goJumboGPT

Security Scams: how they work and what to do if you fall for one

Parcel scams: the fake delivery text and the small fee trick

Why the missed delivery text asking for a small redelivery fee is so effective, what the scammers really want, and how to check a real delivery.

6 min read How we write

The short answer

  • The one or two dollar fee is bait, not the prize: the card details you type are what the scam is for.
  • A real courier will not text you a link asking for a card payment to release a parcel.
  • Check any delivery by typing the tracking number into the courier's own app or site, never through the link you were sent.
  • Expect a follow up call a few days later from a fake bank fraud team, because that is where the real money is taken.
  • If you already paid, cancel the card rather than just watching the account.

The fake missed delivery text works because it is small, plausible and cheap to say yes to. A parcel is waiting, a fee of 1.99 is outstanding, and the sum is too trivial to argue with. That is the design. The fee is not the target and never was. The target is the card number, expiry date, security code and billing address you type on the payment page, plus the confidence that you will pick up the phone when someone calls a few days later claiming to be your bank's fraud team.

The economics, which explain everything else

Think about the numbers from the sender's side. Sending text messages in bulk costs very little. A couple of dollars per victim would be a poor business. Full card details with a matching name and address are worth far more, because they can be resold, used for card not present purchases, or used to enroll the card in a digital wallet.

The small payment does three useful things for the scammer at once. It confirms the card is live and funded. It captures the security code, which is not stored on a merchant's system after a normal purchase. And it establishes a relationship, because you now have a genuine transaction on your statement that a caller can quote back to you. That quoted transaction is what makes the second stage work.

Some versions add a subscription. The small print on the payment page, if there is any, signs you up to a recurring charge of 30 or 40 dollars a month, which continues quietly until you notice.

The variants you will meet

VariantThe messageWhat makes it plausible
Redelivery feeWe missed you, pay 1.99 to rescheduleEveryone has missed a delivery
Customs or duty chargeYour item is held, pay import chargesDuty and import VAT on small parcels are genuinely collected now
Address correctionYour address is incomplete, confirm itAddress errors really do happen
Failed payment at checkoutYour order could not be processed, update your cardCard declines are common
QR code noticeA card through the door, or a sticker on a lockerPaper feels official, and a QR code hides the address
Fake tracking emailYour parcel is delayed, track it hereIdentical layout to the real courier email

Customs charges are the most convincing, because they are real. Many countries now collect small amounts of tax on low value imports, and couriers do pass those charges on. The difference is how: a real courier collects through its own app, its own website with your tracking number, or an invoice it can show you inside your account, not through a link in an unsolicited text, which is ordinary phishing with a courier logo on it.

It is worth knowing why the message reached you at all, because people often assume the sender knew about a real order. Usually nobody did. Mobile numbers are worked through in blocks, sometimes straight along a range and sometimes from contact lists that leaked years ago, and the same text goes out to everyone at once. The sender only needs a small share of recipients to be expecting a parcel that week, which is why the volume rises around sale periods and the weeks before Christmas. If your number and email have turned up in a breach at some other company, expect more of these, not fewer.

QR codes deserve special caution because they show you nothing. A sticker placed over a genuine code on a parcel locker or a delivery notice is invisible. If you scan one, read the domain in the address bar before you touch anything on the page.

Checking a delivery properly, in four steps

  1. Do not tap the link. Close the message.
  2. Find the tracking number from your order confirmation in the retailer's account or in your email, not from the text.
  3. Open the courier's own app, or type the courier's address into your browser yourself, and paste the tracking number there.
  4. If nothing matching exists, there is no parcel, and the message can be deleted and reported.

If you genuinely owe a customs charge, it will be visible inside that official tracking page. It will also still be there tomorrow. Real fees do not expire in two hours.

The follow up call is the expensive part

Days or weeks after you pay the small fee, the phone rings. The caller ID may show your bank. The agent is calm, apologetic and helpful, and mentions the small suspicious payment you recognize, because you made it. They say your card has been compromised and that the account must be secured. Then comes the request: read back the code we have just sent you, or move your balance to a new safe account while we investigate.

That is the real theft, and the small payment was the setup that makes it believable. No bank ever asks for a one time code, and no bank moves your money to a safe account. If a transfer has already left, the first hour is the one that counts. The full script and the rules that break it are in bank impersonation scams, and the reason the caller ID means nothing is explained in phone scams and spoofed numbers.

If you already paid

Do these in order, today.

First, call your card issuer using the number on the back of the card, say that the details were entered on a fraudulent site, and ask for the card to be canceled and reissued. Blocking is better than monitoring, because the details are already gone. Second, ask them to look for any recurring authority set up on the card and remove it. Third, dispute the charge itself; small amounts are routinely refunded, and the process for both credit and debit cards is described in disputing a payment and chargebacks.

Think about what the payment page collected as well as what it charged. Your name, full billing address, card number, expiry date and security code arrive together in one record, and many of these pages also ask for a date of birth or a mobile number for a confirmation code. That combination is worth more than the card alone, because it is enough to attempt a takeover of an account somewhere else or to apply for something in your name. Watch for post addressed to you that you did not expect, a credit check you did not ask for, or a message about an account you never opened, since the early signs of identity theft are quiet and easy to miss.

Then prepare for the call. Tell anyone else in the household what to expect. If someone rings claiming to be the bank, hang up and call the number on the card yourself, even if they are convincing, especially if they are convincing.

Finally, report it. In the US, reportfraud.ftc.gov, and forward the text to 7726. In the UK, forward to 7726 and report to Action Fraud. In Canada, the Canadian Anti-Fraud Centre. In Australia, Scamwatch. In Ireland, report to your bank and your local Garda station.

What to check first

Look at your last two card statements for small unfamiliar payments, especially anything between one and five dollars, pounds or euros. Those test charges are the fingerprints of this scam and they often appear before anything larger. If you want a general method for judging any message rather than just parcel ones, the red flags checklist takes about ten seconds per message and works on all of them.

Common questions

Why do these texts arrive when I really am expecting a parcel?

Because almost everyone is. The messages are sent in huge batches with no knowledge of your orders, and the timing that feels uncanny is coincidence doing the work of research.

How do they know my name?

Usually from a data breach, a marketing list or a leaked customer database. A name in a text proves someone bought a list, not that they are delivering anything to you.

I scanned a QR code on a parcel locker notice, is that a problem?

It is a problem only if you entered something afterward. Check the address in the browser bar. If you typed card or account details, treat it exactly like tapping a scam link and call your card issuer.

The fee was only two dollars and it went through, so what did I lose?

The payment was a test that your card works. The card number, expiry, security code and your address are now saleable, and the same details are used to set up recurring charges or to make the follow up phone call convincing.