Social Engineering & FraudMANIPULATIVE

Package Delivery Lure

What it is

A phishing message posing as a postal or courier service claiming a delivery problem (a held package, an address issue, a small fee due) to harvest payment details or credentials.

How it works

The delivery lure works on plausibility and volume: in an era of constant online shopping, almost everyone is expecting a package, so a "we could not deliver your parcel" notice lands in a receptive mind even for people who did not order anything. It exploits mild curiosity and the wish to resolve a small problem rather than fear of a large one. The message impersonates USPS, FedEx, UPS, DHL, or a national post, and asks the recipient to confirm an address, reschedule delivery, or pay a tiny "redelivery" or "customs" fee. The real purpose is the card details entered on the linked page, or credentials for an account. The small sum is strategic: a two-dollar fee feels too trivial to scrutinize, yet it hands over full card data. The FTC identified fake package-delivery texts among the top text scams of 2022, and the pattern surges around holidays. Because tracking notices are genuinely common, the counterfeit blends into legitimate delivery traffic.

Real-world examples

  • A text reads "USPS: your package is on hold due to an incomplete address" and links to a page that asks for a small fee and your card number.
  • A "customs charge due" message impersonating DHL or a national post targets people expecting international parcels.
  • Fake FedEx or UPS "reschedule your delivery" notices harvest logins or card details during holiday shopping surges.
  • The FTC found fake package-delivery texts among the top five reported text scams of 2022, alongside bank-impersonation lures.

Ethical guidelines

  • Impersonating a delivery service to collect payment or card data is fraud; there is no legitimate use.
  • Carriers should communicate delivery issues in ways that do not train customers to click links and pay fees by text, so the fake stands out.
  • The trivial fee is a deliberate design to bypass scrutiny, and its smallness does not make the theft minor, since the card data is the real prize.

How to defend against it

  • Do not tap links in delivery texts or emails. Track parcels using the carrier's official app or by entering the tracking number on the site you typed yourself.
  • Be suspicious of any "small fee" to release a package; legitimate carriers rarely collect redelivery fees by text link, and customs charges are handled through official channels.
  • Remember that expecting a package does not make a specific message genuine; scammers count on the coincidence.
  • Check the sender and the link's real domain; a delivery lure often uses a lookalike or unrelated address.
  • Forward scam texts to 7726 (SPAM) and report to reportfraud.ftc.gov, then delete them.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Fletcher, E. (Federal Trade Commission) (2023). IYKYK: The top text scams of 2022. FTC Consumer Protection Data Spotlight, June 2023 · link
    Fake package-delivery texts identified among the top five reported text scams of 2022.
  2. Ferreira, A., Coventry, L., & Lenzini, G. (2015). Principles of Persuasion in Social Engineering and Their Use in Phishing. Human Aspects of Information Security, Privacy, and Trust (HAS 2015), Lecture Notes in Computer Science 9190, Springer, 36-47 · link
    Framework for the persuasion principles delivery lures exploit, especially small-commitment requests.
Last reviewed
Suggest a correction

Detect Package Delivery Lure in any text

Paste any message, email, or article into our free Manipulation Detector to see if Package Delivery Lure or other techniques are being used on you.

Related Articles