Awareness

“Your Package Is Delayed” SMS Scam

Published  ·  4 min read
Updated on February 26, 2026

This is currently one of the most consistently successful SMS phishing lures worldwide, especially in regions where people order frequently from e-commerce platforms (Amazon, Shein, Noon, AliExpress, local delivery services, etc.). The message almost always arrives looking like this (variations in English, Arabic, Turkish, Indonesian, etc.): *Your package is delayed due to unpaid customs fee of 4.99 USD.* *Click to pay & reschedule delivery: [shortened link]* *Order #3921746 – Expected tomorrow* or *Delivery issue: Your order #7845123 could not be delivered today.* *Reason: Address verification failed.* *Confirm & update details here: [bit.ly / tinyurl / t.ly link]* *No action = return to sender* **Why This Lure Works So Well Right Now** 1. Extremely high open rate Almost everyone who shops online has a visceral reaction to “package delayed” + order number. The possibility of either losing your delivery or the money you've already spent on it rather than you clicking an ad = instant click. 2. When a link is shortened (such as links from bit.ly, t.ly, tinyurls, goo.gl) the victim cannot see where the link leads until he/she clicks on the link. 3. A fake page that uses the brand of the carrier or retail company (DHL, Aramex, FedEx, USPS or similar/retailers) for its landing page will also help trick users into believing they are at the legitimate company site. It will likely have each of these elements: a) Branding for DHL, Aramex, FedEx, USPS or a local courier b) An order summary that matches your order number c) A small "customs fee" (usually between $2 and $9.99) that will appear on your account d) Multiple ways of paying (credit card, PayPal, Apple Pay, Google Pay) when you enter your credit card info; the card will be stolen immediately! 4. Low suspicion timing Messages arrive during normal delivery hours or right after a real order → victim thinks “oh yeah, I did order something last week.” 5. Follow-up pressure If victim hesitates, second SMS arrives 30–60 min later: “Final notice: fee not paid → package returned to sender tomorrow.” **Common Landing Page Red Flags (Check These Before Entering Anything)** 1. URL is not the real carrier domain (Real examples: dhl.com, aramex.com, fedex.com, noon.com, amazon.com) Fake examples: dhl-delivery[.]support, aramex-track[.]online, amazon-order-verify[.]pages.dev 2. CVV and complete card information are requested from users through a payment page without utilizing 3-D Secure redirect 3. No HTTPS padlock or invalid certificate (Clicking on the HTTPS padlock displays the domain name of the certificate as a mismatch from this site.) 4. Countdown timer (must pay within 30 minutes or your package will be sent back) 5. Grammar / spacing issues (real companies rarely have typos in payment flows) 6. Form asks for more than needed (full name + address + phone again) **What Happens After You Pay** 1. Card cloned immediately (carding shops buy the details within minutes) 2. Making small test transactions to verify whether or not a debit/credit card has been activated. ($1-$5). 3. Larger purchases of electronics/phone top-ups/cryptocurrencies are typically charged to the card after the card has been confirmed as activated. 4. Should 3D Secure be activated, then OTPs may be misused through phishing at the time of the transaction. **Quick Protection Steps Right Now** 1. Never pay customs/delivery fees via unsolicited SMS link Real carriers never ask for payment this way, they send official invoices via email or app. 2. Type the official tracking URL yourself Go directly to dhl.com, aramex.com, fedex.com, etc. → Hand enter the order right into the system. 3. Verify the status of the purchase via the official app/account if you do not appear to have received a notification within the app - it is more likely to be fake. 4. By hovering/long-pressing over a link (just before you click it), you can usually see what the real domain will be. 5. If you already clicked / entered details a. Contact your bank immediately → block card, dispute charges b. Change passwords on any account that used the same card c. Monitor statements for 30–60 days This lure succeeds because it combines urgency, realism, and fear of loss. One wrong tap + one entered card = thousands in fraudulent charges within hours. If you get one of these messages today → delete it and track the order the safe way.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067