Federal investigators have flagged a wave of fraudulent text messages posing as package delivery alerts, warning that the scheme now runs through a network of more than 10,000 fake web addresses built to imitate real shipping carriers. The FBI’s Internet Crime Complaint Center says the campaign has grown large enough that recipients are being told to simply erase the messages rather than try to inspect or respond to them, a stance that reflects how convincing these lookalike sites have become.
How the Delivery-Text Scheme Works
The scam follows a familiar smishing pattern, but at a larger scale than most previous waves. A text message arrives claiming that a package could not be delivered because of an incomplete address, an unpaid customs fee, or a failed delivery attempt. The message includes a link that appears to lead to a shipping carrier’s tracking page. Instead, it routes to one of thousands of near-identical domains built to harvest names, addresses, card numbers, and one-time passcodes the moment a visitor tries to “fix” the delivery. Because each domain is disposable, a carrier or browser blocklist can knock one out only for the operation to redirect traffic to another within hours.
Behind the More Than 10,000 Fraudulent Domains
The scale of the infrastructure is what separates this campaign from an ordinary phishing text. According to the Internet Crime Complaint Center’s public service announcement, the domains are registered and rotated in bulk, many sharing templates, hosting providers, or registration patterns that suggest an organized operation rather than isolated scammers. That volume makes conventional defenses, such as maintaining a list of known-bad web addresses, largely ineffective, since new domains can be stood up faster than they can be catalogued and blocked.
Why the FBI Recommends Deleting the Message
Rather than advising people to examine the link closely or check whether a package is actually in transit, the bureau’s guidance is blunt: delete the text without clicking anything. That recommendation acknowledges that the fake pages are often polished enough, complete with real-looking logos and tracking-number fields, that a casual glance will not reveal anything wrong. The FBI’s warning, reported by Newsweek, notes that even a brief visit to one of these pages can trigger data collection or malware downloads before a person realizes the site is fraudulent.
Warning Signs of a Fake Delivery Notice
A handful of details tend to separate the fraudulent messages from a carrier’s genuine notifications. Legitimate shipping companies rarely ask for payment information by text to “release” a package, and they typically reference an order or tracking number a customer already recognizes. The scam texts, by contrast, often arrive when no package is actually expected, use generic greetings instead of a name, and create urgency by claiming a parcel will be returned or destroyed within a short window unless the recipient acts immediately. The web addresses themselves are usually a giveaway on closer inspection, mixing a carrier’s name with random characters or an unfamiliar domain ending rather than the carrier’s actual website.
Reporting a Suspicious Text to IC3
Beyond deleting the message, the bureau encourages anyone who receives one of these texts, or who has already clicked a link and entered information, to file a report with the Internet Crime Complaint Center at ic3.gov. Those reports feed into the broader effort to track domain patterns, hosting infrastructure, and financial accounts tied to the scheme, which is how law enforcement builds the case needed to pursue takedowns and prosecutions. Carriers such as USPS, UPS, and FedEx also maintain their own channels for forwarding suspicious texts, and mobile carriers can often block a sending number after enough reports accumulate. Because the domains rotate so quickly, though, individual reporting is treated less as a way to stop a single message and more as a way to help investigators map the operation as a whole.
Package-delivery texts succeed as a scam vehicle for a simple reason: online shopping has made a “missed delivery” plausible for almost anyone at almost any time, unlike scams built around a narrower pretext such as a specific bank or tax agency. A text arriving during a busy shipping season, or shortly after a person has actually ordered something online, does not need much polish to seem believable, which is part of why the same basic template can be reused across tens of thousands of domains without losing effectiveness. The approach also sidesteps email spam filters that have grown more aggressive over the years, since text messages are still generally treated as a more trusted channel than inbox mail.
Anyone who has already tapped one of these links and entered card details is generally advised to treat the card as compromised immediately, contacting the issuing bank to cancel it and request a replacement rather than waiting to see whether unauthorized charges appear first. Enabling transaction alerts, checking recent statements line by line, and changing the password on any account that reused the same credentials entered on the fake page are standard follow-up steps, since a single successful lure is sometimes used to test whether a phone number is worth continuing to target with follow-up scams. Multifactor authentication tied to a banking or email app, rather than a text-message code, adds a layer of protection that a stolen password alone cannot bypass.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- Long-term use of common heartburn pills is linked to kidney and dementia risk
- 9 pickup trucks with a reputation for falling apart after 100,000 miles
- Consumer Reports names the 2026 models it expects to break down the most