The Delivery Text Is Not From the Delivery Company
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
A parcel could not be delivered. A small customs fee is outstanding. Your account has been suspended. There is a link.
Text-message phishing — smishing — has become one of the most productive scams running, and not because the messages are clever. They work on timing and volume. Send enough delivery notifications and a large share will land on someone who genuinely is waiting for a parcel.
Why texts work better than emails
Email clients have spent two decades building spam filtering, sender authentication and warning banners. Text messages have almost none of that.
A text arrives in the same thread-based interface as messages from real people, stripped of formatting cues. There is no sender address to inspect, no hover-to-preview on the link, and the link itself is usually shortened, so it reveals nothing. On a small screen, a convincing fake login page is much harder to distinguish from the real one.
Sender IDs can also be spoofed, which produces the most damaging version: a fraudulent message appearing inside the same conversation thread as genuine messages from your bank, because the phone groups them by the displayed name.
The recurring patterns
Almost all of these fall into a handful of shapes:
- The undeliverable parcel with a small fee to release it. The amount is deliberately trivial — small enough not to warrant a second thought, and the real goal is your card details.
- The bank security alert asking you to confirm a transaction you do not recognise, which conveniently requires logging in.
- The tax refund or fine. Refunds exploit greed, fines exploit fear, and fear converts better.
- The wrong number that becomes a conversation. A friendly opener with no link at all, which over days or weeks turns into an investment opportunity. Patient and lucrative.
- The family member with a new number who urgently needs money. Emotional pressure plus urgency plus a plausible story.
The habit that defeats nearly all of it
Never act inside the message.
If a text says there is a problem with your bank account, do not tap the link — open your banking app or type the address yourself. If a parcel is held, go to the courier's own site and enter the tracking number. If a relative texts from a new number asking for money, call the number you already have for them.
This single rule works because it does not depend on you spotting a fake. It removes the link from the equation entirely. You never have to correctly judge whether a message is genuine, which is exactly the judgement these scams are designed to defeat.
Practical extras
- Never enter a card number reached from a text. No legitimate delivery fee needs to be paid that way.
- Report the message. Many countries have a spam-forwarding number; in the UK and several others, forwarding to 7726 (which spells SPAM) is free and feeds carrier-level blocking.
- Delete and block. Do not reply, not even "STOP" — a reply to a scam confirms the number is live and reaches a real person.
- Be sceptical of urgency. Every one of these messages needs you to act now. Genuine organisations are comfortable with you calling back.
A worked example of why the parcel text works
Picture the message arriving at half past four on a Thursday. You ordered something on Monday. You are half-watching for it.
The text says the courier attempted delivery, a small charge is outstanding to cover a redelivery, and there is a link. The amount named is trivial — the sort of sum you would not query on a receipt.
Every element of that is engineered. The timing is not targeted at you; the sender simply blasts millions of these, and a predictable share land on someone genuinely expecting a parcel. The small amount is chosen precisely because it is below the threshold at which people think carefully. And the request is plausible, because customs charges and redelivery fees are real things that really happen.
Tap through and you reach a page that looks like the courier's. It asks for the fee, so it asks for a card number, expiry, security code, name and billing address. You have now handed over everything needed to make purchases, and often enough to pass a telephone identity check with your bank later.
Here is the part that catches careful people: the sum you agreed to is not the point and never was. Some of these operations do not even take the small charge. They take the card details, and in the more sophisticated versions they call you shortly afterwards, claiming to be your bank's fraud team, already knowing your name, address and the last digits of your card — because you gave them those minutes ago. That second call is what converts a card fraud into a drained account.
The ten-second decision procedure
You do not need to judge whether a message is genuine. You need a rule that works without judgement.
- Does the message want me to act? Tap, pay, log in, reply, call a number. If not, it is harmless.
- Could this be true? Sometimes obviously not — a bank you have no account with, a parcel you never ordered. Delete and move on.
- If it could be true, go to the organisation myself. Their app, their website typed by hand, or the number printed on your card or a statement. Never the link, never the number in the message.
- Then check whether the thing the message described is actually there. A real delivery problem appears in the courier's own tracking. A real bank alert appears in the banking app.
That last step is the one people skip, and it is the whole procedure. If the message was genuine, the issue exists in the official channel too, so you lose nothing by going there. If it was not, you have just stepped around the entire attack without ever having to spot anything.
Why "look for the bad spelling" no longer works
Older advice leans on tells: clumsy grammar, odd phrasing, an obviously wrong web address.
Those tells were never reliable and they are worse now. Convincing text is cheap to produce, page layouts are copied directly from the originals, and web addresses can be built to read plausibly at a glance on a phone screen where most of the address is hidden anyway. Shortened links reveal nothing at all before you tap.
There is a subtler problem with tell-based advice: it trains you to approve messages that pass the checks. Someone who has learned to look for spelling mistakes and finds none feels reassured, which is the opposite of the intended effect. A rule that never requires you to authenticate the message does not have that failure mode.
The fair objection
Plenty of legitimate organisations do send texts containing links. Delivery firms, banks, doctors' surgeries and airlines all do it, which makes blanket advice to never tap a link sound unrealistic and slightly preachy.
It is unrealistic if you treat it as a rule about links. It is entirely realistic as a rule about what you do next. Tapping a link and reading a page costs you nothing. The damage only ever occurs at the point where you type something in or install something.
So the workable version is narrower than "never tap": never enter credentials, card details or personal information on a page you arrived at from a message, and never install anything a message suggested. That leaves the convenience of legitimate messages intact while removing the entire value of the fraudulent ones. It is also easier to remember, because it has one condition rather than a checklist.
If you already tapped
Do not panic, but move quickly.
If you entered card details, call your bank using the number on your card and cancel it. Say specifically that the details were entered on a fraudulent page, so that they watch for the follow-up call described above — and treat any incoming call claiming to be the bank as suspect for the next few days, however much it knows about you.
If you entered a password, change it everywhere you used it, starting with email, and revoke active sessions where the service allows it. A password manager makes that a short job instead of an afternoon.
If you installed anything, treat the device as compromised: remove the app, run a scan with reputable security software, and change passwords from a different device rather than the one in question.
Tapping a link and entering nothing is usually not a disaster. The information you typed is what matters. And if any of this has already happened to you, what to do after a data breach covers the wider cleanup. And for the tools that reduce how much of this reaches you at all, see our shortlist of security tools.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
Factory Reset Is Not Enough (But It Nearly Is)
What actually happens to your data when you reset a phone, why modern encryption makes it safe, and the two steps people skip that genuinely cause problems.
privacy
It Sounded Exactly Like Your Daughter
Voice cloning needs seconds of audio and the result is convincing enough to fool parents. Why the technology broke a lifelong instinct, and the family safeword that fixes it.
guides
Best Identity Theft Protection 2026: Real Defence
The best identity theft protection in 2026 is a layered strategy, not one product. The layers that matter and the tools we recommend.
