Join our Newsletter — 33% off our NHI Course

What should employees do when a shipping, shopping, or charity message feels suspicious?

They should stop interacting with the message and validate the request through a trusted channel. That means opening the retailer, carrier, or charity website directly, checking account or shipment status independently, and confirming payment or donation requests with an official contact point. If the message is fraudulent, report it quickly so others are not exposed to the same lure.

How should people respond to a suspicious shipping, shopping, or charity message?

A suspicious message should be treated as untrusted until the request is verified from a source you reached yourself, not by following the message’s links or reply path. The practical issue is not just fraud, but whether the message is trying to redirect payment, collect credentials, or create urgency that bypasses normal review.

The safest response is to pause, verify independently, and avoid any action that could confirm you are receptive to the lure. That usually means checking the order, delivery, or donation request through the organisation’s official site or known contact details, then comparing the message against what that organisation would normally ask for.

What verification steps matter before you trust the request?

Verification should start outside the message itself. Open the retailer, carrier, or charity website directly, sign in through the normal route, and check whether the account, shipment, or donation request actually exists. If the message claims a problem, use an official phone number or contact page you already trust, rather than any number or button embedded in the message.

Look for mismatches in domain names, sender details, payment instructions, and the level of urgency. Fraudulent messages often try to move the conversation away from the organisation’s normal process and into a channel the attacker controls. A quick independent check is more reliable than trying to inspect the message for signs of authenticity on its own.

What should happen after the message is confirmed as fraudulent?

Once the message is identified as fraudulent, the priority is to reduce further exposure. Report it through the organisation’s reporting mechanism, alert the relevant team if it was received at work, and delete it only after reporting if your process requires preservation for analysis. If any data was entered, credentials were reused, or payment details were shared, treat it as a potential compromise event rather than a simple nuisance.

For employees, the value of reporting is not only containment. It also helps security teams block similar lures, warn other recipients, and tune detection rules around the wording, sender infrastructure, and impersonated brand. Fast reporting matters because these campaigns often succeed through volume and repetition, not technical sophistication.

Risk and Threat Considerations

Suspicious shipping, shopping, and charity messages are common because they exploit ordinary trust. The main risk is not the message itself, but the moment a user follows the embedded path and hands over money, account access, or personal data to a fraudulent destination.

Failure mechanism: The attacker relies on urgency, familiar brand cues, and a believable request to get the recipient to click, pay, donate, or sign in before verifying the request through an independent channel.

Impact: The result can be financial loss, account takeover, stolen payment details, or broader exposure if the same credentials are reused elsewhere.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 RS.CO-2 — Communications Suspicious-message reporting depends on timely internal communication.
PR.AT-1 — Awareness and Training Employees need phishing awareness to recognise suspicious shipping and charity lures.
Recommendation — Report the lure through your incident communications path so others can be warned quickly. Train staff to verify requests through trusted channels before acting.
MITRE ATT&CK T1566 — Phishing The message is a phishing lure using social engineering to drive user action.
Recommendation — Map the lure to phishing techniques and tune detections for brand impersonation and urgency cues.
CIS Controls v8 CIS-14 — Security Awareness and Skills Training User verification behaviour is a core anti-phishing safeguard.
CIS-17 — Incident Response Management Fraudulent-message reporting is an incident response action that limits spread.
Recommendation — Embed verification and reporting habits into awareness training. Define a fast reporting path for suspicious messages and suspected compromise.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Reports of suspicious messages support review and correlation across recipients.
Recommendation — Review reported lures and correlate them to block similar activity.

Practitioner Guidance

What to prioritise: Train employees to verify through a known-good route first, because the decision point is whether the request can be confirmed without interacting with the message. If the communication asks for payment, login, or personal information, treat verification as mandatory before any response.

What to verify: Confirm that the organisation actually has the shipment, order, or donation request, and check whether the sender’s domain, destination URL, and request path match the organisation’s normal process. For support teams, the most useful evidence is the original message, sender details, and the exact lure wording so similar attempts can be blocked faster.

Practitioner takeaway: The goal is not to outguess the phish from the inbox, but to remove the inbox from the trust decision and validate the request from a channel the attacker cannot influence.