Why this scam works so well
Almost everyone is waiting for a parcel. Criminals send millions of messages knowing that a meaningful share will reach someone with a genuine delivery pending, and that person has a ready-made reason to believe the message. Nothing about the text needs to be clever when the timing does the persuading.
The fee is deliberately small, usually between one and three pounds, dollars or euros. A small charge feels low-risk and bypasses the caution people apply to larger payments, while the real value to the criminal is the full card number, expiry, security code and the personal details typed alongside it.
- A believable reason: you probably are expecting something
- A tiny fee that feels too small to be worth a scam
- Urgency: the parcel is returned to the depot in 48 hours
- Brand names people trust: Royal Mail, USPS, DHL, Evri, FedEx, An Post
- A link that looks close enough to the real domain at a glance
What the fake messages actually look like
The current wave uses short domains that combine a carrier name with an unrelated suffix, such as a carrier word followed by a country code or a random string. The page that opens is often a faithful copy of the real tracking site, sometimes with a live-looking map and a progress bar, because the HTML is simply cloned from the genuine one.
Email versions add an invoice or a customs charge, which is the variant most likely to catch people who order from overseas. The message claims that duty is outstanding and the parcel is held at customs. Genuine customs charges are collected by the carrier through their own app or an official notification card, never through a link in an unsolicited text.
- 'Your parcel is held at our depot — pay the £1.99 redelivery fee'
- 'Customs duty of $3.40 is outstanding on your package'
- 'We attempted delivery today. Reschedule within 24 hours'
- A link on a domain that is not the carrier's own website
- A form asking for full card details, address and date of birth
The second call is the expensive part
Paying two pounds is not what costs people thousands. Days later, a caller says they are from your bank's fraud team, references the exact small transaction you made, and says your account is compromised. Because they know a real detail you have not told anyone, the call sounds legitimate.
They then ask you to move money to a 'safe account', read out a code, or install remote-access software so they can 'secure' your device. No bank ever does any of these things. Hang up, wait five minutes or use a different phone, and call the number printed on your card.
How to check a delivery safely
Never use the link in the message. Open the carrier's own app or type their website address yourself, then paste in the tracking number from your order confirmation. If there is no tracking number in your own email from the retailer, there is no parcel.
Remember that carriers do not have your mobile number unless the sender gave it to them, and that legitimate redelivery is arranged inside their app or website, not through a card form on a page you reached from a text.
- Check in the carrier's app, never through the message link
- Match the tracking number against your own order confirmation
- Treat any fee request in an unsolicited message as fraudulent
- Report the text by forwarding it to your national spam-reporting service
- Tell older relatives about the follow-up 'bank fraud team' call
What to do if you already entered your card
Freeze the card in your banking app immediately, which takes seconds and is reversible, then call the bank on the number on the card and ask for it to be replaced. Watch for small test transactions in the following days: criminals often trial a tiny amount before attempting a large one.
If you also gave your address and date of birth, treat it as an identity exposure rather than just a card loss. Consider a credit-file notice, change passwords on accounts that use those details for recovery, and expect impersonation calls for several weeks.
Protection that reduces the damage
A password manager will not fill your details into a lookalike domain, which turns a convincing copy into an obvious fake before you type anything. Security software that blocks known phishing domains stops many of these pages from loading at all, and mobile suites increasingly filter scam texts as well.
Card controls matter as much as software: virtual or single-use card numbers, app notifications on every transaction, and a low contactless limit all shrink the window between a leak and a loss.
- A password manager that refuses to autofill on a fake domain
- Security software with phishing and scam-message filtering
- Virtual card numbers for one-off online payments
- Instant transaction notifications on every card
- Two-factor authentication on the email address that resets your bank
