By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Investigation Revealed a Global Scam
A few weeks later, my bank completed its investigation.
The fake delivery website wasn’t operated by a real courier company.
It was part of a larger phishing network targeting thousands of people every day.
The criminals continuously created new fake websites using names that closely resembled legitimate delivery companies.
When one website was reported and shut down, another quickly took its place.
The packages changed.
The company names changed.
The scam remained the same.
Why Delivery Scams Are So Successful
The fraud investigator explained why these attacks fool so many people.
Almost everyone shops online.
Almost everyone waits for deliveries.
Scammers take advantage of this everyday routine.
Instead of sending random phishing emails, they exploit a situation people already expect.
If you’re waiting for a package, a delivery problem feels believable.
That is exactly what makes the scam so effective.
The Small Fee Was Never Important
Looking back, I realized something.
The scammers didn’t care about the $2.99.
Their real goal was much more valuable.
They wanted:
- My payment card details.
- My billing address.
- My name.
- My phone number.
The fake delivery fee simply encouraged me to enter everything voluntarily.
Warning Signs of Package Delivery Scams
Several warning signs became obvious after the investigation.
🚩 Unexpected Text Messages
If you receive a delivery notification you weren’t expecting, verify it before clicking any links.
Don’t assume every package text message is genuine.
🚩 Requests for Small Payments
Fraudsters often request very small amounts like:
- $1.99
- $2.99
- $3.50
These amounts seem harmless but are commonly used to trick victims into entering payment information.
🚩 Suspicious Website Addresses
Always check the website address carefully.
Scammers often use domain names that closely resemble legitimate courier companies but contain:
- Extra letters.
- Missing letters.
- Hyphens.
- Different domain endings.
One small difference can mean you’re on a fake website.
🚩 Pressure to Act Immediately
Messages such as:
- “Your package will be returned today.”
- “Confirm within two hours.”
- “Final delivery attempt.”
are designed to make you act before thinking.
Legitimate companies generally provide multiple ways to verify delivery information through their official websites or apps.
🚩 Payment Before Delivery
If you’re asked to pay unexpected fees through a link in a text message, verify the request using the courier’s official website or customer service before entering any information.
How to Protect Yourself
Simple habits can help prevent these scams.
- Track packages using the retailer’s official website or app.
- Visit courier websites by typing the address yourself instead of using links in unexpected messages.
- Enable transaction alerts through your bank.
- Never enter payment information on websites reached through unsolicited text messages without verifying them first.
- Report suspicious messages to your mobile carrier or the impersonated company when possible.
- Delete phishing messages after reporting them.
A few extra minutes of verification can prevent weeks of financial recovery.
Frequently Asked Questions
Are all package delivery text messages scams?
No.
Legitimate delivery companies do send tracking updates.
However, if a message asks for unexpected payments or personal information, verify it through the company’s official website or app before taking action.
What is “smishing”?
Smishing is a form of phishing that uses SMS or text messages instead of email to trick people into revealing sensitive information or visiting fraudulent websites.
What should I do if I entered my card details?
Contact your bank or card issuer immediately using its official contact information.
They can block your card, monitor for fraudulent activity, and advise you on the next steps.
Final Thoughts
I thought I was solving a delivery problem.
Instead…
I handed my payment information to criminals pretending to be a courier company.
The text looked genuine.
The website looked professional.
The payment amount looked harmless.
Everything had been carefully designed to earn my trust.
The lesson I learned was simple.
Never trust a delivery text simply because you’re expecting a package.
Verify first.
Click later.
Because the next message in your inbox could be from a delivery company…
Or from a hacker pretending to be one.
About the Author
Jackson Godwin is a Cybersecurity Consultant specializing in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
Through JacksonTechnology.com.ng, he publishes cybersecurity awareness stories, ethical hacking tutorials, compliance guides, and practical online safety advice to help individuals and organizations recognize phishing attacks, online shopping fraud, payment scams, ransomware, identity theft, AI-enabled scams, and other emerging cyber threats.
His mission is to make cybersecurity practical, relatable, and accessible—one cyberstory at a time.







