Links on this page may be affiliate links — the price stays the same for you. How affiliate links work

United Kingdom / Guides / Shopping and your rights / Phishing Around Delivery and Payment Notifications: What to Watch For

26 June 2026 · 4 min read · Shopping and your rights

Phishing Around Delivery and Payment Notifications: What to Watch For

Why a delivery text is such a good disguise

A message about a parcel works as a scam precisely because it is plausible. Most people who shop online are expecting at least one delivery at any given time, so a text claiming there is a problem with a package fits neatly into an existing expectation, unlike, say, a message about a prize you never entered. The scam even has an official name in fraud prevention literature: smishing, phishing carried out by text message rather than email, and it is treated as a specific, tracked category of scam by both the FTC in the US and reporting bodies in the UK.

How the fake delivery message actually works

The FTC describes the pattern clearly: a text arrives claiming to be from a courier or postal service, often naming a real company such as a major parcel carrier or a national postal service, with a supposed tracking code and a link to "update delivery preferences" or resolve a problem with the address. Clicking the link leads to a page designed to look like the real courier's site, where the target is asked to enter personal or financial information, or sometimes to pay a small "redelivery fee" that goes straight to the scammer. The FTC notes a useful detail: postal and courier services generally do not send unsolicited text updates unless the recipient specifically signed up for tracking alerts, so an unexpected delivery text is already slightly suspicious before its content is even read.

The UK reporting system treats this as a known, large-scale problem

The UK's national approach reflects how common this has become. The National Cyber Security Centre runs a dedicated reporting route: suspicious emails can be forwarded to [email protected], and suspicious text messages can be forwarded free of charge to the short number 7726, which reports the message to the recipient's mobile network. Action Fraud, the UK's national fraud and cybercrime reporting centre, separately tracks parcel delivery phishing as a recurring seasonal pattern, particularly around periods of heavy online shopping, and recommends never providing bank details or passwords in response to a delivery message, however official it looks.

Payment notifications carry the same trick, aimed differently

A close relative of the fake delivery text is the fake payment or account notification: a message claiming a card payment failed, a subscription is about to renew at a higher price, or an account has been locked, again with a link to "fix" the problem. The mechanism is the same one used in delivery scams, urgency plus a link to a convincing fake page, just aimed at getting login details or card numbers directly instead of routing through a fake redelivery fee. The same caution applies: a genuine payment problem from a real retailer or bank does not usually need to be resolved by clicking a link in an unexpected text or email.

Habits that make this scam far less effective

  • Do not click a link in an unexpected delivery or payment text or email; if you think it might be genuine, open the courier's or company's app or type its known address directly into the browser instead.
  • Check whether you actually signed up for tracking alerts from that specific carrier; an unrequested delivery text is a reason for suspicion on its own, per FTC guidance.
  • Never enter a card number or password on a page reached by clicking a link from a text message, regardless of how official the page looks.
  • Report suspicious texts and emails using the official channels, forwarding texts to 7726 and emails to [email protected] in the UK, or through ReportFraud.ftc.gov in the US, which helps these systems flag repeat patterns.

None of this has anything to do with a genuine voucher code or coupon code from a retailer's own checkout; those are applied on the shop's own site at the point of payment, never through a link sent afterwards claiming a delivery or payment problem. We list checked codes across 527 shops in 22 countries on daily-coupons.info, and never ask for card details or account passwords to use a listed code, as explained on our FAQ page.

This article is general safety information, not legal advice. If you believe you have been targeted or have already provided information to a phishing message, contact your bank and the relevant national reporting service promptly.

Frequently asked questions

How can I tell a genuine delivery text from a fake one?

The safest approach is not to judge the text itself but to check independently: open the courier's official app or website directly, without using any link from the message, and look up the order status there using your own order number.

What should I do if I already clicked the link but did not enter any information?

Clicking alone is lower risk than entering data, but it can still confirm to a scammer that your number or address is active, so extra caution with future messages is worthwhile, and running a security check on the device is a reasonable precaution.

Is it worth reporting a phishing text if nothing was lost?

Yes. Reporting services such as the UK's 7726 number and [email protected], or the FTC's ReportFraud.ftc.gov in the US, use these reports to identify and block new scam campaigns, which helps even when the individual report involved no financial loss.

Do payment notification scams only target credit cards?

No. They target any payment method with linked personal or financial data, including debit cards, digital wallets and, increasingly, payment apps, since the goal is usually to capture login details or card numbers rather than to exploit one specific payment type.

← Back to all guides