"Hello, delivery service: your parcel 7G42B is waiting at the collection point. To confirm your identity, please reply to this text message with the 6-digit pickup code received on this number."
This one doesn't ask for your bank card. It doesn't send you to a fake banking page, doesn't demand £1.99 in customs fees, doesn't threaten to return the parcel to the sender. It asks for one tiny, almost administrative thing: six digits. Six digits you have in fact just received, that don't look like a password, and whose purpose you're not entirely sure about.
That's exactly why it works. The pickup code at a collection point is one of the few everyday secrets that nobody treats as a secret. You show it on screen to the shopkeeper, you read it out loud in a crowded shop, you forward it to your partner so they can grab the package on the way home. Scammers have simply understood that this scrap of a code is worth, in practice, the price of the parcel.

What the pickup code really protects
Ever since collection point networks exploded — corner shops, automated lockers, pickup boxes in stations and shopping centres — carriers have had to solve a simple problem: how do you make sure the right person collects the right package, without demanding ID every single time?
The answer was the one-time code, sent by text message or email to the recipient. In many networks, this code replaces the identity check: presenting it is enough for the parcel to be handed over. Some chains also ask for ID, but the practice varies enormously from one shopkeeper to the next, and it is precisely this variability that opens the breach.
In other words, the pickup code is not a logistical detail. It's a key. Whoever has it can, in many cases, walk off with a package that isn't theirs — without violence, without breaking in, without even having to spin a long lie to the shopkeeper.
A pickup code behaves like a bank card PIN: it only has value as long as you're the only one who knows it.
The four scenarios that come up most often
1. The fake carrier customer service
This is the most direct version. You're expecting a parcel, you receive a text message presenting itself as the carrier and invoking some verification pretext: "incomplete address", "parcel held", "duplicate registration", "anti-fraud check". You're asked to send back the code to "unlock" the pickup.
In more elaborate variants, a phone call follows the text. A calm voice, professional jargon ("round", "hub", "approved delivery point"), a first name, a case number. None of that costs anything to manufacture.
2. The impatient buyer on a classified ads platform
You're selling an item. The buyer says they've paid, asks you to send the parcel — then, once the shipping label is dropped off, demands "the tracking number and the pickup code so my cousin can collect the package on my behalf". The payment, meanwhile, was never actually validated, or will be disputed afterwards. You lose both the item and the money.
The reverse variant exists too: you're the buyer, and the "seller" asks you for the code you received in order to "prove the delivery took place" and release their payment. Once the code is handed over, the parcel is collected by a third party, and the seller swears they sent everything.
3. The parcel you never ordered
This one is trickier. A text message announces a parcel waiting for you, with a code. You don't remember a thing, but curiosity does the rest. In reality, a scammer has used your number as the contact number for a fraudulent order paid for with stolen data. They need your code to collect the goods without linking the pickup to their own identity. By passing it on, you become the visible link in a fraud that isn't yours.
4. The code that isn't a pickup code at all
Finally, there's a confusion that scammers carefully cultivate. Text messages containing a 6-digit code have become so commonplace — logging into an account, validating a payment, two-factor authentication — that many people no longer read the sender or the wording. A scammer trying to log into your account on a delivery, messaging or payment platform will call you posing as "the delivery service" and ask you for "the code you've just received". That isn't a pickup code: it's the key to your account.
Why this scam flies under the radar
Classic smishing campaigns have one weak point: they contain a link. A link can be examined, analysed, and eventually reported and blocked. Browsers display warnings, operators filter, malicious domain databases get updated.
Here, there's often no link at all. Just a request phrased in plain language. No technical filter can decide that a text message asking for "the 6-digit code" is fraudulent, since dozens of legitimate services send exactly that kind of message. The only defence is human.
Add to that three factors working against us:
- The loss looks small. A £60 parcel isn't an emptied bank account. Many victims never file a complaint, which makes the phenomenon statistically invisible.
- Responsibility is blurry. The carrier considers it delivered against presentation of a valid code. The platform points to the seller. The seller did ship the item. Nobody feels accountable for the hole.
- We're often on the move. These messages arrive while we're walking, driving, at work. We reply fast, badly, without rereading. Keeping your phone accessible and charged at such moments is a matter of convenience, but a compact power bank also has this perverse effect: you're permanently reachable, and therefore always in a position to answer in a hurry. Availability is not vigilance.

The signals that should stop your thumb
A text message of this kind almost always contains at least one of these clues:
| Signal | What's really going on |
|---|---|
| You're asked to send back a code | No carrier needs a code it generated itself |
| The message comes from a mobile number (06/07) | Carriers use short codes or alphanumeric sender IDs |
| A third party is to collect the parcel for you | Pickup authorisation, where it exists, goes through your customer account, not by text |
| The parcel is unknown to you | Your number may have been used as a front for a fraudulent order |
| An identity check by text message is invoked | Identity is verified in store, with ID, not by replying to a message |
| There's a short deadline (24 h, 2 h, "before closing") | Urgency is the scammer's only real tool |
The underlying reflex is always the same, and it fits in one sentence: a code you receive is never passed on, to anyone, whatever the pretext. Not to the carrier, not to the buyer, not to the shopkeeper calling you, not to a "technician". The code is shown at the counter, at the moment of pickup, and that's it.
What to do when the text message arrives
- Don't reply. Not "no", not "stop", not an insult. Any reply confirms that the number is active and belongs to a responsive person.
- Check through a channel you chose yourself. Open the carrier's app or type its website address yourself, and check the tracking with the number shown in your order confirmation email. Never via a link you received.
- For a private sale, stay inside the platform. Internal messaging keeps a record. A buyer who wants to leave the platform to continue by text or on a messaging app is very often showing their hand.
- Report the message. The 33700 service, set up by French operators, lets you forward a fraudulent text message free of charge: you send the message to 33700, then the sender's number in a second text. The Cybermalveillance.gouv.fr portal and the PHAROS platform (internet-signalement.gouv.fr) also collect these reports.
- If you've already given out the code, contact the carrier immediately to try to block the pickup, and the retailer or platform to open a dispute. File a complaint: even for a modest amount, that's what allows investigators to connect scattered cases. Arcep regularly points out that grouped reports are what triggers the blocking of numbers used on a mass scale.
Reducing the attack surface, before the first text message
This scam rests on one very simple piece of data: your mobile number, linked to a delivery in progress. The less that link circulates, the less exposed you are.
- Limit how widely your main number is shared. For one-off purchases and private sales, a dedicated second line is an underrated option: a pay-as-you-go SIM card with no contract slipped into an old handset, or into the second slot of a dual-SIM phone, keeps your commercial exchanges separate. If that number starts receiving a barrage of smishing, you know where the leak came from — and you can replace it without having to notify your entire family.
- Don't leave your codes sitting on screen. Preview notifications display codes on the lock screen, visible to anyone on public transport. Turning off text message content previews takes thirty seconds in the settings, and a smartphone privacy screen filter prevents side-angle reading for those who use their phone a lot in public.
- Don't store your paperwork just anywhere. Confirmation emails, shipping labels and order references are what will let you prove your good faith in the event of a dispute. A local backup on an encrypted USB drive or in a dedicated folder, kept away from an email account that could itself be compromised, saves you from losing all your evidence at once.
- Share the right reflexes around you. The people least comfortable with screens are the most exposed, because they see the code as a formality. A small practical cybersecurity guide for seniors left near the landline, or simply a sentence stuck on the fridge — "never dictate a code received by text message" — often does more than any technical filter.
What this scam says about the system
Pickup code hijacking isn't a computer vulnerability. It's the result of a commercial trade-off: to smooth out millions of pickups a day, delivery networks replaced a heavy check — ID — with a light, transferable one. The gain in convenience is real. The cost, meanwhile, has been shifted to the recipient, who has become the keeper of a secret whose value was never explained to them.
It's the same mechanism as with one-time banking codes, two-factor authentication codes or login confirmations. Everywhere, security now rests on a single rule that scammers only have to make you forget for the length of a message: what arrives on your phone stays on your phone.
A carrier that needs to verify your identity will do so at the counter. A platform that needs to confirm a delivery will do so in your customer account. A legitimate buyer never needs your six digits. The moment someone asks you for them, they're not trying to help you: they're trying to take your place.



