Fake Delivery and Customs Texts: Decoding How the Parcel Scam Works

Confidentialité

Back to the blog
L'équipe Envoyer SMS Gratuit22 August 202610 min read
Filed underConfidentialité

Some scams vanish after six months. The parcel scam has been going strong since 2020 and shows no sign of running out of steam. Every year, Cybermalveillance.gouv.fr ranks it among the most frequent reasons the general public gets in touch, and the 33700 platform continues to receive tens of thousands of reports a month on this theme alone.

Its longevity is no accident. It rests on an almost perfect combination: a believable context (we all receive parcels), a trifling sum (under three euros, so hardly suspicious), artificial urgency ("within 48 hours") and a stolen trusted brand. Understanding how it works internally, step by step, remains the best vaccine.

Man sitting on a sofa reading a message on his mobile phone screen, seen from behind

Why parcels rather than anything else

Fraudsters work on conversion rates. A scenario only interests them if it speaks to a large share of the population at the precise moment the message lands.

Parcels tick every box:

  • Frequency. According to Fevad (the French federation of e-commerce and distance selling), consumers in France have ordered several billion parcels in recent years. At any given moment, a considerable proportion of the population is genuinely waiting for a delivery. So the message lands "just right" without the scammer knowing a single thing about you.
  • The ordinariness of the sender. Chronopost, Colissimo, DHL, UPS, Mondial Relay, Vinted: names we see go by without a second thought. The brand triggers no alarm.
  • The small amount. Asking for €1.99 or €2.99 disarms suspicion. Nobody thinks "someone is trying to rob me." They think "more fees, how annoying."
  • Seasonality. Volumes explode during the sales, Black Friday, the end-of-year holidays and — a period often overlooked — the back-to-school season, when school and computer purchases pick up again.

Add end-of-day fatigue and a smartphone screen glanced at one-handed on the metro, and the margin for error becomes enormous.

Anatomy of a booby-trapped message

Take a typical example, reconstructed from public reports:

Colissimo: your parcel could not be delivered, incomplete address. Please pay the reshipping fee (€1.95) before 24/08: colissimo-suivi-fr[.]net/xk9

Four ingredients are stacked in there.

1. A credible sender. It sometimes appears as an alphanumeric name ("COLISSIMO"), sometimes as a ten-digit mobile number. The first case is often sender spoofing; the second, a disposable prepaid SIM card. In both cases, what appears on your screen is never proof of identity.

2. A problem that puts you at fault. "Incomplete address," "parcel on hold," "payment declined." The wording subtly assigns you responsibility: you're the one who has to fix it, so you're the one who has to act.

3. A short deadline. Two to four days. Long enough to seem reasonable, too short to let you calmly check the next day.

4. A disguised link. The domain name resembles the carrier's but always deviates from it: an added hyphen, an exotic extension (.net, .top, .icu, .cc), a misleading subdomain such as laposte.suivi-colis.xyz. A useful reminder: in a web address, what matters is what comes immediately before the first /, read from right to left.

What happens after the click

The landing page is usually a very polished copy of the carrier's site. The form asks for your name, address and phone number, then the bank card to "pay" those famous two euros.

The two euros aren't the loot. They serve as a test: the transaction confirms that the card is active and that you're willing to go through with it. The real objective is twofold.

  • Assembling a sellable data set: name, postal address, mobile number, card number, expiry date, security code. That block is resold as is.
  • Triggering a second wave. A few days later, an "anti-fraud adviser from your bank" calls you, cites your name, your bank and your latest transaction — the €1.95 one — to get you to approve payments or "move your funds to safety." This is the stage where losses run into the thousands of euros. The Banque de France and the DGCCRF regularly warn about this sequence, sometimes called the fake bank adviser scam.

In other words: the parcel text isn't the scam. It's the way in.

The variants circulating in 2026

The basic scenario has diversified. The main versions observed:

VariantPretextWarning sign
Customs feesNon-EU parcel held at customsCustoms never demand payment by text with a link
ReshippingIncomplete or missing addressA carrier leaves a delivery notice, not a payment link
Pickup locker"Pickup code expired, regenerate it"No code is ever regenerated in exchange for payment
App to install"Track your parcel in our app" via a file outside the official storeInstalling outside the App Store / Google Play = danger
Refund"Your parcel is lost, claim your refund"A refund never requires the security code

The "app" variant is the most dangerous on Android: the file offered installs malware capable of reading your incoming texts, and therefore of intercepting banking verification codes. On iPhone, the attack tends to go through a web page imitating the sign-in screen.

A detail many people are unaware of: genuine customs fees are owed to the carrier at the moment the parcel is handed over, or paid via the carrier's official customer account — never through a link received by message. The applicable rules are published by the Direction générale des douanes et droits indirects, which states on its website that it never requests payment by text message.

Seven checks that take thirty seconds

Faced with a message of this kind, the idea isn't to become a cybersecurity expert, but to install a few automatic reflexes.

  1. Are you actually expecting a parcel? If not, the matter is settled. And if you are, remember: a legitimate carrier knows your address, because the seller passed it on.
  2. Don't click. Type it out. Open the carrier's website yourself, or the official app, and paste in your tracking number. Genuine tracking is always accessible without a link.
  3. Read the domain name under your breath. chronopost.fr, yes. chronopost-livraison-fr.top, no.
  4. Check the tracking number. A genuine Colissimo number follows a precise format (two letters, nine digits, two letters for international shipments, for instance). Fake messages often leave one out, or give an inconsistent one.
  5. Be wary of the ridiculous amount. The smaller the sum, the more you should wonder why it's being demanded by message rather than on the website.
  6. Look at the language. Missing accents, absent spaces before punctuation, capital letters in the middle of a sentence, translated-sounding phrasing: these clues are becoming rarer with automated writing tools, but they persist.
  7. Ask a search engine. Copying a sentence from the message in quotation marks is often enough to surface dozens of identical accounts.

Smartphone lying on a wooden table displaying a fraudulent bank alert text notification on its lock screen

Reducing your exposure upstream

You can't stop the messages from arriving, but you can limit the damage and the number of attempts.

Compartmentalise your online purchases. A single-use virtual bank card, offered by most French banks, makes a leaked number harmless. Some prefer a rechargeable prepaid card dedicated to purchases on lesser-known sites: the ceiling mechanically limits the loss.

Use a secondary email address for orders. It will absorb customer database leaks, which are common among small online retailers.

Protect the device itself. A smartphone with a cracked screen is hard to read, and a hard-to-read screen encourages misreading a web address. A simple tempered glass screen protector and a shockproof case extend the device's life and, indirectly, the quality of your vigilance. In the same spirit, a phone whose battery lasts the day spares you rushed checks in power-saving mode; a compact power bank has more protective effects than you might imagine, if only by giving you time to call your bank.

Turn on the built-in filters. Android and iOS both offer sorting of messages from unknown senders and one-tap reporting. On iPhone: Settings → Messages → Filter Unknown Senders. On Android, Google's Messages app includes spam detection that can be enabled in the protection settings.

Educate those around you. People least comfortable with technology are over-represented among victims. A big-button phone for seniors, with a stripped-down interface, reduces the risk of accidentally tapping a link. And for those who want to dig deeper, a practical cybersecurity guide for beginners often has more impact than an explanation repeated out loud ten times.

You clicked and paid: what to do

Time matters more than embarrassment. Here's the order of operations.

Within the hour

  • Contact your bank (the card-blocking number on the back of your card, or the interbank emergency service on 0 892 705 705) and block the card.
  • Change the password of the linked email account, then that of your online banking, from another device if possible.
  • If you installed an app from outside the official store, turn off mobile data and uninstall it; if in doubt, a factory reset remains the only guarantee.

Within 48 hours

  • Report the message by forwarding it to 33700, a free service run by French mobile operators, or via the dedicated app. Then report the web address on the Phishing Initiative platform.
  • File a complaint, online via the pre-complaint service or at a police station. Your bank will require the receipt.
  • Report the incident on Cybermalveillance.gouv.fr, which will point you to the appropriate steps.

In the following days

  • Monitor your statements daily for a month.
  • Remember article L133-18 of the French Monetary and Financial Code: for an unauthorised transaction reported without delay, the bank must refund immediately, unless it can demonstrate gross negligence on your part. A payment obtained by deception is not, in itself, gross negligence — several Cour de cassation rulings have reaffirmed this in recent years, notably in fake bank adviser cases.
  • Never engage again with an "anti-fraud department" that calls you out of the blue. Hang up and dial the number on your contract yourself.

What a genuine carrier never does

To finish, a short list worth keeping in mind. A legitimate carrier:

  • never asks for your bank card number by text;
  • never asks for the three-digit security code, whatever the situation;
  • never has you install an app from a link received by message;
  • never threatens to destroy or return the parcel within 24 hours;
  • doesn't then call you to "secure" your bank account.

Text messaging remains a wonderfully practical tool: direct, universal, readable on any device. That is precisely why fraudsters covet it. Sending a short message to a loved one, warning of a delay, passing on a code: these legitimate uses have no reason to disappear. You just need to keep one rule in mind, valid for all mobile messaging — a message containing both a link and a sense of urgency deserves to be treated as fake until proven otherwise.

Official resources

  • Cybermalveillance.gouv.fr — reflex fact sheets and online diagnosis
  • 33700 — free reporting platform for fraudulent texts and calls
  • Phishing Initiative — reporting of malicious web addresses
  • DGCCRF — consumer alerts and complaint procedure
  • Direction générale des douanes et droits indirects — the real rules on parcel customs clearance
Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit