Package Delivery Scams: How to Spot and Stop Them
By Josh C.
In the UK, 49% of people targeted by scammers received a malicious parcel-delivery text or email in 2023, making parcel delivery scams the most common scam type identified that year, according to Citizens Advice. This isn't a minor nuisance. Scammers have turned the ordinary expectation of a delivery into a reliable way to steal card details, passwords, and personal information.
The most dangerous messages aren't always riddled with spelling mistakes. Some copy carrier branding, use believable delivery language, and arrive when you're waiting for a parcel. The right response is simple but firm: never solve a delivery problem through an unsolicited message. Verify it independently.
Why Package Delivery Scams Are Surging
Package delivery scams work because they attach fraud to a normal event. People shop online, receive tracking updates, miss deliveries, and occasionally pay legitimate customs or redelivery charges. A message that says “your parcel is delayed” doesn't sound absurd. It sounds like something that could happen today.
The scale is clear across several countries. In Australia, consumers reported more than 11,000 parcel-delivery scams in 2023, with more than A$720,000 in reported losses between 1 January and 31 October, compared with 2,931 reports and A$56,000 in losses during the previous year, according to the Australian Competition and Consumer Commission. The National Anti-Scam Centre said delivery-phishing reports had quadrupled during that year.
In the UK, Citizens Advice reported that people over 75 were the most frequently targeted age group overall, with 87% facing some kind of scam during the survey period. That doesn't mean older adults are careless. It means scammers understand that unexpected contact, unfamiliar technology, and pressure around payments can create a difficult moment.

The threat follows real shopping habits
The Federal Trade Commission says impersonators pretend to be USPS, UPS, or FedEx, then direct recipients to lookalike websites requesting a small redelivery fee or bank details. Its guidance on impersonation scams recommends checking URLs for subtle misspellings and avoiding payment links in unsolicited messages.
The seasonal pattern matters too. Norton reported that package delivery scams jumped 89% in summer compared with the rest of the year and blocked 43,326 attacks across the summers of 2024 and 2025, as described in its research on summer scams. Busy shopping periods give criminals more plausible excuses and give recipients less time to question them.
Businesses face a related physical-security problem because criminals can combine digital impersonation with stolen or redirected parcels. For background on protecting goods at the fulfilment stage, the warehouse security systems guide from Wisenet Security Ltd. offers useful context. Consumers should also understand the broader identity tactic described in this guide to brand impersonation, where a trusted name is used to make a fraudulent request feel routine.
Common Package Delivery Scam Schemes
Package scams now exploit more than obvious phishing texts. The most effective messages imitate carrier language and real delivery exceptions, so shipment anxiety does the persuading. A notice about an incomplete address, an unreachable driver, or a modest release fee can look routine. After you click, the supposed carrier may collect payment details, account credentials, or enough personal information to support later fraud.
The message-based traps
Fake rescheduling notices say a delivery attempt failed or that you must arrange another appointment. The link leads to a carrier-style page requesting your name, address, phone number, card details, or login credentials. The page may copy familiar colors and wording, but those details do not verify the sender.
Additional-fee demands describe the charge as customs, redelivery, address correction, or parcel release. A small amount lowers resistance and makes the request seem administrative. The target is often your card information or identity data, not the delivery fee.
False tracking alerts include a tracking number, carrier logo, and status such as “held,” “pending,” or “delivery exception.” The reference may come from a real order, be randomly generated, or exist only to make the message appear official. The FTC addresses this pattern in its consumer warning about fake delivery messages.

A message can match the carrier's usual tone and refer to a genuine shipment. Grammar and branding alone are poor tests. Treat any message that asks you to click, pay, or enter information as untrusted until you confirm the issue through the retailer's account or the carrier's official website and app.
The parcel that arrives without an order
Brushing scams reverse the usual sequence. An unexpected parcel arrives in your name, sometimes containing a cheap item, a tracking label, a QR code, or a request for a review. The FTC explains that sellers can use unordered goods to create fake reviews connected to an order. Its consumer guidance on brushing scams advises recipients to keep merchandise they did not order and report the incident.
The item may not be the main danger. A QR code can open a counterfeit shopping page, while a review request can tie your identity to an account you do not control. The shipment can also signal that a shopping account or address database was exposed. Independent researchers recorded more than 100 fake shipment campaigns almost every month in 2025, including 218 campaigns in June 2025 and 208 in December 2025, after almost no observed activity in 2024, according to Infosecurity Magazine.
Do not scan the QR code, contact the sender using package details, or post a review. Keep the merchandise, secure your shopping accounts, and report the scam.
For a carrier-specific example, read our breakdown of the DHL text message scam.
Red Flags That Reveal a Scam
A delivery message can look polished and still be fraudulent. Judge it by the action it demands and by whether you can verify that request outside the message.

Five warning signs to check
- Unexpected fee demand: A message asks for payment before delivery. Do not use its payment link. Check the order and tracking details through the retailer's or carrier's official app.
- Generic greeting: “Dear customer” or no greeting can indicate a mass campaign. Personalization does not prove legitimacy, but generic wording deserves scrutiny.
- Mismatched URL: Inspect misspellings, extra words, unusual endings, shortened links, and substitutions such as
amaz0n.com. A carrier-style message can copy official language while sending you to a counterfeit site. - Urgent pressure: “Act now,” “final notice,” and “delivery cancelled” are meant to prevent independent checking. Verify any delivery problem through an official channel.
- Poor formatting or strange grammar: Errors may expose a fake, but clean writing proves nothing. Sophisticated campaigns imitate legitimate carrier terminology and formatting.
The strongest warning is the combination. An unexpected message from an unfamiliar sender that demands payment and includes a link should receive no reply.
Physical parcels require the same caution. An unsolicited package containing a QR code, review request, or unfamiliar sender may be part of a brushing or fake-shipment operation. Set it aside, do not scan anything, and review your shopping accounts through their normal apps.
Practical rule: Treat every unsolicited delivery link as unsafe, even when the timing seems believable.
A video walkthrough of these warning signs reinforces the same check: never trust the sender's link.
How to Verify Legitimate Delivery Messages
The difficult cases are carrier-mimicking alerts that arrive when a real delivery is expected. They may use accurate terminology and refer to a genuine shipment, yet still direct you to a counterfeit payment or verification page. Verify the delivery outside the message.

Compare the route, not just the wording
A legitimate notification should match an order you recognize. Open the retailer's official app, use a bookmark you saved yourself, or type the carrier's web address manually. Enter the tracking number there instead of following the message's link.
| Legitimate delivery communication | Suspicious delivery communication |
|---|---|
| Matches an order you placed | Refers to a parcel you don't recognize |
| Can be confirmed in the retailer's or carrier's official app | Requires the message link for verification |
| Uses a known account or notification channel | Requests card details or passwords unexpectedly |
| Gives you a safe way to check the status independently | Creates pressure to act immediately |
A genuine delivery exception may require action, but the message is not the place to provide payment details. Contact the retailer through customer-service information in your order confirmation, not the phone number or link supplied by the alert.
A safe verification routine
- Pause. Don't reply, click, scan, download, or pay.
- Find the original order. Check the retailer account, receipt, or confirmation email you already trust.
- Open the official carrier channel. Use the carrier's app or manually entered website.
- Check the tracking number. Compare the status, delivery address, and expected shipment details.
- Call through an independent source. Use a number from the official website, your order record, or the back of a payment card.
One check is not enough. A tracking number may appear in the carrier system while the alert changes the delivery address or asks for an unexpected card payment. Stop if any detail fails to match, then contact the retailer through its official channel.
For a focused example, review the UPS text message scam guide. A valid tracking number should connect to the same order, address, and delivery status you see in the retailer's account.
Protection Strategies That Work
Good protection starts with hardening the accounts that scammers target after a delivery-themed message succeeds. Older adults should not need to become cybersecurity specialists to receive parcels safely, and caregivers can help configure these controls once and review them regularly.
Use a password manager to create a different password for each major shopping, email, and payment account. Turn on multifactor authentication wherever it is offered. An authenticator app or security key is safer than approving an unexpected sign-in request.
Review active sessions and connected devices in retail, email, and payment accounts. Sign out devices you do not recognize, remove old addresses, and delete saved cards that are no longer needed. These checks limit what a criminal can access if a fake shipment message leads to stolen credentials.
Delivery scams now extend beyond obvious phishing texts. Fraudsters copy carrier branding and write convincing exception notices that exploit genuine shipment anxiety. Brushing and fake-shipment schemes can also create unfamiliar orders or tracking activity, so account reviews matter even when the message looks professional.
Add a screening layer
Gini Help is one option for people who want protection across calls, email, and SMS in one app. Its service uses AI to screen unknown calls, analyze messages and emails, and provide live call analysis when a user answers. Family plan options share threat intelligence across members, which can help a caregiver and older relative recognize the same scam patterns.
Download it through Google Play or the App Store. A screening service does not replace checking an order through a trusted account, but it can reduce suspicious contacts reaching a person in the first place.
Secure the delivery point as well. Use delivery instructions, collection points, or a trusted recipient when parcels might otherwise sit outside. For household and mailbox measures, the Business Mail Boutique LLC package theft guide complements digital safeguards.
What to Do If You've Been Targeted or Victimized
Receiving a suspicious message doesn't mean you've been harmed. If you haven't clicked or replied, preserve the message for reporting, block the sender, and delete it. Don't test the link, call the number, or respond to ask whether it's genuine.
If you entered card or bank information, contact the financial institution immediately through its official number. Ask what protective action is appropriate, review recent transactions, and follow the institution's instructions about replacing the card or securing the account. If you entered a password, change it from the official website and change it anywhere else you reused it.
Follow the right response order
- Stop contact. Close the page and disconnect from the scammer. Don't negotiate or promise payment.
- Secure financial accounts. Contact your bank or card provider using a trusted channel if financial details were exposed.
- Change credentials. Update compromised passwords, beginning with email and shopping accounts. Enable multifactor authentication.
- Save evidence. Keep screenshots, sender details, the full message, transaction records, and package labels.
- Report the fraud. Submit a report through ReportFraud.ftc.gov, even if you didn't lose money.
Reporting helps authorities identify patterns and gives investigators information about campaigns that may be targeting other households. You can also report the message to the impersonated carrier through its official fraud-reporting process, but don't use contact details supplied by the suspicious message.
Handle unsolicited parcels carefully
If a parcel arrived without an order, the FTC says you don't have to return the merchandise or pay for it. Keep it, but don't scan QR codes, follow review prompts, or contact the sender. Change shopping-account passwords and report the incident, following FTC guidance on unexpected packages.
The package may be part of a brushing operation that uses your identity to create fake reviews. It can also signal that an account, address, or personal detail deserves closer examination. Check account activity directly and tell household members not to engage with the package's printed instructions.
Protecting Vulnerable Family Members
Caregivers should take an active role before a suspicious message arrives. Older adults are often targeted through familiar routines, and a scammer needs only one rushed decision. A calm family agreement gives your relative permission to pause and ask for help without feeling embarrassed.
Set up a simple rule together: no unexpected delivery payment gets made until another trusted person verifies it. Add that rule to a written card near the phone or computer. Store official retailer and carrier apps in an easy-to-find folder, and remove unfamiliar apps, browser notifications, and saved payment methods that aren't needed.
Family members should also help with account protection. Use unique passwords, multifactor authentication, bank alerts, and a shared process for reviewing unusual messages. If you use a family protection service, choose one that can screen multiple contact channels and share relevant threat information with the people who provide support.
Watch for changes rather than waiting for a confession. Warning signs include unexplained parcels, new urgency about bills, unfamiliar account alerts, repeated calls from supposed carriers, or sudden reluctance to discuss online activity. Ask open questions and avoid blame. Scammers create the problem, not the person who was deceived.
Teach one sentence that works under pressure: “I won't click this. I'll check the order another way.” Practise it together using a harmless example. That small habit can interrupt the moment when package delivery scams are most effective.
Gini Help screens calls, texts, and emails for scam signals, including delivery-themed lures, and can provide live analysis during calls. Visit Gini Help to review the protection options, then install the app with a trusted family member and agree on a verification rule before the next suspicious delivery alert arrives.