numbers, names, and any other personal details. Do not paste the message itself.

3. Use an AI assistant only to organize what needs checking.
On your own device, give it your plain description and ask something like: "What should I verify independently before acting on this?"

Use the answer as a checklist. The assistant cannot tell you whether the text is real, so it is not the place for a verdict.

4. Check through a channel you reach yourself.
Never use anything in the text to verify the text. Go to the source on your own:

Type of text Where to check
Package The carrier's or retailer's official app or site, using your own order confirmation
Toll Your toll account, by typing the agency's address yourself or opening its app
Traffic or ticket The court or DMV site you look up yourself, or the phone number on a paper notice
Payment Your bank or card app, your statement, or the number on the back of your card

If nothing shows up in your real account, there is no issue.

5. Decide.

  • Nothing found: report the text and delete it. Use your phone's "Report Junk" option or forward it to 7726 (SPAM), and optionally report it at reportfraud.ftc.gov.
  • Real issue found: handle it only inside the official site, app, or phone call you opened yourself. Delete the text anyway.

The family rule

"Don't tap the text. Go to the source."

Monthly five-minute practice

Pick a fixed day, such as the first Sunday of the month.

  1. Minute 1: One person invents a scenario out loud, such as "You get a text saying a package couldn't be delivered." Everyone says the family rule together.
  2. Minutes 2–3: Each person, on their own phone, finds the real channel for that scenario and confirms they can open the app or site and log in.
  3. Minute 4: Anyone who received a suspicious text that month describes it in their own words, without showing or forwarding it, and says what they did.
  4. Minute 5: Fix one gap, such as a missing official app, a forgotten password, or a bank number not saved in contacts.

Rotate who invents the scenario each month, and cycle through the four types.

If someone already tapped or paid

Tell the family right away, with no blame. Then call the bank or card company using the number on the card, and change the password for any account involved, starting with email if it was entered anywhere. Speed matters more than embarrassment.

A note from us, beside this response: the AI wrote “If nothing shows up in your real account, there is no issue.” The AI gives this as a rule. It cannot know your accounts: one can be empty because a charge has not posted yet, or because the claim belongs to an organization you have no account with. If the text names one you do deal with, ask it directly through its own site, app or a number you already have.

What we found

The part the card cares about most held: anyone who got a text "describes it in their own words, without showing or forwarding it". It also says the assistant "cannot tell you whether the text is real". One sentence goes further than it should, and our note sits beside it. Teach that sentence as a family rule and a real notice that has not posted yet gets deleted with the fakes; skip the routine and someone pays from a text.

Before you paste anything

Remove or replace personal details before putting any description into an AI chat: real names, street or email addresses, your phone number, tracking numbers, account numbers, case numbers, one-time codes, passwords, card data, and government ID numbers. For this topic, do not paste the suspicious message itself; describe what it claims and asks for in your own words.

When AI is the wrong tool

If money has already moved, card or bank details were entered, or unfamiliar charges appear, contact the card issuer, bank, or credit union directly using a number you already trust; the FTC’s standing recovery guidance says to contact the issuer or financial institution immediately, and the CFPB advises watching for unfamiliar charges. If you entered a password, go directly to the affected account, change it, and turn on two-factor authentication, following the FTC’s standing guidance. If you gave out a Social Security number, use the FTC’s IdentityTheft.gov recovery process. If the text claims a real toll, package, or court issue, settle that question with the agency or company through its own independently reached channel, not through the AI conversation.

Where this leaves you

The useful outcome is a repeatable way to separate the message from the claim it makes. You are better prepared to ask the AI for structure, then take the factual question to the organization that can actually answer it.

Questions you might still have

The notes and the questions and answers on this page were drafted with AI and reviewed by the site’s owner before publishing. The note beside Card 7 that begins “From the site owner’s own incident-response work” is the owner’s own. No reader sent the questions in, and neither the questions nor the answers are part of any AI response shown above. The answers describe the runs published above, as of 2026-10-03.

Your answer will differ — differ how?

We don't know yet; one run is one sample. Each prompt on this page was run once, on 2026-10-03, on Claude without using the web, using made-up details. None was run on ChatGPT or Gemini, and there are no re-runs, so we cannot say how far answers move. What we can name is where difference comes from: your product, its tier and settings, whether it can browse, and what you describe. What no example can settle is whether your own answer is right. The organization's records do that, reached your own way.

Five of your eight examples carry a note correcting the AI for sounding too sure. Cards 1 and 4 tell the AI not to call the message genuine or fraudulent, and their examples gave no verdict. So why publish the other prompts without that line?

Because the prompts are ChatGPT's, and we never edit a platform's prompt. A shortfall gets a note beside it, or we ask the platform to write again before publication. We ask again when a result is harmful or does not do the card's job; a too-sure sentence in an otherwise useful answer gets a note, and that is what these were. You are free to change any prompt you copy. We publish them as written and have not run any changed version, and two cards run once each cannot settle whether the line is what made the difference.

The post says it was written by ChatGPT, but every example was run on Claude. If I paste these into ChatGPT, what have your examples actually shown me?

Less than the masthead might suggest. They show what each prompt produced once, on Claude, on 2026-10-03, without using the web and with made-up details. They do not show how ChatGPT answers its own prompts; we have not run them there, or on Gemini. What you can take from them is the shape of a response to these instructions, and the places one AI went past the evidence, so you know what to look for in yours. What this can't settle is whether ChatGPT does better or worse. We don't know.

I checked my account and found nothing. The AI says that settles it; your notes say it doesn't. So when am I allowed to delete the text and stop thinking about it?

Report it, then delete it whenever you like. The FTC, January 2025, says to report it and delete it, and the sources we read say to check the claim through a phone number or website you know is real, not through the text. What stays open is the claim, and there is a reasonable place to stop: you have looked in the account you actually hold, and you have asked the organization, by your own route, whether anything is pending and whether it texts customers. If you hold no account with it and your vehicle has not been on its roads (or, for a parcel text, you are expecting nothing), there may be nothing of yours to look up; a notice by post, if that agency sends one, is then the thing to watch for. What this can't settle is that nothing is owed; only the organization knows that.

Card 1's example says find the toll operator with a search engine. Card 7's example says don't use a search result reached in a hurry. If I have no account and no old statement, how do I find the real site?

We have no route that makes a searched-for site certain, and the two examples do pull against each other. The slower path is the steadier one: start from your state's transportation department or motor-vehicle agency, as card 2's example suggests, and follow its own link to the toll operator. If you do search, treat the address you find as a claim, and compare it against a second place you did not reach from the first. That is a rule of thumb, not a sourced method. Our sources for this post say to use a website or number you know is real, and they stop there. Card 7's line about scam sites buying ad spots that imitate toll agencies is the AI's own. The FTC (August 2020) and the FBI (December 2022) have warned about paid search results that impersonate companies in general; neither was writing about toll agencies. The caution costs a little time.

Three of the examples say replying can make the link tappable, and you say you haven't confirmed that. Is it true or not — and if you don't know, why is it sitting in three answers on your page?

We don't know, and we have not tested it. It is on the page three times because we publish each response as received; we flag a doubtful line in our notes (this one under Card 1) and never edit it. None of the sources we read says it. The nearest is New York's February 2025 warning that some fake toll texts ask for a "Y" before sending a link. Your decision does not hang on it: the FCC's standing guidance is not to respond, even when a message says to "text STOP". What this can't settle is why a sender wants the reply.

Built the way every prompt post here is built: we brief, a platform writes, and its prompts and wording are published unedited — with a public note wherever we found it fell short. We never edit a prompt.

Previous
Previous

Five things we left out of a post — and why they could steer you wrong

Next
Next

A text says my package is stuck and my toll is unpaid :: Claude