SardineCon SF/2026

Learn More

What is Delivery smishing scam?

Subscribe to newsletter

A delivery smishing scam is a text posing as a delivery company about a missed package or fee, linking to a page that harvests card details or logins. It rides on how many parcels people expect, so a message about a delivery problem feels routine rather than suspicious.

What is a delivery smishing scam?

Delivery smishing is phishing delivered by text message, dressed as a parcel notification. The text claims a package could not be delivered, that a small customs or redelivery fee is owed, or that an address needs confirming, and it includes a link. The link leads to a lookalike site that harvests personal data, card details, or account logins.

The scam thrives on volume and plausibility. Almost everyone is expecting something in the mail, so a generic delivery text has a decent chance of reaching someone who genuinely has a parcel in transit. The requested amount is deliberately tiny, often a dollar or two, because the goal is not that fee. The goal is the card number and personal details entered on the fake page, which can then be used for card fraud, account takeover, or resale.

For fraud teams, delivery smishing is a top of the funnel technique. On its own it is just a text, but it feeds downstream fraud: card-not-present charges, new-account fraud from harvested identity data, and takeovers when the harvested credentials match a real login.

How a delivery smishing scam unfolds

The message is only the opening move in a longer harvest:

  1. BlastSend at scale Bulk texts posing as a courier go to huge lists, needing only a small hit rate to pay off.
  2. LureClaim a delivery problem A missed parcel, a redelivery slot, or a tiny customs fee prompts the recipient to tap the link.
  3. HarvestCapture data on a fake page A convincing lookalike site collects name, address, card details, and sometimes a login.
  4. ExploitCash out downstream The stolen data drives card-not-present fraud, new-account fraud, or account takeover, or is resold.
    • ImmediateCard testing Harvested cards run through small test charges to confirm they work.
    • LaterIdentity reuse Personal data feeds account takeover or new-account fraud weeks later.

Who is involved?

Who

Their role

The smishing operator

Sends the bulk texts, runs the fake page, and collects the harvested data.

The recipient victim

Enters card and personal details believing they are fixing a real delivery.

The phishing-kit provider

Supplies the lookalike site templates and hosting, often sold as a kit or service.

Banks and merchants

Absorb the downstream card-not-present fraud and account takeovers the harvested data enables.

What it looks like in practice

A cardholder who is genuinely waiting on a parcel gets a text from what looks like a courier: the package is held pending a small unpaid delivery fee, tap here to reschedule. The linked page mirrors the courier's branding, asks for the delivery address, then requests card details to pay the fee.

The cardholder pays the small amount and moves on. Within a day, a run of tiny authorizations appears on the card as the details are tested, followed by a larger card-not-present purchase from an unfamiliar merchant. The address and name harvested alongside the card later surface in an attempt to open a new account.

Why it matters for operators

Delivery smishing is cheap to run and relentlessly high volume, so a bank will see its effects continuously rather than as isolated events. The damage does not stop at the tiny fee; it is the fresh, valid card and identity data that matters, because that data fuels card-not-present fraud and later account and identity attacks.

Because the harvested cards are newly captured and known-good, they often behave like textbook card testing: a burst of small authorizations to confirm the card works, then a jump to real spend. Spotting that testing signature quickly, and correlating card-not-present fraud back to recent smishing waves, lets a team blunt an entire campaign rather than chasing one disputed charge at a time.

What to watch in the data

  • Card-testing bursts. Clusters of small authorizations on many cards in a short window, a classic sign freshly harvested cards are being validated.
  • Tiny fee, new merchant. A small charge described as a delivery or customs fee to a merchant the customer has never used.
  • Shared harvest fingerprints. Multiple compromised cards linking back to the same fake page, hosting, or short window.
  • Fresh-data account attempts. New-account or takeover attempts using name and address combinations recently seen in smishing lures.
  • Spoofed sender patterns. Delivery texts from rotating numbers or shortened links, reported through customer contact channels.

Quick questions

Why do the scammers ask for such a small fee?

The fee is bait, not the payoff. Entering it hands over the card number and personal details, which are worth far more through downstream card fraud, account takeover, and resale than a one or two dollar charge.

Why is the delivery theme so effective?

Most people have a parcel in transit at any given time, so a delivery-problem text feels routine. High message volume plus that plausibility means even a low response rate yields plenty of victims.

What happens to the harvested card data?

It is often validated with small test charges, then used for larger card-not-present purchases or sold. The accompanying identity data can drive new-account fraud or account takeover later.

How is smishing different from email phishing?

Same goal, different channel. Smishing arrives by text, which tends to feel more immediate and personal, has fewer spam filters, and often uses shortened links that hide the real destination.

How can operators connect the texts to fraud they see?

By correlating card-testing bursts and card-not-present fraud back to shared harvest sources and timing. Linking many compromised cards to one campaign lets you act on the wave rather than individual charges.

What should customers be told?

Do not tap links in delivery texts. Check parcel status directly on the courier's official app or site, and never enter card details to release a package over a texted link.

What to know alongside Delivery smishing scam

Report

2026 Fraud and AML Report

Skip the predictions. This report breaks down what fraud and AML teams are actually dealing with, and how to respond.

Download report