Fake tracking links: the parcel scam built for impatient buyers
Your phone buzzes: your parcel could not be delivered because of an unpaid fee, and a link will fix it. If you are expecting a package, the message lands at the worst possible moment. That is the point.
The click you were set up to make
Fake delivery notices are now the most commonly reported text scam in the United States. FTC data show consumers lost $470 million to text scams in 2024, with bogus package delivery alerts topping the list of reported fraud types (https://www.ftc.gov/news-events/news/press-releases/2025/04/new-ftc-data-show-top-text-message-scams-2024-overall-losses-text-scams-hit-470-million). The scam does not fight your skepticism. It waits for a moment when you have none left. The timing is statistical, not personal. Scammers send millions of messages knowing that some recipients genuinely do have parcels in transit. AARP surveys found 55 percent of US adults received a fraudulent shipping notification in the past year, up from 29 percent in 2022 (https://www.aarp.org/money/scams-fraud/fake-usps-ups-smishing-texts/). Volume is the strategy; conversion takes care of itself.Inside a cloned tracker page
Click the link and you typically land on a pixel-perfect copy of a postal tracker: real logos, real fonts, sometimes even a plausible tracking number and simulated delivery history. Many kits go further. Researchers at Censys documented one USPS-impersonating kit that served USPS's own production HTML, CSS, and fonts verbatim from the phishing host, complete with the agency's live Google Analytics tag firing on every victim visit. The forms ask for exactly what a redelivery would require: name, street address, phone number, and a small card payment of two or three dollars. The United States Postal Inspection Service is blunt about the tell it wants consumers to remember: USPS does not send unsolicited texts with links, so any such message is fake by definition (https://www.uspis.gov/news/scam-article/smishing-package-tracking-text-scams). FedEx and UPS post similar warnings. Modern kits also stage trust theater before the theft. Forcepoint analysts described a DHL campaign with a fake one-time-code page that verified nothing but made the following password field feel routine (https://www.forcepoint.com/blog/x-labs/fake-dhl-phishing-campaign-credential-theft). A parcel page never needs your account password or a second card after the first "declines." When it asks anyway, that is the payload.What actually gets harvested
The small fee is bait; the data is the business. A completed form yields a full identity kit — name, address, phone — plus live card details, all of which feed card-not-present fraud and follow-up scams tailored to people who just proved they respond to delivery texts. In one UK experiment, researchers who submitted test cards to twelve smishing URLs watched scammers attempt cash-outs within days, mostly small cross-border charges designed to slip past fraud checks. Address harvesting has its own resale market. Knowing where someone lives, when they are home, and which carrier they use supports parcel interception, brushing schemes, and convincing pretext calls later. The tracking link is often step one of a longer playbook, not a one-off heist.An industry, not a hustle
This is phishing-as-a-service at scale. Netcraft traced the "darcula" platform across more than 20,000 phishing domains targeting postal services in over 100 countries, distributed through iMessage and RCS specifically to bypass SMS firewalls (https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services/). Resecurity's investigation of the "Smishing Triad" found kits renting for around $200 a month, complete with admin panels, statistics dashboards, and Telegram support (https://www.resecurity.com/blog/article/smishing-triad-targeted-usps-and-us-citizens-for-data-theft). Infrastructure rotates faster than blocklists can follow. Infoblox researchers counted 40 to 160 new USPS-themed domains registered per day, spread across at least sixteen distinct criminal operators using domain-generation algorithms (https://ddi.mohflo.net/index.php/2023/12/21/phishers-weather-the-storm-the-dns-landscape-of-u-s-postal-smishing-attacks/). Some kits even redirect desktop browsers to the genuine site, showing the phish only to mobile users. The lesson from why phishing mirrors work applies directly: familiarity is doing the lying.Habits that beat the hook
You cannot spot these links by squinting anymore, so change where you click rather than what you notice. Verification belongs in your own apps and bookmarks, never in a pushed link.- Delete any delivery text you did not request; carriers say unsolicited tracking texts are always fake.
- Type the carrier's address yourself or open its official app, then paste the tracking number manually.
- Treat any "small fee" as a red flag, not a rounding error — no legitimate carrier collects it via text link.
- If you already entered card details, call your bank immediately and watch statements for tiny test charges.