The Fake Delivery Notice Smishing Scam: How a Simple Text Can Drain Your Bank Account
Smishing is short for “SMS phishing.” It works exactly like the email phishing scams you’ve heard about, but it comes through text messages. And it is exploding right now because people trust text messages more than they trust email. Older Americans, especially those aged 45 to 64, are prime targets. You’re busy, you order things online, you expect packages. The scammers know that. They also know that you’re less likely to scrutinize a text on your phone than an email on your laptop. The fake delivery notice is the most common smishing variant, and it works because it plays on a simple human instinct: you want your stuff.
How do these criminals get your phone number? They buy it from data brokers. They scrape it from social media, fake surveys, or even from hacked accounts on shopping websites. The text itself is designed to create urgency. “We attempted delivery at 2:15 PM, but you were unavailable. Click here to reschedule within 24 hours or your package will be returned.” That time pressure makes you act without thinking. You’re worried about missing a birthday gift or an important work delivery. You click.
The link generally leads to a webpage that looks almost identical to the real carrier’s site. The logo is right. The font is the same. The URL might be close but not exact – like “usps-delivery.com” instead of “usps.com.” That page asks for your name, address, phone number, and then a credit card number to pay a fee, usually between one and three dollars. That fee is the hook. It is small enough that you don’t think twice, but it gives the scammer your full payment details. Some go further and ask for your Social Security number and date of birth, supposedly for “age verification on the package.” If you give that, they now have everything they need for identity theft: open credit cards in your name, take out loans, even file a fraudulent tax return.
But the real danger doesn’t stop with the initial theft. Even if you don’t enter your SSN, the moment you enter your credit card number, the scammer can drain it. Many times they don’t bother with a small test charge. They go straight for large purchases or cash advances. And because you gave them your phone number and address, they may sell that information to other scammers. You might start receiving more smishing texts, or worse, phone calls from people pretending to be bank fraud investigators who already know your card number. That is a second-stage scam called “phishing call” or “vishing.” They’ll say your card was used fraudulently, and they need you to “verify” by providing the one-time code sent to your phone. If you do, they use that code to change your online banking password and empty your accounts.
You can spot a fake delivery text if you take three seconds to think. First, legitimate delivery companies never ask you to click a link to reschedule delivery unless you specifically requested a change through their official app or website. If you didn’t initiate contact, that text is fake. Second, the URL in the message will look odd. Do not tap it. Instead, look at the sender number: real carriers use short codes like 28777 for UPS or 26662 for USPS, but scammers spoof those too. Better to ignore the text entirely and go directly to the carrier’s official website or app to check your tracking status. Third, no legitimate company demands payment for a redelivery unless you already chose a premium service. The standard “sorry we missed you” note left on your door includes a phone number to call, not a link to pay.
What do you do if you already fell for one? Act immediately. Contact your bank or credit card company and freeze the card. Report the fraud. Change any passwords you use on that device. Place a fraud alert on your credit file with all three major bureaus: Equifax, Experian, and TransUnion. If you entered your Social Security number, freeze your credit entirely. File a complaint with the Federal Trade Commission at reportfraud.ftc.gov. And do not feel embarrassed. The scammers are professional criminals who spend thousands of hours perfecting these messages. The average person stands no chance in the split second they grab for a phone. The only defense is a habit: never click a link in an unsolicited text. Ever.
Smishing attacks are not going away. They adapt. Lately, scammers have started using text threads that look like they are replies to a conversation you never had, or texts that claim you have a voicemail from someone you know. The same rule applies: if you did not expect a link, do not tap it. Delete the message and block the number. Your discipline is the only firewall that matters.


