By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

I Looked at the Website Again
After closing the page, I decided to investigate it more carefully.
At first glance, it looked almost identical to the courier company’s official website.
It had:
- The company logo.
- Professional colours.
- Delivery icons.
- Tracking information.
- Customer service links.
Everything appeared genuine.
But when I looked closely, I noticed something important.
The website address wasn’t quite right.
The Web Address Was Fake
The scammers had copied the courier company’s name into the web address.
But they had added extra words and characters.
At a quick glance, it looked official.
When read carefully, it clearly wasn’t.
That small difference could easily be missed by someone who was in a hurry.
Cybercriminals know that most people don’t carefully examine website addresses before entering personal information.
The Tracking Information Didn’t Make Sense
The page claimed my parcel couldn’t be delivered.
Yet it didn’t display:
- My tracking number.
- The sender’s name.
- The delivery address.
- The item description.
- Any delivery history.
Instead, it simply displayed a generic message saying my package required another delivery attempt.
A real courier usually provides much more specific tracking information linked to your shipment.
Then I Noticed the Payment Page
The scammers weren’t asking for a large amount of money.
The so-called redelivery fee was very small.
That was intentional.
Many people won’t hesitate before paying a small fee.
The criminals weren’t interested in the fee itself.
They were interested in the payment card information entered on the page.
Once victims typed:
- Card number
- Expiry date
- Security code (CVV)
the scammers could attempt to misuse those details.
I Contacted the Courier Company
To be absolutely certain, I visited the courier company’s official website by typing its address directly into my browser.
Then I entered my genuine tracking number.
The result was completely different.
My parcel was still moving through the normal delivery process.
There had never been a failed delivery.
There was no outstanding fee.
The SMS had been entirely fraudulent.
The Timing Wasn’t a Coincidence
At first, I wondered how the scammers knew I was expecting a delivery.
The truth is…
They probably didn’t.
Thousands of people order products online every day.
Criminals send fake delivery messages to huge numbers of phone numbers.
Eventually, some recipients happen to be expecting genuine parcels.
Those people are far more likely to believe the message.
It’s a numbers game.
The Scam Was Built Around Convenience
The fake message offered what seemed like a simple solution.
One click.
One small payment.
Problem solved.
The criminals understood that people are busy.
Many of us prefer solving small problems quickly rather than investigating them.
That desire for convenience is exactly what the scammers exploit.
I Nearly Trusted the SMS
Looking back, I realised I almost trusted the message for one reason.
It arrived at exactly the right time.
That made the story believable.
If I hadn’t paused to verify the tracking information independently, I might have entered my payment card details without a second thought.
The Lesson Was Bigger Than One Scam
This wasn’t really about parcels.
Or delivery companies.
Or even online shopping.
It was about learning one important cybersecurity habit.
Never trust unexpected messages simply because they seem to match something happening in your life.
Always verify independently.
In the final part of this article, I’ll explain the biggest warning signs of delivery SMS scams, show you how to recognise fake courier websites, and share practical steps you can take to protect your bank cards and personal information from similar attacks.
Continue Reading: The Delivery SMS That Stole My Card Details (Part 3)







