Package Delivery Lure
What it is
A phishing message posing as a postal or courier service claiming a delivery problem (a held package, an address issue, a small fee due) to harvest payment details or credentials.
How it works
Real-world examples
- •A text reads "USPS: your package is on hold due to an incomplete address" and links to a page that asks for a small fee and your card number.
- •A "customs charge due" message impersonating DHL or a national post targets people expecting international parcels.
- •Fake FedEx or UPS "reschedule your delivery" notices harvest logins or card details during holiday shopping surges.
- •The FTC found fake package-delivery texts among the top five reported text scams of 2022, alongside bank-impersonation lures.
Ethical guidelines
- ●Impersonating a delivery service to collect payment or card data is fraud; there is no legitimate use.
- ●Carriers should communicate delivery issues in ways that do not train customers to click links and pay fees by text, so the fake stands out.
- ●The trivial fee is a deliberate design to bypass scrutiny, and its smallness does not make the theft minor, since the card data is the real prize.
How to defend against it
- ►Do not tap links in delivery texts or emails. Track parcels using the carrier's official app or by entering the tracking number on the site you typed yourself.
- ►Be suspicious of any "small fee" to release a package; legitimate carriers rarely collect redelivery fees by text link, and customs charges are handled through official channels.
- ►Remember that expecting a package does not make a specific message genuine; scammers count on the coincidence.
- ►Check the sender and the link's real domain; a delivery lure often uses a lookalike or unrelated address.
- ►Forward scam texts to 7726 (SPAM) and report to reportfraud.ftc.gov, then delete them.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Fletcher, E. (Federal Trade Commission) (2023). IYKYK: The top text scams of 2022. FTC Consumer Protection Data Spotlight, June 2023 · linkFake package-delivery texts identified among the top five reported text scams of 2022.
- Ferreira, A., Coventry, L., & Lenzini, G. (2015). Principles of Persuasion in Social Engineering and Their Use in Phishing. Human Aspects of Information Security, Privacy, and Trust (HAS 2015), Lecture Notes in Computer Science 9190, Springer, 36-47 · linkFramework for the persuasion principles delivery lures exploit, especially small-commitment requests.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.