Fake bpost Customs Fee Scam Steals Bank Details

Malwarebytes · Low sophistication
Last updated September 18, 2026

A real phishing campaign impersonated postal couriers (including Belgium’s bpost) to trick people into paying a small “customs fee” for an undelivered parcel. Victims were sent to a fake courier website that collected personal details, then escalated to stealing full card and banking (IBAN) information.

How the Attack Worked

This campaign impersonated bpost, the Belgian postal service, with a message claiming a parcel could not be delivered because a small customs fee of €4.95 remained unpaid. The message included a tracking number to add credibility and urged the recipient to click a link to resolve the issue quickly.

The link did not go directly to a bpost site. It first passed through a URL-shortening service before redirecting to a fake bpost-branded page. That page asked for personal details such as name, phone number, email, and age. Once that information was submitted, the site escalated its request to full card details and IBAN, banking information far beyond what a small customs fee would ever require.

Why It Succeeded

The scam relied on a small dollar amount to lower the victim's guard. A request for €4.95 feels low-risk and mundane, which made people more willing to comply quickly without scrutinizing the request. The fake site reinforced this false sense of safety with reassuring security language, including references to a secure SSL connection, 256-bit encryption, and SEPA compliance, all designed to make the payment page look like a legitimate courier checkout flow.

The attack also targeted a broad audience. Because parcel deliveries are relevant to nearly everyone, this pretext works across all employees, administrative staff, and customer support roles, not just finance teams.

What to Watch For

  • An unexpected message about a delivery problem tied to a small, urgent fee
  • A link that routes through a URL shortener before reaching the courier's supposed website
  • A payment page that asks for far more information than a delivery fee would justify, including IBAN and full card numbers
  • Sender addresses or linked domains that do not match the courier name used in the message

How to Build Resistance

Organizations and individuals can reduce risk from this type of scam with a few consistent habits. Verify any delivery claim independently by opening the courier's official app or typing its website address directly into a browser, then check the delivery using the tracking number provided. Always compare the sender's address and the linked domain against the courier's real domain, since a message can use a trusted courier's name while linking somewhere unrelated.

Treat any unexpected fee or promised refund as a potential lure, since scammers use small transactions to extract much more valuable financial data. A request for an IBAN alongside full card details is a strong warning sign, especially when tied to a minor delivery charge. If card or banking information was already submitted to a suspicious site, contact the bank or card provider immediately and monitor the account for fraudulent activity.

Key findings

  • Campaigns impersonate well-known couriers and claim a delivery failed due to an invalid address or unpaid fees.
  • A featured example impersonated Belgium’s bpost and demanded a small customs payment (€4.95) to encourage quick compliance.
  • Links were routed through a URL shortener before redirecting to a fake bpost-branded site.
  • The phishing site collected personal details first (name, phone, email, age), then requested IBAN and full card details.
  • The fake site used reassuring security language (e.g., “Secure SSL connection,” “256-bit SSL,” “SEPA compliant”) to appear legitimate.
  • Stolen card details may be used for fraud or sold; collected personal/banking data can enable more convincing follow-on scams.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/AP, Executive assistants, Front desk/administrative staff, Customer support/helpdesk.
  • Affected industries: Postal and courier services, Logistics and delivery, Consumers/households, Retail/e-commerce.
  • Attack channels: email, website.
  • Impersonated: bpost (Belgian postal service).

Red flags to watch for

  • Unexpected small fee request tied to delivery urgency
  • Link goes through a URL shortener before the courier site
  • Website asks for excessive information (IBAN plus full card details) for a small customs fee
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake bpost customs fee scam work?

Victims received a message claiming a parcel could not be delivered until a small customs fee of €4.95 was paid. The link passed through a URL shortener before landing on a fake bpost-branded site that first collected personal details, then requested IBAN and full card information.

Why did this phishing scam seem trustworthy?

The fake site displayed reassuring security language such as claims of a secure SSL connection and SEPA compliance to make the payment page look legitimate, even though it was collecting sensitive banking data.

What should I do if I entered my card or bank details on a fake delivery site?

Contact your bank or card provider immediately and monitor your accounts for fraudulent activity.

How can I verify a delivery fee message is real?

Do not use links in the message. Instead, open the courier's official app or type its website address directly into your browser and check the delivery status with your tracking number.

Read the video transcript

You get an email from “bpost”: undelivered package, €4.95 customs due, click to pay now. You tap the link, it runs through a URL shortener, then lands on a perfect-looking bpost page asking for your name, phone, email… then IBAN and full card details. Here’s the tell: no real courier needs your IBAN and full card just to fix a €4.95 fee, especially after a URL shortener and an email from a non‑bpost domain. If you get a parcel fee message, ignore the link. Open the courier’s official app or type their website yourself and check the tracking number there.

Similar attacks

Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Fake T-Mobile Points Expiry Texts Hit Phones

Fake T-Mobile Points Expiry Texts Hit Phones

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed…

September 17, 2026
Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026
Fake Microsoft Scan Pushes AV Uninstall Scam

Fake Microsoft Scan Pushes AV Uninstall Scam

Scammers are running Microsoft-branded “SysScan” websites that display a fake security scan and falsely claim Windows no longer supports third‑party antivirus. Victims are pressured to uninstall their antivirus, submit personal and banking details, and prepare for a “refund manager” phone call,…

August 24, 2026
Fake Tesla Token Presale Kit Steals Crypto

Fake Tesla Token Presale Kit Steals Crypto

Researchers found a turnkey scam kit sold on a cybercrime forum that lets criminals quickly stand up a fake crypto “presale” website styled to look like Tesla. The site uses pressure tactics and a fake investment dashboard to trick people into either handing over their wallet recovery phrase or…

August 12, 2026
Fake TikTok Shop Sites Mimic Badges to Steal Pay

Fake TikTok Shop Sites Mimic Badges to Steal Pay

Scammers are setting up lookalike websites that copy TikTok Shop’s design, trust badges, and wording to trick people into thinking they’re shopping inside TikTok. The main risk is entering payment (and sometimes loan-application) details into a site that has no real connection to TikTok, leading to…

August 11, 2026