Scams

QR Code, Toll-Text and Package Scams: The 2026 Family Briefing

The August 2026 briefing on QR code, unpaid-toll and package-delivery text scams: what the current wave looks like, why smart people fall for them, and the family rule that stops all three.

QR Code, Toll-Text and Package Scams: The 2026 Family Briefing — illustration

Updated for August 2026. We refresh this briefing monthly as the wave shifts — bookmark it, and forward it to the family group chat; that’s what it’s for.

Three scams currently account for most of the “is this real?” screenshots relatives send us: the unpaid-toll text, the missed-package text, and the malicious QR code. None are sophisticated. All are working at industrial scale — the FTC’s consumer alerts and the FBI’s IC3 have tracked toll-scam texts alone in the tens of millions this year — because they’ve stopped attacking your computer and started attacking your hurry.

Here’s this month’s field guide: what each looks like right now, the tells, and the single house rule that beats all three.

1. The unpaid-toll text

Current wave: “FastTrak/E-ZPass: Your account has an unpaid toll of $6.99. To avoid a late fee of $50, settle at: [link].” August’s variants increasingly name your actual state’s toll brand and arrive from ordinary-looking mobile numbers or iMessage/RCS accounts, since carriers now filter obvious spam senders.

Why it works: the amount is small, the “late fee” is scary, and you have driven recently. Paying $7 to dodge $50 is a rational decision — which is exactly the trap. The page then harvests card details, and the real prize, and often a “verification” one-time code that lets them enroll your card in a mobile wallet they control.

The tells: toll agencies don’t collect by text link; the URL is never the agency’s real domain (look for lookalikes: ezpass-pay.com-style constructions); there’s always a countdown. The move: delete it, and if doubt lingers, type your toll agency’s address into the browser yourself. Not the link. Ever.

2. The missed-package text

Current wave: “USPS: Your package is on hold due to an incomplete address. Confirm details within 24h: [link].” August flavor: fake customs fees on foreign parcels ($1-3 — deliberately trivial) and delivery-window texts that arrive, cruelly, while you’re actually expecting something from the Prime-day-adjacent sales.

Why it works: you are expecting a package. Half the country always is. The scam pre-matches reality often enough that vigilance feels paranoid.

The tells: carriers don’t ask for payment or “address confirmation” via text link; tracking numbers in scam texts don’t match your real orders; the domain, again, is the giveaway. The move: open the retailer’s app or the carrier’s real site and check the tracking number you already have. The text adds nothing the app doesn’t know.

3. The malicious QR code

Current wave: “quishing” has gone physical and corporate — stickers over real codes on parking meters and EV chargers (pay-by-QR makes this lucrative), codes in mailed letters claiming to be from your bank (“scan to verify your account”), and fake voicemail/HR emails at work with a QR to “authenticate.” The QR’s trick is that the URL stays invisible until you’ve already committed, and phone cameras make scanning feel safe because nothing “downloads.”

The tells: a sticker with edges over another code; any QR whose purpose is login, payment or “verification” arriving unsolicited; a scanned URL that isn’t exactly the brand’s domain (your camera shows a preview — read it before tapping). The move: for parking and chargers, prefer the machine’s keypad or the official app you already have; for banks, no legitimate bank sends QR-verification letters — call the number on your card instead.

The house rule that beats all three

Notice the pattern: every one of these arrives uninvited, creates urgency, and offers a link/code as the only path. So the rule — teach it in one breath at dinner:

“We don’t pay, log in, or ‘verify’ through links or codes that came to us. We go to the app or website ourselves.”

That’s it. It requires no ability to inspect URLs, works for a 9-year-old and a 90-year-old, and survives scam variants that don’t exist yet. It’s the same principle behind our family safe word for voice-cloning calls — remove the decision from the moment of pressure. Tape both rules to the fridge; we’re only half joking.

If someone already tapped

Speed matters, shame doesn’t — these things are designed to work on smart, busy people:

  1. Card details entered: call the number on the back of the card, kill it, get a reissue. Watch for small “test” charges.
  2. Password entered: change it wherever it’s used (this is why a password manager that never reuses passwords converts a disaster into an errand), and turn on 2FA — hardware keys are immune to exactly this phishing.
  3. One-time code shared: contact the bank immediately and say so specifically — wallet-enrollment fraud is time-sensitive.
  4. Report it: ReportFraud.ftc.gov and forward scam texts to 7726 (SPAM). It genuinely feeds the filters.

Then send the family the fridge rule. This month’s wave will pass; the next one only works on households that haven’t had the dinner conversation yet.