Fake Parcel Delivery Scams Steal Financial Data via Phishing Websites
Global phishing campaigns impersonating parcel delivery services are tricking users into visiting fake courier websites to steal sensitive personal and financial information.

Cybercriminals are increasingly leveraging sophisticated phishing campaigns that impersonate well-known global parcel delivery services to defraud unsuspecting individuals. These scams, which have been observed targeting customers of major postal operators such as USPS, Colissimo, bpost, Correos, and PostNL, aim to trick recipients into visiting malicious websites designed to harvest their sensitive data.
The modus operandi typically begins with an unsolicited email or message claiming a delivery issue, such as an unpaid customs fee or an undeliverable package due to an incorrect address. For instance, a recent campaign targeting bpost customers in Belgium involved an email demanding a small customs duty of €4.95, an amount small enough to encourage immediate payment without deep scrutiny. The messages often include tracking numbers and branding that closely mimic legitimate postal services to enhance their credibility.
Upon clicking a link within the deceptive message, users are often redirected through URL-shortening services to a fake courier website. These fraudulent sites meticulously replicate the visual design and branding of legitimate postal services, even displaying false security claims like "Secure SSL connection" and "SEPA compliant" to lull victims into a false sense of security. The goal is not merely to collect the purported fee but to extract a wide range of personal and financial information.
The scam progresses through multiple stages, first requesting basic personal details such as name, phone number, email address, and age. Subsequently, victims are prompted to enter banking information, including IBANs and card numbers with expiry dates. In some instances, the scam may even reference receiving funds, a tactic designed to confuse the user and mask the true intent of stealing payment details.
Once submitted, this sensitive data is immediately at risk. Threat actors can use stolen card details for fraudulent purchases or sell them on the dark web. The personal and banking information gathered can also be leveraged for future, more targeted social engineering attacks or identity theft. The sophistication of these campaigns lies in their ability to mimic legitimate services and exploit the common expectation of receiving packages.
To protect against such threats, cybersecurity experts advise users to independently verify any delivery claims. This involves opening the courier's official app or typing its website address directly into a browser to check tracking information, rather than relying on links provided in unsolicited messages. Users should also be wary of unexpected fees or requests for extensive financial information, especially when linked to minor delivery charges.
If a user suspects they have entered their information on a fraudulent site, immediate action is crucial. Contacting the bank or card provider to freeze the affected card and monitor accounts for suspicious transactions is paramount. Changing passwords used on the suspicious site is also recommended. Security software, such as Malwarebytes' Scam Guard, can assist in analyzing suspicious messages and links before users interact with them, providing an additional layer of defense against these evolving phishing tactics.