The Fake Delivery Text
A message saying your parcel is held at customs, asking for a small payment or a tap on a link. The most common scam message there is.
What it looks like
- A short text: your parcel is held at customs, the address was incomplete, or delivery failed.
- It contains a shortened link (bit.ly, tinyurl, or a domain you do not recognise).
- The amount asked for is small — £1.99, €2.40. Small enough to look not worth arguing about.
How to spot it
- Are you actually expecting a parcel? If not, the answer ends here.
- Look at the domain in the link. A courier's address ends in the courier's own name; "parcel-track-uk.xyz" does not belong to anyone.
- Couriers do not collect customs fees through a link in a text. Payment happens on their own site or at a depot.
- The message hurries you: "pay within 24 hours or the parcel is returned." The hurry is there to stop you thinking.
What to do
- Do not tap the link. Delete the message.
- If you really are expecting a parcel, type the tracking number into the courier's own app or website yourself.
- Block the number and report it — the same message is going to thousands of other people.
If it already happened
- If you entered card details, call your bank now and have the card stopped. Call even at 3am; banks have 24-hour lines for exactly this.
- If a payment went through, ask your bank for a chargeback. The first 24 hours give the best chance.
- If you installed an app, remove it, restart the phone, and change your banking passwords from a different device.
- There is nothing to be embarrassed about. These messages go to millions of people and are written to be convincing. The sooner you call, the better the outcome.
Common questions
I tapped the link but did not enter anything. Am I at risk?
Almost certainly not. Opening a page is usually harmless; the risk begins when you type something in or download a file. If an app was downloaded, remove it and restart the phone.
The sender name was a real courier. How?
The sender name on a text can be set to anything — it is called sender ID spoofing. The name proves nothing. Look at the link and at what is being asked for.