Fake package-delivery messages are a recurring phishing tactic in the United States and other countries, often claiming that a shipment cannot be delivered until the recipient fixes an address problem or pays a small fee.
A recent campaign documented by Malwarebytes impersonated Belgian postal operator bpost and claimed that a package could not be delivered because a customs fee remained unpaid. The linked website then requested personal information, payment-card details and banking data.
Although the campaign targeted bpost customers, the same technique is common in the United States, where similar messages frequently impersonate the U.S. Postal Service.
A small fee can open the door to much more data
According to Malwarebytes, the bpost email sent recipients through a URL-shortening service before redirecting them to a site designed to resemble the postal operator’s legitimate website.
The fake page copied bpost branding and displayed security language such as “Secure SSL connection” and “Secure payment.” Those labels did not prove the site was legitimate; HTTPS can encrypt a connection without establishing that the website belongs to the organization it claims to represent.
The site first asked for personal details, then requested financial information including an IBAN, card number and expiration date.
The small delivery charge provides a plausible reason to start a payment process, while the information collected can be far more valuable. Card details may be used for fraudulent purchases, and personal or banking information can help make later scams more convincing.
Similar scams target USPS customers
The U.S. Postal Inspection Service warns about package-tracking “smishing” scams, a form of phishing delivered by text message. These messages may claim that a package cannot be delivered because of an address problem and direct the recipient to an unfamiliar website.
The agency says USPS tracking text messages are tied to tracking requests initiated by customers and advises consumers to be cautious of unsolicited delivery messages containing links.
Legitimate delivery charges can make these scams harder to judge at a glance. bpost’s official guidance, for example, says customers can receive genuine requests to pay import costs, but directs them to complete payments through its official app or Track & Trace service.
That makes independent verification the safer approach. Rather than using a link in an unexpected message, recipients can open the courier’s official app or type its known website address directly into a browser and check the shipment there.
Spelling mistakes and poor translations can expose some phishing attempts, but polished scam sites may closely resemble legitimate services. Unexpected requests for extensive financial information are a stronger warning sign, especially when a small delivery fee leads to requests for multiple forms of banking data.
For suspicious USPS-related texts, the Postal Inspection Service recommends forwarding the message to 7726 and reporting USPS impersonation attempts to the agency.
Anyone who has already entered card or banking information on a suspected phishing site should contact their bank or card issuer promptly, monitor accounts for unfamiliar transactions and freeze or replace affected cards when appropriate. Any password entered on the site should also be changed, particularly if it was reused elsewhere.

Leave a Reply