Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
Global Fake Parcel Delivery Phishing/Smishing Campaign (TL-2026-2562), also tracked as Fake Parcel Delivery Scam, is a medium-severity phishing campaign, first published 2026-09-18. It has no confirmed attribution, affects bpost bpost brand / customer delivery-notification identity, maps to 10 MITRE ATT&CK techniques (T1056.003, T1204.001, T1566.002), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2562
- Threat ID
- TL-2026-2562
- Also known as
- Fake Parcel Delivery Scam, Customs Fee Package Smishing, bpost Customs Fee Phishing
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-18
- Last reviewed
- 2026-09-18
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, financial-services, ecommerce, logistics-postal
- Target regions
- belgium, united states of america, france, spain, italy, netherlands, Europe, North America
- Detection rules
- 9
- Indicators of compromise
- 12
An active, multi-country phishing and smishing campaign impersonates major postal/courier brands (bpost, USPS, Colissimo, Chronopost, Correos, Poste Italiane, PostNL) with fake undelivered-package and customs-fee notices, driving victims through a URL-shortener redirect to lookalike sites that progressively harvest names, phone numbers, email addresses, and full card/IBAN banking details.
How Global Fake Parcel Delivery Phishing/Smishing Campaign works
Malwarebytes Labs documented an active phishing and smishing campaign in which criminals send fake 'failed delivery' notices (email and SMS) impersonating bpost, USPS, Colissimo, Chronopost, Correos, Poste Italiane, and PostNL, claiming a package is held pending a small unpaid customs/redelivery fee (observed lure: a Dutch-language email claiming a package could not be delivered on September 9, 2026, over an unpaid EUR 4.95 customs duty). Victims who click the embedded link are routed through the third-party QR-code/URL-shortening service qr.paps.jp (specifically hxxps://qr[.]paps[.]jp/1GWsa), which redirects to lookalike domains impersonating bpost's official portal: hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/ and bpost[.]center. The fraudulent site closely mimics bpost's branding and walks the victim through sequential data-collection pages: first name, phone number, email address and age; then IBAN and card number/expiry; and finally full banking and payment-card details under the pretext of paying the outstanding fee. Malwarebytes noted a tell-tale quality flaw in the kit -- one payment button was mistranslated as 'Indian search' instead of the correct Dutch 'Betaal' (Pay), consistent with a templated, non-native-language phishing kit reused across multiple brand skins.
No CVE or software vulnerability underlies this threat; it is a social-engineering, credential/financial-data-theft campaign, not an exploit against a technical control. Belgium's national cybersecurity awareness service (Safeonweb, run by the Centre for Cybersecurity Belgium) and bpost itself separately warn that bpost-themed phishing/smishing is a recurring, ongoing problem, directing recipients to verify deliveries only via the official My bpost app and to report suspicious messages to abuse@bpost.be. The same 'failed delivery + small outstanding fee' template recurs across the wider postal/courier ecosystem: the U.S. Postal Inspection Service documents an equivalent USPS 'customs fee' smishing pattern (reporting channel spam@uspis.gov / SMS shortcode 7726), and Italy's national CERT (CERT-AGID) documented an near-identical fake-delivery smishing wave impersonating Poste Italiane as far back as December 2024, showing this lure template has been reused against these same courier brands for at least two years.
This specific campaign was not attributed by Malwarebytes to a named threat actor or phishing kit. For broader context only (not a confirmed link to this incident), independent researchers have separately reported a large, unrelated-but-similar wave of courier-brand-impersonation smishing across Europe in 2026: Whalebone reported over 1,000 newly registered European courier-impersonation phishing domains intercepted in the first half of April 2026 alone (using low-trust TLDs and domains resembling delivery-service names), and security researchers/Google have separately publicized the China-linked 'Smishing Triad' actor and its 'Lighthouse' phishing-as-a-service platform, which licenses templated courier- and toll-brand-impersonation smishing kits at scale. No source ties the specific bpost/USPS/Colissimo/Chronopost/Correos/Poste Italiane/PostNL campaign analyzed here to Lighthouse, Smishing Triad, or any other named kit or actor; these are cited solely as documented landscape precedent for the same tactic (mass templated courier-impersonation smishing harvesting payment data). A BeaconBeagle infrastructure check against both fake bpost domains returned no C2/infrastructure correlation matches, consistent with this being a standalone credential/payment-harvesting phishing kit rather than malware-backed C2 infrastructure.
Impact is direct financial and identity theft against consumers: victims who submit data risk unauthorized card charges, account takeover, and IBAN-based fraud (e.g., unauthorized SEPA transfers). Recommended defenses are entirely procedural/awareness-based: never click links in unsolicited delivery notices, verify only through official courier apps/sites, treat any request combining IBAN and card details as fraudulent, and report/forward suspicious messages to the relevant courier abuse address, national CERT, or telecom SPAM shortcode (7726).
MITRE ATT&CK techniques used in TL-2026-2562
Collection
Execution
Initial Access
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1608.005 Link Target
Reconnaissance
Impact
Defense Evasion
Affected products and versions in Global Fake Parcel Delivery Phishing/Smishing Campaign
- bpost — bpost brand / customer delivery-notification identity (impersonated)
Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
Fixed in: N/A - USPS — USPS brand / customer delivery-notification identity (impersonated)
Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
Fixed in: N/A - La Poste (Colissimo / Chronopost) — Colissimo and Chronopost brand / delivery-notification identity (impersonated)
Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
Fixed in: N/A - Correos — Correos brand / customer delivery-notification identity (impersonated)
Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
Fixed in: N/A - Poste Italiane — Poste Italiane brand / customer delivery-notification identity (impersonated)
Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
Fixed in: N/A - PostNL — PostNL brand / customer delivery-notification identity (impersonated)
Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
Fixed in: N/A
Remediation for Global Fake Parcel Delivery Phishing/Smishing Campaign
Immediate actions
- Do not click links in unsolicited parcel-delivery SMS or email notices; navigate directly to the courier's official app or website using a known tracking number instead
- Never enter card number, expiry/CVV, or IBAN details on a page reached via a shortened link (e.g. qr.paps.jp) or a lookalike domain such as bpost.center or a *.my.id subdomain impersonating a courier
- If card or IBAN details were already submitted, contact the card issuer/bank immediately to block the card and enable fraud monitoring (e.g. Belgian Card Stop: +32 78 170 170)
- Forward suspicious bpost-themed messages to abuse@bpost.be; forward USPS-themed smishing to spam@uspis.gov, and forward any smishing text to the universal SMS spam shortcode 7726
- Report the phishing domains and shortlink to the relevant national CERT/awareness body (e.g. Belgium's safeonweb.be, Italy's CERT-AGID) and to the abused URL-shortener provider (paps.jp) for takedown
Workarounds
- Independently verify any delivery notice through the courier's official tracking app/site using the tracking number, ignoring the embedded link in the message entirely
- Treat any message requesting both IBAN and card number to release a shipment as fraudulent regardless of how convincing the branding appears
Longer-term hardening
- Deploy brand-abuse/newly-registered-domain monitoring to detect lookalike domains impersonating courier brands (patterns such as bpost, usps, colissimo, chronopost, correos, posteitaliane, postnl combined with 'delivery'/'customs'/'pakje'/'colis' keywords)
- Educate customers and employees that legitimate couriers never request card or IBAN details by SMS or email to release a package for a small customs/redelivery fee
- For enterprise email/web gateways: block or warn on known abused URL-shortener/QR-redirect domains tied to active smishing campaigns
- Consider mobile carrier/SMS-firewall content filtering for known smishing keyword patterns (customs fee, redelivery fee, tracking) associated with reported campaigns
Timeline of Global Fake Parcel Delivery Phishing/Smishing Campaign
- Italy's national CERT (CERT-AGID) documents an earlier, near-identical fake-delivery smishing wave impersonating Poste Italiane, showing this lure template has targeted the same courier brands for at least two years.
- Security researchers and Google publicize the 'Lighthouse' phishing-as-a-service platform operated by the 'Smishing Triad' actor, which licenses templated courier- and toll-brand-impersonation smishing kits at scale; not confirmed as the kit behind this specific bpost campaign.
- Whalebone reports intercepting over 1,000 newly registered European courier-impersonation phishing domains in the first half of April 2026, indicating a broader ongoing wave of similar delivery-brand smishing across the continent.
- The phishing email sample analyzed by Malwarebytes falsely claims a bpost package 'could not be delivered' on this date due to an unpaid EUR 4.95 customs fee, driving the victim to the phishing redirect chain.
- bpost's official phishing-awareness page and Belgium's Safeonweb consumer-alert service remain active and continue to flag bpost-impersonation phishing/smishing as an ongoing, currently active threat to consumers.
- Malwarebytes Labs publishes public analysis of the fake parcel-delivery phishing/smishing campaign impersonating bpost, USPS, Colissimo, Chronopost, Correos, Poste Italiane, and PostNL, confirming active harvesting of PII and card/IBAN data via qr.paps.jp and the lookalike bpost.center / bpost.be-pakje-ontvangen-nl-recevoir-colis-fr.my.id domains.
Sources cited for Global Fake Parcel Delivery Phishing/Smishing Campaign
- Fake parcel delivery messages steal your card and bank details
- Phishing | bpost
- Currently many phishing messages detected that seem to come from bpost
- Smishing: Package Tracking Text Scams
- Bpost - phishing!
- Falso avviso di consegna: una nuova campagna di smishing colpisce gli utenti di Poste Italiane
- The Rise of Fake Shipment Tracking Scams in MEA
- Courier-Themed Phishing Campaign Targeting European Users
- "Lighthouse" Phishing Kit Powers Global Smishing Attacks
More in phishing
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via nxcli.io
Detection coverage for TL-2026-2562
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2562 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2562
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.