According to Statista, over 161 billion parcels were shipped worldwide in 2022, cementing courier services as the backbone of modern e-commerce.
Cybercriminals are now heavily exploiting this global reliance through a massive “fake shipment tracking” phishing scheme.
By capitalizing on the anxiety of a missed delivery, threat actors are deploying real-time phishing campaigns to harvest personal information and banking credentials, with a significant concentration of attacks targeting the Middle East and Africa (MEA).
How The Phishing Campaign Operates
Attackers initiate the scam by sending urgent SMS messages claiming a package delivery has failed. These texts typically urge victims to update their address information or pay unexpected handling fees and tariffs to release the parcel.
To ensure these alerts appear completely authentic, scammers use local-looking anonymous numbers or spoofed Sender IDs.

This spoofing technique allows the fraudulent messages to bypass basic scrutiny by merging directly into the legitimate message threads of trusted couriers already on the victim’s phone.
Once a victim clicks the link, they are directed to a fraudulent website hosted on cheap, disposable top-level domains such as .xyz, .help, or .shop.
Under the hood, these phishing pages are highly sophisticated. HTML analysis by Group-IB researchers reveals embedded scripts that establish an open WebSocket connection, allowing attackers to log keystrokes in real time.
As victims type their addresses, credit card numbers, and one-time passwords, the data is instantly exfiltrated to attacker-controlled servers.
Furthermore, the malicious scripts generate unique UUID tokens to track individual victim sessions, indicating a highly organized backend operation.

Much of this infrastructure shares characteristics with Darcula, a Chinese-language Phishing-as-a-Service (PhaaS) platform.
Operating largely through underground Telegram channels, Darcula provides cybercriminals with over 20,000 counterfeit domains and hundreds of phishing templates.
While the primary lure involves postal services, this organized operation is rapidly expanding to mimic online shops, transportation apps, and telecommunications providers.
Mitigating The Phishing Threat
The rapid expansion of these fake shipment scams requires proactive defensive action from both consumers and organizations.

Because Group-IB the attackers rely heavily on high-pressure social engineering tactics, identifying the red flags is the most effective way to prevent credential theft.
- Never click tracking links sent via SMS, WhatsApp, or email directly.
- Manually visit the official courier website and enter your tracking number to verify its status.
- Cross-reference unsolicited tracking numbers against your actual purchase history and invoices.
- Scrutinize website URLs for unfamiliar or uncommon domain extensions like .sbs, .top, or .click.
- Remember that legitimate courier companies do not demand sudden payment for simple administrative tasks like address updates.
- Businesses should implement robust domain security protocols, such as DMARC and SPF, to prevent brand spoofing.
- Organizations must regularly educate customers about ongoing phishing attempts and provide secure, official verification channels.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.