By Jackson Godwin.Cybersecurity Analyst & Penetration Tester

The Package Delivery Text That Was Actually a Hacker
Disclaimer: This story is fictional but inspired by real package delivery scams, SMS phishing (“smishing”) attacks, and identity theft cases. It is written to educate readers about cybersecurity awareness and safe online practices.
The Text Arrived at the Perfect Time
I had ordered several items online that week.
One package was still marked “Out for Delivery.”
So when my phone buzzed, I didn’t think twice.
The text message read:
“Your package could not be delivered due to an incomplete address. Please confirm your delivery details here.”
A link appeared below the message.
Everything seemed normal.
It Looked Like a Real Delivery Company
When I opened the link, the website looked identical to a major courier service.
It displayed:
- The company’s logo.
- Tracking information.
- Delivery status.
- Customer support links.
- Professional branding.
The page even showed my package as:
“Awaiting Address Confirmation.”
I immediately believed it was genuine.
The Delivery Fee Was Tiny
After confirming my address, another message appeared.
“A delivery reprocessing fee of $2.99 is required before your package can be released.”
Only $2.99.
That didn’t seem unusual.
Many courier companies charge small redelivery or customs fees.
I clicked Continue.
They Asked for My Card Details
The payment page requested:
- Card number.
- Expiration date.
- CVV.
- Billing address.
Everything looked secure.
There was even a padlock icon in my browser.
I entered my information.
The page loaded for several seconds.
Then displayed an error.
“Payment failed. Please try again later.”
I closed the website and decided to wait.
My Package Never Arrived
The following day, I checked the tracking number again.
This time, I visited the courier’s official website.
The tracking number didn’t exist.
Confused, I searched my email for the original shipping confirmation.
The tracking number in my order confirmation was completely different.
The text message had never been connected to my package.
Then My Bank Called
That afternoon, my bank’s fraud department contacted me.
The representative asked:
“Did you recently authorize several international online purchases?”
I hadn’t.
I immediately opened my banking app.
Multiple payment attempts had been made using my card.
The tiny $2.99 delivery fee had only been bait.
The scammers never wanted to deliver a package.
They wanted my payment information.
One Click Changed Everything
Looking back, the timing made the scam almost impossible to question.
I really was expecting a package.
The fake message arrived at exactly the right moment.
The attackers hadn’t guessed.
They had taken advantage of something millions of people experience every day.
Waiting for a delivery.
(Continue in Part 2, where I’ll explain how the fake delivery website fooled thousands of victims, reveal how the attackers used the stolen payment details, and show the warning signs I completely missed.)







