That package delivery text you didn't ask for? It's probably a scam.
Your phone buzzes: a text says your USPS package could not be delivered and you need to click a link to reschedule. It looks real. It probably isn't — and millions of people get the same message every month.
According to the Federal Trade Commission, Americans lost $470 million to text-message scams in 2024 — nearly $100 million more than the year before, and five times higher than what was reported just four years ago. The single most commonly reported type of text scam? Fake package delivery alerts impersonating USPS, FedEx, UPS, and Amazon.
Security researchers have a name for it: smishing — SMS phishing. It is the most-reported phishing threat hitting American phones right now. If you have received one of these texts, or know someone who has, here is what is actually happening and what to do about it.
What the text says — and what it is really after
These messages almost always follow one of a few familiar scripts:
- "Your package could not be delivered." A link invites you to reschedule, update your address, or pay a small redelivery fee — often $1.99 or $3.50.
- "Your shipment is on hold." A customs issue, address mismatch, or unpaid duty is holding your parcel. Click here to clear it.
- "Action required: your package will be returned." A short deadline — 24 or 48 hours — adds pressure and discourages careful thinking.
The link leads to a website that is a very close copy of the real carrier's site, complete with the official logo, matching colors, and a plausible tracking number. Once there, you are asked to confirm your name, address, and a credit or debit card number for the "small fee." That information goes directly to criminals who will use it for identity theft or sell it to others.
In some versions, there is no fee page at all. Instead, the site silently attempts to install software on your phone, or it asks you to call a phone number where someone posing as a carrier representative then walks you toward sharing your banking details or granting remote access to your device.
Who is behind it — and why there are so many of these texts
Security researchers at Resecurity and Palo Alto Networks Unit 42 have documented a China-linked criminal network known as the "Smishing Triad" that has industrialized these attacks. The group operates more than 194,000 malicious domains. In campaigns documented in 2023 and 2024, more than 28,000 of those domains were built specifically to impersonate USPS. Altogether, the network has been documented reaching more than one million victims across 120 countries.
The Smishing Triad does not just run scams — it sells them. Ready-made kits, complete with lookalike carrier websites, pre-written text scripts, and even customer support, are available to other criminals by monthly subscription, starting around $200. That model is why the volume of fake delivery texts keeps rising: the tools are inexpensive, the setup takes minutes, and the payoff per victim can be significant.
One reason these texts are especially hard to spot: they are often sent through Apple iMessage using compromised accounts, which lets them bypass the filters phone carriers use to block suspicious numbers. A message that arrives inside your normal iMessage thread looks far more trustworthy than a random string of digits in your SMS inbox.
What to do
- Do not tap the link. If you receive an unexpected delivery text, open your browser and navigate directly to usps.com, fedex.com, or ups.com yourself. Enter the tracking number there. If there is a real problem with your package, you will see it — no link from a text required.
- Pay nothing through a text link. Legitimate carriers never collect a redelivery fee by text message. If any fee is requested, treat the message as a scam and delete it.
- If you tapped the link but entered nothing, close the browser, clear your browsing history, and monitor your accounts and phone activity for unusual behavior over the next few weeks.
- If you entered your card number or personal information, contact your bank or card issuer right away to report it and request a new card number. Place a fraud alert on your credit file by calling any one of the three major bureaus — Equifax, Experian, or TransUnion — and they are required to notify the other two.
- Report it. Forward the text to 7726 (SPAM) — a free service that reports it directly to your carrier. If the text impersonated USPS, email a screenshot to spam@uspis.gov. You can also file a report at the FBI's Internet Crime Complaint Center at ic3.gov.
- Talk about it before it happens. These texts reach everyone. The families who catch them are usually the ones who have talked about this ahead of time — a quick conversation today is worth more than any security app.
Related reading
- What to do in the first hour after clicking a suspicious link — a step-by-step guide for when the tap already happened, before the damage spreads.
- How to report a phishing message and preserve the evidence — the same process applies to suspicious texts; what investigators actually need from you.
- Scam Library: package delivery and smishing scams — real examples of what these messages look like and the variations to watch for.
The text is often just the opening move.
A fake delivery text softens you up — then the follow-up arrives in your inbox: a "shipping confirmation" email, a fake bill, a phishing link that looks official. Family Sentinel monitors your family's email for exactly these patterns and sends an alert in minutes, before money or information moves. Read-only by design, with a real Security Architect behind every alert — and every warning carries your family's own verification phrase so a scammer can never fake one.
Start your free month →Want the next threat before it reaches you?
Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.