Delivery fraud is a scam that uses package delivery as the hook for stealing payment information or money. A common pattern is a fake courier or fee request tied to an unexpected package, where the victim is pressured to pay immediately and the scammer captures card details through a manipulated payment process.
What Delivery Fraud Is
Delivery fraud is a social-engineering scam that uses the trust people place in package delivery and courier services. The fraudster creates urgency, then steers the victim toward a payment action that exposes card details or transfers money directly.
How Delivery Fraud Works
The scam usually begins with an unsolicited message, call, or doorstep interaction about an unexpected parcel, customs issue, missed delivery, or outstanding fee. The goal is not the package itself, but a fast reaction before the target verifies the claim.
Attackers often mimic legitimate delivery brands, use lookalike tracking pages, or ask the victim to “confirm” a small payment. That payment flow can be a fake checkout page, a card-enrollment step, or a form that captures payment data for later misuse.
Delivery fraud works because it combines a believable context with time pressure. People are more likely to comply when they expect a package, fear losing it, or think a minor delivery charge is routine.
Common Variants and Red Flags
Delivery fraud appears in several forms, including fake redelivery fees, customs clearance scams, courier impersonation, and phishing messages that imitate shipment alerts. The specific lure can change, but the pattern is consistent: a payment request tied to urgency and limited verification time.
Red flags include unusual sender addresses, shortened or misspelled URLs, payment requests that arrive before any confirmed purchase, and messages that ask for immediate action outside the normal merchant or carrier checkout flow.
Any request for card details, one-time codes, or bank transfer information in response to an unexpected parcel should be treated as suspicious until independently verified through official carrier channels.
Security Implications
Delivery fraud is financially damaging because it can lead to immediate card theft, unauthorized payments, and follow-on account abuse if the captured details are reused elsewhere. It also exploits brand trust, which can reduce the victim’s skepticism even when the transaction itself looks abnormal.
The broader security issue is not just the payment loss. Successful scams can also create identity and account exposure when victims reuse passwords, enter personal data, or approve a payment prompt that is later linked to fraudulent activity.
For organisations, the risk extends to employees using work devices or corporate cards to resolve what appears to be a routine delivery issue. A single convincing message can bypass normal caution and create a direct path to fraud.
Risk and Threat Considerations
Delivery fraud is effective because it uses urgency, legitimacy cues, and routine consumer behaviour to push victims into making a payment before they can validate the request. The same pattern can be scaled through mass messaging, brand impersonation, and cloned checkout pages.
Failure mechanism: The victim is steered away from the real delivery process and into a fraudulent payment or data-entry flow where card details, banking information, or one-time verification codes are captured.
Impact: The result can be direct financial loss, card compromise, account takeover risk, and secondary abuse if the stolen payment data or personal information is reused in other scams.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0, OWASP ASVS and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Delivery fraud relies on user deception and urgency. |
| Recommendation — Train users to verify delivery-payment requests through trusted channels before entering any payment details. | ||
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training | The scam is defeated by user awareness and verification behavior. |
| PR.AA-01 — Identity Management, Authentication, and Access Control | Fraud often captures credentials or payment data through fake flows. | |
| Recommendation — Provide phishing and scam awareness training that covers parcel and courier impersonation. Require authenticated access to payment or shipment portals rather than trusting message-linked forms. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Fraudulent checkout and phishing pages depend on weak visibility into deceptive flows. |
| Recommendation — Log and monitor suspicious payment and account-verification attempts to support detection and response. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Security Awareness Training | Users need training to spot courier impersonation and payment scams. |
| Recommendation — Include delivery-fraud scenarios in security awareness training. | ||
Practitioner Guidance
What to watch for: Treat any unexpected delivery fee, re-delivery demand, or customs payment request as untrusted until you confirm it through a known carrier website or official app. The safest response is to independently navigate to the vendor rather than follow links from the message itself.
Governance implication: Organisations should make it clear how employees verify shipment-related requests, especially when company cards, procurement workflows, or executive travel deliverables are involved. A simple verification habit is often the difference between a nuisance and a successful fraud attempt.