With billions of ecommerce shipments circulating globally each month, receiving package tracking notifications on smartphones has become second nature. Capitalizing on this constant expectation, cybercrime syndicates deploy automated package delivery smishing scams. By sending alarming text messages regarding “incomplete delivery addresses” or “unpaid customs fees,” fraudsters trick mobile users into surrendering financial data and installing spyware.

The Mechanics of SMS Phishing (Smishing) Operations

Smishing campaigns operate at massive scale utilizing automated SMS blasters and rogue cellular base stations (IMSI catchers). Victims receive a text message purportedly from the United States Postal Service (USPS), UPS, FedEx, or DHL. The message typically states: “Your package cannot be delivered due to an incorrect house number. Please update your address within 12 hours or item will be returned.”

Smishing IndicatorLegitimate Delivery NotificationFraudulent Smishing SMS
Originating Phone NumberOfficial 5- or 6-Digit ShortcodeRandom 10-Digit Mobile or Foreign Country Code (+44, +63)
Target URL DestinationOfficial Carrier (e.g., usps.com)Typosquat Domain (e.g., usps-redelivery-tracking.info)
Requested PaymentZero Redelivery FeesDemands \$0.30 – \$1.50 “Redelivery Fee” via Card
Urgency MechanismInformational TrackingThreatens Immediate Return or Legal Seizure

The Two Destructive Objectives Behind Delivery Texts

1. Harvesting Credit Card and Banking Details

When the victim clicks the embedded link, they are directed to an authentic-looking replica of the delivery company’s tracking portal. After “confirming” their address, the site demands a nominal redelivery or customs fee—usually between \$0.50 and \$2.50. Victims readily input their full credit card details, CVV security codes, and billing addresses because the amount seems trivial. In reality, the stolen card details are instantly funneled to criminal carding forums or used to enroll the victim in recurring high-dollar subscription billing traps.

2. Distributing Aggressive Android Malware (FluBot / MoqHao)

In more dangerous variations targeting Android users, clicking the SMS tracking link prompts the user to download an update for a “Postal Tracking App” via a sideloaded APK. Once installed, this banking trojan intercepts SMS two-factor authentication codes, steals contacts, and silently turns the infected smartphone into an automated smishing relay node that blasts thousands of fraudulent texts to other numbers at the victim’s expense.

CARRIER POLICY FACT: The USPS and major global shipping carriers will NEVER send an unsolicited SMS containing an active link to pay a redelivery fee. Delivery exceptions are handled via physical paper door tags left at your residence.

How to Handle Suspicious Delivery Notifications

  • Never Click the Link: Treat every unsolicited text message containing a package tracking hyperlink with extreme suspicion.
  • Inspect the Tracking Number Independently: Copy only the alphanumeric tracking number, open your web browser, navigate directly to the carrier’s verified home page (e.g., ups.com or usps.com), and paste the code into their official search bar.
  • Forward Smishing Messages to 7726: In the US and UK, forward the fraudulent text message to the universal shortcode 7726 (SPAM) to alert telecommunications security teams.
  • Delete and Block the Sender: Immediately purge the message to avoid accidental clicks and block the transmitting number.

Frequently Asked Questions About Delivery Text Scams

Why do I receive delivery scam texts when I haven’t ordered anything?
Scammers blast automated messages to millions of randomly generated telephone numbers simultaneously. They rely on probability; on any given day, a large percentage of recipients are legitimately waiting for an online purchase.

What should I do if I entered my debit card number on a fake delivery page?
Immediately call the phone number on the back of your card to freeze the compromised card, report the fraudulent exposure, and request a newly issued card with a fresh account number.

Share.

Marcus Vance is a senior cybersecurity researcher and digital privacy advocate with over 11 years of experience in threat intelligence and authentication protocols. At Cauitonery, Marcus leads consumer investigations into phishing vectors, smishing schemes, zero-trust account hardening, and privacy defenses.

Leave A Reply

Exit mobile version