With billions of ecommerce shipments circulating globally each month, receiving package tracking notifications on smartphones has become second nature. Capitalizing on this constant expectation, cybercrime syndicates deploy automated package delivery smishing scams. By sending alarming text messages regarding “incomplete delivery addresses” or “unpaid customs fees,” fraudsters trick mobile users into surrendering financial data and installing spyware.
The Mechanics of SMS Phishing (Smishing) Operations
Smishing campaigns operate at massive scale utilizing automated SMS blasters and rogue cellular base stations (IMSI catchers). Victims receive a text message purportedly from the United States Postal Service (USPS), UPS, FedEx, or DHL. The message typically states: “Your package cannot be delivered due to an incorrect house number. Please update your address within 12 hours or item will be returned.”
| Smishing Indicator | Legitimate Delivery Notification | Fraudulent Smishing SMS |
|---|---|---|
| Originating Phone Number | Official 5- or 6-Digit Shortcode | Random 10-Digit Mobile or Foreign Country Code (+44, +63) |
| Target URL Destination | Official Carrier (e.g., usps.com) | Typosquat Domain (e.g., usps-redelivery-tracking.info) |
| Requested Payment | Zero Redelivery Fees | Demands \$0.30 – \$1.50 “Redelivery Fee” via Card |
| Urgency Mechanism | Informational Tracking | Threatens Immediate Return or Legal Seizure |
The Two Destructive Objectives Behind Delivery Texts
1. Harvesting Credit Card and Banking Details
When the victim clicks the embedded link, they are directed to an authentic-looking replica of the delivery company’s tracking portal. After “confirming” their address, the site demands a nominal redelivery or customs fee—usually between \$0.50 and \$2.50. Victims readily input their full credit card details, CVV security codes, and billing addresses because the amount seems trivial. In reality, the stolen card details are instantly funneled to criminal carding forums or used to enroll the victim in recurring high-dollar subscription billing traps.
2. Distributing Aggressive Android Malware (FluBot / MoqHao)
In more dangerous variations targeting Android users, clicking the SMS tracking link prompts the user to download an update for a “Postal Tracking App” via a sideloaded APK. Once installed, this banking trojan intercepts SMS two-factor authentication codes, steals contacts, and silently turns the infected smartphone into an automated smishing relay node that blasts thousands of fraudulent texts to other numbers at the victim’s expense.
How to Handle Suspicious Delivery Notifications
- Never Click the Link: Treat every unsolicited text message containing a package tracking hyperlink with extreme suspicion.
- Inspect the Tracking Number Independently: Copy only the alphanumeric tracking number, open your web browser, navigate directly to the carrier’s verified home page (e.g.,
ups.comorusps.com), and paste the code into their official search bar. - Forward Smishing Messages to 7726: In the US and UK, forward the fraudulent text message to the universal shortcode 7726 (SPAM) to alert telecommunications security teams.
- Delete and Block the Sender: Immediately purge the message to avoid accidental clicks and block the transmitting number.
Frequently Asked Questions About Delivery Text Scams
Why do I receive delivery scam texts when I haven’t ordered anything?
Scammers blast automated messages to millions of randomly generated telephone numbers simultaneously. They rely on probability; on any given day, a large percentage of recipients are legitimately waiting for an online purchase.
What should I do if I entered my debit card number on a fake delivery page?
Immediately call the phone number on the back of your card to freeze the compromised card, report the fraudulent exposure, and request a newly issued card with a fresh account number.
