A shipping scam is a fraudulent message or website that pretends there is a delivery problem so the victim will click a link, download malware, or submit sensitive information. These scams rely on the trust people place in parcel tracking and the expectation of a quick delivery update.
Expanded Definition
A shipping scam is a delivery-themed fraud that uses urgency, familiarity, and routine expectations about parcel tracking to push a harmful action. The message may claim a fee is due, a parcel is delayed, or a label is missing, then steer the target toward a fake tracking page or a malicious file. The scam is effective because the story feels ordinary, not because it is technically sophisticated.
The boundary to watch is that the scam is defined by the deception and its intended outcome, not by the channel alone. It can arrive by SMS, email, messaging apps, search ads, or a spoofed website, and it may imitate a real carrier without being connected to one. Guidance across the industry is consistent on the core pattern, although the exact lure changes by region and delivery platform. A useful reference point for the broader phishing pattern is the CISA social engineering and phishing guidance, which describes why trust cues and urgency make these messages persuasive.
Examples and Use Cases
Shipping scams tend to follow a small number of repeatable patterns, which is why they remain effective even when the branding changes.
- A text message claims a package is waiting for a small customs or redelivery payment and links to a lookalike checkout page.
- An email says a delivery could not be completed and asks the recipient to open an attached invoice, label, or receipt.
- A fraudulent tracking site asks for card details, address confirmation, or account login credentials before showing a fake status update.
- A message about a missed delivery urges immediate action, which increases the chance of rushed clicks and form submission.
- A spoofed support page asks the user to install a mobile app or open a document, turning a parcel story into malware delivery.
The tradeoff for defenders is that legitimate courier communications can look similar to scam traffic, so simple keyword filtering is rarely enough. Users and security teams need to judge the destination, not just the wording.
Security Implications
The main security problem is that the scam weaponises a normal business expectation: people do not want to miss a package, and they often act quickly when a delivery appears stalled. That urgency can lead to credential theft, payment fraud, malware installation, or disclosure of personal data. In enterprise settings, the same lure can be used against employees who receive shipments at work, creating a path from a harmless-looking notice to endpoint compromise or account takeover.
Misclassification is also a practical failure mode. If users assume every shipping notice is routine, they may ignore spoof indicators such as odd domains, pressure to pay in unusual ways, or requests for authentication outside the carrier’s normal workflow. The most common symptom is that the scam succeeds before any technical control has a chance to intervene, because the victim supplies the needed data directly. From a defensive perspective, this is a trust-abuse problem first and a malware problem second.
Domain and Governance Relevance
Shipping scam belongs primarily to fraud prevention, phishing defence, and user awareness, not to identity architecture. Its security relevance comes from the control failure around trust verification: the recipient is asked to authenticate a story, a link, or a payment request before the organisation can validate it independently. That makes delivery-themed fraud especially useful for testing how well messaging controls, browser protections, and reporting paths work in practice.
The NHI angle is indirect rather than central. A shipping scam can be used to steal credentials that later affect business accounts, but that downstream consequence does not change the primary subject of the term. For NHIMG readers, the useful governance question is whether delivery-related lures are covered by general phishing controls, reporting workflows, and awareness training, rather than whether they map to a machine-identity problem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 14 — Security Awareness and Skills Training | Shipping scams rely on user deception, so awareness is a direct control lever. |
| 9 — Email and Web Browser Protections | These scams are commonly delivered through email, SMS-linked pages, and fake sites. | |
| Recommendation — Train users to verify delivery claims before clicking links or opening attachments. Block known malicious domains and filter suspicious delivery-themed messages. | ||
| MITRE ATT&CK | T1566 — Phishing | Shipping scams are a phishing variant that uses a delivery pretext to elicit action. |
| Recommendation — Map delivery-lure activity to T1566 and hunt for credential-harvest or malware follow-on. | ||
| NIST CSF 2.0 | PR.AT-1 — Awareness and Training | User recognition and verification behavior are central to resisting shipping scams. |
| PR.DS-1 — Data Management | Fake tracking pages often seek personal, payment, or account data from victims. | |
| Recommendation — Build delivery-scam recognition into role-based security awareness programs. Limit exposure of sensitive data that a scam page could harvest from users. | ||
Related resources from NHI Mgmt Group
- How should crypto platforms reduce scam losses without slowing legitimate users?
- Who is accountable when a help desk scam leads to account takeover?
- How should security teams reduce phishing risk when AI makes scam messages more convincing?
- How can organisations measure whether scam prevention is working?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org