ZeroHour
Malwarebytes Labspublished ()ingested @malwarebytes
Part of a story covered by 5 sources: “Phishing and smishing waves impersonate T-Mobile Rewards, Revolut, and bpost to harvest credentials, card details, and one-time codes” — merged summary and timeline →

Fake parcel delivery messages steal your card and bank details

lowPhishing & fraud exploited in the wildimportance 38
AI summary · glm-5.3-flash

Phishing emails impersonating bpost claim a €4.95 customs fee to trick Belgian customers into submitting card and bank details on fake courier sites.

A recent campaign targeting customers of the Belgian postal service bpost uses Dutch-language emails claiming a package was undelivered due to unpaid €4.95 customs duties, then directs victims through a URL shortener to fake bpost domains such as bpost.center that harvest personal data, IBAN, and full card details. Similar parcel delivery scams impersonate USPS, Colissimo, Chronopost, Correos, Poste Italiane, and PostNL across multiple countries. Stolen card data may be used for fraudulent purchases or sold to other criminals.

  • Emails claim €4.95 unpaid customs duty to lure victims to fake bpost sites
  • Links route through a URL shortener (qr.paps.jp) to lookalike domains
  • Fake pages collect name, phone, IBAN, and full card details
  • Parallel campaigns impersonate USPS, Colissimo, Chronopost, Correos, Poste Italiane, PostNL
  • Advice: verify deliveries via official apps, freeze exposed cards, contact bank

Indicators of compromiseAll →

TypeIndicatorContext
domainbpost.be-pakje-ontvangen-nl-recevoir-colis-fr.my.idampaign used several fake bpost domains, including: hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/ bpost[.]center , which is the domain shown in the sc
domainbpost.center/bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/ bpost[.]center , which is the domain shown in the screenshots below. The
domainqr.paps.jpink first passes through a URL-shortening service ( hxxps://qr[.]paps[.]jp/1GWsa ) before redirecting to a fake bpost site. The ca
urlhttps://bpost[e. The campaign used several fake bpost domains, including: hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/ bpost[.
urlhttps://qr[ks The link first passes through a URL-shortening service ( hxxps://qr[.]paps[.]jp/1GWsa ) before redirecting to a fake bpost site.
Full article709 words · extracted from malwarebytes.com · click to collapse

Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands.

The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information.

A fake bpost delivery email

A recent campaign targeting customers of the Belgian postal service bpost begins with an email claiming that a package could not be delivered because €4.95 in customs duties has not been paid.

A phishing email pretending to be from bpost, claiming €4.95 in customs duties is owed before a parcel can be delivered. 
A phishing email, in Dutch, pretending to be from bpost

In English, the subject and message read:

Undelivered package—customs duties due (tracking no. 3232116291*******).

Your package could not be delivered on September 9, 2026, because the customs duties (€4.95) have not been paid.

The amount is small enough that recipients may pay without giving it much thought. However, the website does not stop at collecting the supposed fee. It asks for personal information, card details, and banking information.

How the scam works 

The link first passes through a URL-shortening service (hxxps://qr[.]paps[.]jp/1GWsa) before redirecting to a fake bpost site. The campaign used several fake bpost domains, including:

hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/

bpost[.]center, which is the domain shown in the screenshots below.

The page copies bpost’s branding and displays security claims such as “Secure SSL connection,” “256-bit SSL,” “SEPA compliant,” and “Secure payment.” These labels were added by the scammers and do not prove that the page or payment is secure.

We’ve translated the screenshots below from the original Dutch into English.

The first page asks for the recipient’s name, phone number, email address, and age:

That reference to receiving funds does not match the email’s claim that a customs fee must be paid. The next page asks for an IBAN, card number, expiry date, and payment amount:

Then it asks for the real target: full card and bank details. 

The original Dutch version contained another mistake: One of its buttons read “Indian search” instead of “Betaal,” the Dutch word for “Pay.” Mistakes like this can expose a scam, but many phishing pages are built carefully enough that there will be no obvious typo or mistranslation.

Once submitted, card details may be used for fraudulent purchases or sold to other criminals. The personal and banking information may also be used to make later scams more convincing.

How to protect yourself 

  • Check delivery claims independently. Open the courier’s official app or type its website address into your browser, then use your tracking number to check the delivery.
  • Check the sender and destination. A message may use a courier’s name while coming from an unrelated email address or linking to a different domain.
  • Be wary of unexpected fees or refunds. A small payment or promised refund can be used to persuade you to provide much more valuable information.
  • Be wary of requests for extensive financial information. A request for an IBAN as well as card details should be treated with suspicion, particularly when it supposedly relates to a small delivery fee.

If you entered your card or banking information on a suspicious site, contact your bank or card provider immediately. Freeze the affected card if your banking app allows it, monitor your accounts for unfamiliar transactions, and change any password you entered on the site.

Malwarebytes tracks and blocks these campaigns as they appear. If you’re unsure about a message, Scam Guard—built into Malwarebytes for Windows, Mac, Android, and iOS—can check it for you. Paste in the message or link, or upload a screenshot, for an instant assessment.

Malwarebytes Scam Guard
Scam Guard can analyze a suspicious email, text, link, or screenshot and tell you whether it may be a scam.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

About the author

Sr. Director, ThreatLabs, Europe. Cybersecurity geek. Food, music, movies and arts lover. My dog Yoda has me trained really well.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details