Package / delivery scams are fraudulent messages that impersonate a carrier or retailer and claim your parcel is delayed, held, or undeliverable — then steer you toward a link, a small “redelivery” or “customs” fee, or a form that captures your card and personal data. They work on a simple statistical bet: at any moment a large share of people genuinely is expecting a delivery, so an unexpected “problem with your parcel” note lands inside a plausible, expected class of notification.
The lure usually arrives by text or email carrying real-looking carrier branding, and points to a look-alike tracking or payment page. The requested amount is deliberately trivial — often a currency unit or two — because the money is rarely the point: the payoff is the card number, billing address, and sometimes ID data you enter to “release” the package, which is then monetized or resold.
Variants escalate the payload. Some pages prompt you to “install the carrier app” (sideloading malware); some route to a live “customer service” number that pivots to a phone con; some are pure data harvesting with no fee at all. The recognition constant holds across every version: an unsolicited delivery message about a shipment you cannot independently confirm, creating mild urgency and pointing to a link, fee, or number you did not initiate.