By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Fraud Investigator Knew the Scam Immediately
As soon as I reported the unauthorized transactions, my bank assigned a fraud investigator to my case.
The first thing he asked was:
“Did you recently receive a package delivery text message?”
I nodded.
Before I could finish explaining, he said:
“We’ve seen this scam hundreds of times.”
That surprised me.
I had assumed I was one of only a few victims.
Instead, it was one of the fastest-growing SMS phishing scams.
The Website Was Never Real
The investigator examined the link from the text message.
At first glance, it looked identical to the courier’s official website.
But when he looked closely, the differences became obvious.
The domain name contained an extra letter.
The website had been registered only a few days earlier.
The contact page didn’t work.
The privacy policy had been copied from another company.
Everything about the site had been designed to imitate a trusted delivery service.
The Tracking Number Was Fake
I showed him the tracking number displayed on the website.
He searched the courier’s official tracking system.
Nothing.
The number had never existed.
The scammers generated fake tracking information simply to make victims believe a real package was waiting.
The package wasn’t delayed.
There was no package at all.
Why the $2.99 Fee Worked
The investigator explained something interesting.
If the scammers had demanded $500, most people would refuse immediately.
But a tiny delivery fee seemed believable.
People don’t worry about losing a few dollars.
They worry about missing an important delivery.
The small payment wasn’t the goal.
It was the excuse.
The Card Details Were the Real Prize
Once I entered my:
- Card number
- Expiration date
- CVV
- Billing address
the scammers had everything they needed to attempt fraudulent purchases.
The fake payment failure wasn’t a technical problem.
It was part of the scam.
They already had my information.
There was no reason to process the $2.99 payment successfully.
I Wasn’t the Only Victim
While researching online, I found reports from people across different countries.
Some received fake messages claiming to be from:
- USPS
- FedEx
- DHL
- UPS
- Royal Mail
- Local courier companies
Although the company names changed, the scam followed the same pattern.
A fake delivery problem.
A tiny payment.
A phishing website.
Stolen payment information.
Timing Was Their Biggest Weapon
The investigator explained why these attacks succeed so often.
Millions of people order products online every day.
Many are genuinely expecting packages.
Scammers don’t need to know whether you’re waiting for a delivery.
They simply send thousands of fake messages.
Eventually, some recipients will actually be expecting a parcel.
That’s when the scam feels believable.
I Changed More Than My Card
After replacing my payment card, I also:
- Changed important passwords.
- Enabled two-factor authentication.
- Reviewed my banking alerts.
- Became much more cautious about links sent by text message.
One fake delivery notification had completely changed how I handled SMS messages.
In the final part of this story, I’ll explain how package delivery phishing scams work, reveal the warning signs everyone should recognize, and share practical steps to avoid becoming the next victim.
Continue Reading: The Package Delivery Text That Was Actually a Hacker (Part 3)







