Fake parcel delivery messages steal your card and bank details

Imported from official source

Cybersecurity Classified by Officially

Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands.

The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information.

A fake bpost delivery email

A recent campaign targeting customers of the Belgian postal service bpost begins with an email claiming that a package could not be delivered because €4.95 in customs duties has not been paid.

A phishing email, in Dutch, pretending to be from bpost. 

In English, the subject and message read:

Undelivered package—customs duties due (tracking no. 3232116291*******).

Your package could not be delivered on September 9, 2026, because the customs duties (€4.95) have not been paid.

The amount is small enough that recipients may pay without giving it much thought. However, the website does not stop at collecting the supposed fee. It asks for personal information, card details, and banking information.

How the scam works 

The link first passes through a URL-shortening service (hxxps://qr[.]paps[.]jp/1GWsa) before redirecting to a fake bpost site. The campaign used several fake bpost domains, including:

hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/

bpost[.]center, which is the domain shown in the screenshots below.

The page copies bpost’s branding and displays security claims such as “Secure SSL connection,” “256-bit SSL,” “SEPA compliant,” and “Secure payment.” These labels were added by the scammers and do not prove that the page or payment is secure.

We’ve translated the screenshots below from the original Dutch into English.

The first page asks for the recipient’s name, phone number, email address, and age:

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-you...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.