Fake package delivery texts, and why they know your name

"Your package is held at our facility. Update your delivery preferences to avoid return." A tracking number, a link, and a small fee to release it.

You didn't order anything. Or you did, and that's the problem, because at any given moment most people have a package in transit and no clear memory of which carrier has it.

These are smishing messages: phishing delivered by text. How phishing works covers the family they belong to. This is about this particular one, which is the highest-volume version in circulation.

Why the text works

It exploits a small, specific gap in your knowledge. You're probably expecting something. You probably don't remember the carrier. The message asks for an amount too small to argue about, usually a dollar or two in redelivery or customs fees.

The fee isn't the point. The point is your card number, entered on a page that looks like a carrier's site. Some versions instead collect enough personal detail to open accounts, and some drop malware if you're on a device that allows it.

The tell most people miss: carriers don't charge redelivery fees by text message, and they don't need your card to release a parcel.

How to read one

The link is the evidence. Real carriers use their own domains. Fakes use lookalikes with an extra word, an unusual ending, or a shortened link that hides where it goes. If you can't see the full destination, treat it as fake.

Check the sender. Legitimate carrier messages come from consistent short codes or numbers. A personal mobile number, an email-style address, or a foreign country code is a giveaway.

Match it against a real order. Open the retailer's app or your order confirmation and look at the actual tracking there. Never through the text.

Notice the pressure. A deadline, a threat of return to sender, a package "held." Real delivery notices don't manufacture urgency.

Check the tracking number independently. Copy it and paste it into the carrier's real site, typed by you. Fake numbers don't resolve, or resolve to something unrelated.

What to do

Don't tap the link. Don't reply, including "STOP," which confirms the number is live and sells for more.

Report it. Forward the message to 7726 (SPAM) on major US carriers, at no charge. Report it in your phone's messaging app as junk, and file with the FTC.

Delete it and block the sender. Expect more from different numbers, since these are sent in bulk from rotating senders.

If you tapped the link but entered nothing, you're probably fine. Close the page, don't return to it, and watch for follow-ups.

If you entered card details, call your card issuer now, report it as fraud, and ask for a replacement card. Watch for small test charges, which typically precede larger ones.

If you entered personal details such as your address and date of birth, treat it as the start of an identity-theft attempt. A credit freeze is the proportionate response, and the first 48 hours after a data breach covers the same immediate window.

Why it has your real name

Most of these texts are blind, sent to blocks of numbers. The ones that use your actual name, and sometimes your street, are a different tier, and they convert far better precisely because the detail reads as legitimate.

That detail is bought, not hacked. Data brokers and people-search sites publish full names next to phone numbers and current addresses, compiled from public records, purchase data, and app trackers, and sold in bulk to anyone who pays. A list of numbers is cheap. A list of numbers with matching names and addresses is worth more, because a message that opens with your name gets tapped.

It's also why the volume rises rather than falls. Every list you land on gets resold.

Delist finds those listings, files the removals, and keeps re-checking them, since brokers routinely repost profiles after they come down. Fewer live records means fewer lists carrying your number next to your name. Run a free scan to see where your details are published.

If the calls are following the same pattern, scam calls that already know your bank details covers that version.

Frequently asked questions

How did they know I was expecting a package?

Usually they didn't. These go out in bulk, and enough recipients have something in transit that guessing works. Messages using your real name mean your number appeared on a list that included it.

Is it safe to tap the link just to look?

No. Some pages attempt drive-by downloads or fingerprint your device, and tapping confirms the number is live. There's nothing to learn from the page that's worth the risk.

What happens if I reply STOP?

Nothing good. Scam senders ignore opt-outs, and a reply confirms a real person is reading. Report and block instead.

I paid the $1.99 fee. What now?

Call your card issuer, report it as fraud, and ask for a replacement card. The small charge exists to validate the card before it's sold or used for something larger.

Why does this keep happening after I block the numbers?

Because the senders rotate through numbers continuously. Blocking stops one sender, not the campaign. Reporting to 7726 does more, since carriers use it to filter at the network level.

Do these messages ever come from real carriers?

Yes, carriers send genuine delivery notifications. The distinguishing feature is that real ones never ask for payment or personal details by text. When in doubt, check tracking in the retailer's app instead.

Find out what data brokers know about you

Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.

Start your free scan