The tiny parcel redelivery fee that puts your card at risk
Expecting a delivery makes the message believable. It does not make a payment link safe, even when the fee is only a few cents.

You really are waiting for a package. The text says the address is incomplete, delivery has failed, or a small redelivery charge is outstanding. The coincidence is persuasive: why would a delivery message arrive now unless it concerned your order? A moment later, you are entering a card to solve a problem that may never have existed.
The useful question is not whether you expect a parcel. It is whether this request can be connected to your actual shipment through a channel you already trust. A small fee, a correct-looking logo and a convenient arrival time do not make that connection. Neither does a page that remembers information you just typed into it.
Start with the order, not the text
Open the retailer’s app or the order confirmation you already had before the message arrived. Find the carrier and tracking number there. Then use the carrier’s independently opened website or app. If the order is being handled by a different carrier from the one in the text, that discrepancy is useful; if the names match, you still have to check the shipment itself.
People often skip this step because it feels slower than paying a nominal amount. Yet it answers a question that inspecting the message’s graphics cannot: is there an actual delivery issue attached to the order? A scam page can copy a familiar design. It cannot become the authoritative record of your shipment simply by displaying a tracking-shaped number.
Be cautious about universal statements. Carriers have different customs, delivery and payment arrangements, and a legitimate charge can exist in some circumstances. This guide does not claim that every carrier payment is fraudulent. It recommends resolving any real charge through the carrier or retailer you independently identified, rather than through an unsolicited link.
What the Postal Inspection Service actually says
The U.S. Postal Inspection Service’s package-text guidance, updated in May 2025, explains that unsolicited tracking messages with unfamiliar links can be smishing. It describes USPS tracking notifications as a service requested for a specific tracking number, not an unexpected demand to provide financial details. Its advice includes independently visiting USPS and reporting suspicious messages.
That is a USPS-specific statement. Do not stretch it into a technical rule covering every logistics company worldwide. For another carrier, check that company’s own guidance. The portable lesson is about origin: you should be able to reach the shipment record without depending on the suspicious message’s link, phone number or instructions.
The exposure ladder: four different situations
You only received the message
Receiving a text is not evidence that someone controls your device or knows your shopping history. Package deliveries are common, so a broad message can coincide with a real order. If there is no independent sign of trouble, report the message and check the actual shipment through your normal route. You do not need to reply to ask which parcel they mean.
You opened the link but entered nothing
Close the page. Note whether it asked you to download an app, install a profile, allow notifications or provide credentials. A visit is not the same event as typing a card or executing software. Avoid both extremes: do not declare the device certainly compromised, but do not ignore an installation or security warning that actually occurred.
Keep the device and browser updated. If something was installed or an unfamiliar permission was granted, use the device maker’s official support guidance or trusted assistance. Do not use a cleanup service advertised by the suspicious page itself. The page is not qualified to diagnose the problem it claims you have.
You entered personal or payment information
Make a list of the fields, not a screenshot containing all their values. “Name, address, phone, card number, expiry and security code” is enough to explain the type of exposure. Contact the relevant card issuer promptly. If you typed banking credentials or reused an account password, treat that as a separate account-security issue.
You also approved a verification prompt
Read the original bank message again through the official message or app, without following new links. What action did it describe? Tell the issuer whether it referred to a purchase, adding a card, signing in or something else. Do not assume a code was merely confirming your shipping address because the scam page called it “delivery verification.”
“It declined my card” is not reassurance
A legitimate declined purchase means the attempted payment was not approved. A message on an untrusted page does not carry the same meaning. It could be an arbitrary screen designed to request another card. You cannot infer the backend result from the page’s wording.
| What the page said | What you actually know | Safer next step |
|---|---|---|
| Payment failed | The page displayed an error | Stop retrying; tell the issuer the details were entered |
| Try a different card | The site wants another payment instrument | Do not expand the exposure |
| Confirm with a code | A separate authorization may be involved | Read the issuer’s original prompt and contact it independently |
| Your parcel is now released | The site displayed a success message | Check the real tracking record |
The Postal Inspection Service also advises notifying the financial institution after interacting with the suspicious URL, even where the person did not press a final submit button. The practical reason to be cautious is that a form’s visible completion state cannot reliably tell you whether typed information stayed private.
A recovery sequence for a busy person
First, stop the interaction. Do not return to inspect whether the site now works, and do not call a number it presents as support. Second, contact the issuer of every card you entered. A temporary card lock can be an interim measure where available, but ask the issuer whether replacement or another restriction is needed.
Third, separate account credentials from card details. A replacement card does not change a password you also entered. Use a trusted route and device to secure the affected account, review recovery information and inspect recent activity. If the same password was used elsewhere, those accounts need attention too. Avoid changing unrelated accounts blindly while overlooking the one credential you actually exposed.
Fourth, keep the shipment problem separate. If your real tracking record shows a delivery exception, resolve that with the genuine carrier. Being targeted by a scam does not automatically mean the parcel is lost. It also does not mean the retailer caused the message. Do not infer a specific data breach from timing alone.
Finally, preserve a short private record: time, sender, claimed carrier, suspicious address, information entered, transactions noticed and support references. This gives you something concrete to use if an issuer asks for more details later.
The follow-up call can be a second trap
After entering a phone number and card details, an unexpected caller may appear to know exactly what happened. That knowledge can feel like proof that the caller is the bank. It is not. The information may simply come from the form or from another source.
End the incoming call and contact the institution yourself. Do not move money, disclose a one-time code or install remote-support software because a caller says the parcel scam made it necessary. Our bank impersonation guide covers the “protect your money” pretext, while fake support and refund requests explains another common route into a second incident.
If you are helping a relative, offer to sit with them during the official call. Do not take over their accounts or ask them to send you full card details. Calm company and a written sequence are often more helpful than a long lecture on how suspicious the text looked in hindsight.
Questions that often arrive after the panic
I used a false address. Does that protect my card? No. An inaccurate field does not make the real card fields private. Tell the issuer which information was genuine. Do not test the site again with additional invented data.
I have no new charge. Can I forget it? The absence of an immediate charge is useful information, but it does not establish that exposed details are safe. Ask the issuer how to handle the exposure and what account activity to watch.
Should I warn the retailer? You can report impersonation through a verified support route, particularly if the message named the retailer. Describe what you observed without claiming a breach you cannot establish. The retailer may be able to clarify tracking, but your issuer handles card protection.
Is every delivery text now untrustworthy? No. The goal is not to stop using useful notifications. It is to avoid letting a notification become the sole authority for an unexpected payment or credential request.
Sources and reporting
- USPIS: package tracking text scams, including its current reporting instructions.
- FTC: recognizing and reporting spam texts.
For U.S. USPS impersonation, use the reporting route on the Postal Inspection Service page. Messaging-app spam controls and 7726, where supported, provide additional reporting options. Reporting a message is different from restricting a card: if details were exposed, do both relevant jobs. For a similar small-payment trap on the road, see unpaid toll texts.
Found a factual error or a source that has changed?
Send a correction →

