Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details

Global Fake Parcel Delivery Phishing/Smishing Campaign (TL-2026-2562), also tracked as Fake Parcel Delivery Scam, is a medium-severity phishing campaign, first published 2026-09-18. It has no confirmed attribution, affects bpost bpost brand / customer delivery-notification identity, maps to 10 MITRE ATT&CK techniques (T1056.003, T1204.001, T1566.002), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2562

Threat ID
TL-2026-2562
Also known as
Fake Parcel Delivery Scam, Customs Fee Package Smishing, bpost Customs Fee Phishing
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-09-18
Last reviewed
2026-09-18
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, financial-services, ecommerce, logistics-postal
Target regions
belgium, united states of america, france, spain, italy, netherlands, Europe, North America
Detection rules
9
Indicators of compromise
12

An active, multi-country phishing and smishing campaign impersonates major postal/courier brands (bpost, USPS, Colissimo, Chronopost, Correos, Poste Italiane, PostNL) with fake undelivered-package and customs-fee notices, driving victims through a URL-shortener redirect to lookalike sites that progressively harvest names, phone numbers, email addresses, and full card/IBAN banking details.

How Global Fake Parcel Delivery Phishing/Smishing Campaign works

Malwarebytes Labs documented an active phishing and smishing campaign in which criminals send fake 'failed delivery' notices (email and SMS) impersonating bpost, USPS, Colissimo, Chronopost, Correos, Poste Italiane, and PostNL, claiming a package is held pending a small unpaid customs/redelivery fee (observed lure: a Dutch-language email claiming a package could not be delivered on September 9, 2026, over an unpaid EUR 4.95 customs duty). Victims who click the embedded link are routed through the third-party QR-code/URL-shortening service qr.paps.jp (specifically hxxps://qr[.]paps[.]jp/1GWsa), which redirects to lookalike domains impersonating bpost's official portal: hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/ and bpost[.]center. The fraudulent site closely mimics bpost's branding and walks the victim through sequential data-collection pages: first name, phone number, email address and age; then IBAN and card number/expiry; and finally full banking and payment-card details under the pretext of paying the outstanding fee. Malwarebytes noted a tell-tale quality flaw in the kit -- one payment button was mistranslated as 'Indian search' instead of the correct Dutch 'Betaal' (Pay), consistent with a templated, non-native-language phishing kit reused across multiple brand skins.

No CVE or software vulnerability underlies this threat; it is a social-engineering, credential/financial-data-theft campaign, not an exploit against a technical control. Belgium's national cybersecurity awareness service (Safeonweb, run by the Centre for Cybersecurity Belgium) and bpost itself separately warn that bpost-themed phishing/smishing is a recurring, ongoing problem, directing recipients to verify deliveries only via the official My bpost app and to report suspicious messages to abuse@bpost.be. The same 'failed delivery + small outstanding fee' template recurs across the wider postal/courier ecosystem: the U.S. Postal Inspection Service documents an equivalent USPS 'customs fee' smishing pattern (reporting channel spam@uspis.gov / SMS shortcode 7726), and Italy's national CERT (CERT-AGID) documented an near-identical fake-delivery smishing wave impersonating Poste Italiane as far back as December 2024, showing this lure template has been reused against these same courier brands for at least two years.

This specific campaign was not attributed by Malwarebytes to a named threat actor or phishing kit. For broader context only (not a confirmed link to this incident), independent researchers have separately reported a large, unrelated-but-similar wave of courier-brand-impersonation smishing across Europe in 2026: Whalebone reported over 1,000 newly registered European courier-impersonation phishing domains intercepted in the first half of April 2026 alone (using low-trust TLDs and domains resembling delivery-service names), and security researchers/Google have separately publicized the China-linked 'Smishing Triad' actor and its 'Lighthouse' phishing-as-a-service platform, which licenses templated courier- and toll-brand-impersonation smishing kits at scale. No source ties the specific bpost/USPS/Colissimo/Chronopost/Correos/Poste Italiane/PostNL campaign analyzed here to Lighthouse, Smishing Triad, or any other named kit or actor; these are cited solely as documented landscape precedent for the same tactic (mass templated courier-impersonation smishing harvesting payment data). A BeaconBeagle infrastructure check against both fake bpost domains returned no C2/infrastructure correlation matches, consistent with this being a standalone credential/payment-harvesting phishing kit rather than malware-backed C2 infrastructure.

Impact is direct financial and identity theft against consumers: victims who submit data risk unauthorized card charges, account takeover, and IBAN-based fraud (e.g., unauthorized SEPA transfers). Recommended defenses are entirely procedural/awareness-based: never click links in unsolicited delivery notices, verify only through official courier apps/sites, treat any request combining IBAN and card details as fraudulent, and report/forward suspicious messages to the relevant courier abuse address, national CERT, or telecom SPAM shortcode (7726).

MITRE ATT&CK techniques used in TL-2026-2562

Collection

T1056.003 Web Portal Capture

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1608.005 Link Target

Reconnaissance

T1598.003 Spearphishing Link

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Global Fake Parcel Delivery Phishing/Smishing Campaign

  • bpost — bpost brand / customer delivery-notification identity (impersonated)
    Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
    Fixed in: N/A
  • USPS — USPS brand / customer delivery-notification identity (impersonated)
    Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
    Fixed in: N/A
  • La Poste (Colissimo / Chronopost) — Colissimo and Chronopost brand / delivery-notification identity (impersonated)
    Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
    Fixed in: N/A
  • Correos — Correos brand / customer delivery-notification identity (impersonated)
    Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
    Fixed in: N/A
  • Poste Italiane — Poste Italiane brand / customer delivery-notification identity (impersonated)
    Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
    Fixed in: N/A
  • PostNL — PostNL brand / customer delivery-notification identity (impersonated)
    Vulnerable versions: N/A - brand-impersonation phishing, not a software vulnerability
    Fixed in: N/A

Remediation for Global Fake Parcel Delivery Phishing/Smishing Campaign

Immediate actions

  • Do not click links in unsolicited parcel-delivery SMS or email notices; navigate directly to the courier's official app or website using a known tracking number instead
  • Never enter card number, expiry/CVV, or IBAN details on a page reached via a shortened link (e.g. qr.paps.jp) or a lookalike domain such as bpost.center or a *.my.id subdomain impersonating a courier
  • If card or IBAN details were already submitted, contact the card issuer/bank immediately to block the card and enable fraud monitoring (e.g. Belgian Card Stop: +32 78 170 170)
  • Forward suspicious bpost-themed messages to abuse@bpost.be; forward USPS-themed smishing to spam@uspis.gov, and forward any smishing text to the universal SMS spam shortcode 7726
  • Report the phishing domains and shortlink to the relevant national CERT/awareness body (e.g. Belgium's safeonweb.be, Italy's CERT-AGID) and to the abused URL-shortener provider (paps.jp) for takedown

Workarounds

  • Independently verify any delivery notice through the courier's official tracking app/site using the tracking number, ignoring the embedded link in the message entirely
  • Treat any message requesting both IBAN and card number to release a shipment as fraudulent regardless of how convincing the branding appears

Longer-term hardening

  • Deploy brand-abuse/newly-registered-domain monitoring to detect lookalike domains impersonating courier brands (patterns such as bpost, usps, colissimo, chronopost, correos, posteitaliane, postnl combined with 'delivery'/'customs'/'pakje'/'colis' keywords)
  • Educate customers and employees that legitimate couriers never request card or IBAN details by SMS or email to release a package for a small customs/redelivery fee
  • For enterprise email/web gateways: block or warn on known abused URL-shortener/QR-redirect domains tied to active smishing campaigns
  • Consider mobile carrier/SMS-firewall content filtering for known smishing keyword patterns (customs fee, redelivery fee, tracking) associated with reported campaigns

Timeline of Global Fake Parcel Delivery Phishing/Smishing Campaign

  • Italy's national CERT (CERT-AGID) documents an earlier, near-identical fake-delivery smishing wave impersonating Poste Italiane, showing this lure template has targeted the same courier brands for at least two years.
  • Security researchers and Google publicize the 'Lighthouse' phishing-as-a-service platform operated by the 'Smishing Triad' actor, which licenses templated courier- and toll-brand-impersonation smishing kits at scale; not confirmed as the kit behind this specific bpost campaign.
  • Whalebone reports intercepting over 1,000 newly registered European courier-impersonation phishing domains in the first half of April 2026, indicating a broader ongoing wave of similar delivery-brand smishing across the continent.
  • The phishing email sample analyzed by Malwarebytes falsely claims a bpost package 'could not be delivered' on this date due to an unpaid EUR 4.95 customs fee, driving the victim to the phishing redirect chain.
  • bpost's official phishing-awareness page and Belgium's Safeonweb consumer-alert service remain active and continue to flag bpost-impersonation phishing/smishing as an ongoing, currently active threat to consumers.
  • Malwarebytes Labs publishes public analysis of the fake parcel-delivery phishing/smishing campaign impersonating bpost, USPS, Colissimo, Chronopost, Correos, Poste Italiane, and PostNL, confirming active harvesting of PII and card/IBAN data via qr.paps.jp and the lookalike bpost.center / bpost.be-pakje-ontvangen-nl-recevoir-colis-fr.my.id domains.

Sources cited for Global Fake Parcel Delivery Phishing/Smishing Campaign

More in phishing

Detection coverage for TL-2026-2562

As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2562 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2562

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats