A real phishing campaign impersonated postal couriers (including Belgium’s bpost) to trick people into paying a small “customs fee” for an undelivered parcel. Victims were sent to a fake courier website that collected personal details, then escalated to stealing full card and banking (IBAN) information.
How the Attack Worked
This campaign impersonated bpost, the Belgian postal service, with a message claiming a parcel could not be delivered because a small customs fee of €4.95 remained unpaid. The message included a tracking number to add credibility and urged the recipient to click a link to resolve the issue quickly.
The link did not go directly to a bpost site. It first passed through a URL-shortening service before redirecting to a fake bpost-branded page. That page asked for personal details such as name, phone number, email, and age. Once that information was submitted, the site escalated its request to full card details and IBAN, banking information far beyond what a small customs fee would ever require.
Why It Succeeded
The scam relied on a small dollar amount to lower the victim's guard. A request for €4.95 feels low-risk and mundane, which made people more willing to comply quickly without scrutinizing the request. The fake site reinforced this false sense of safety with reassuring security language, including references to a secure SSL connection, 256-bit encryption, and SEPA compliance, all designed to make the payment page look like a legitimate courier checkout flow.
The attack also targeted a broad audience. Because parcel deliveries are relevant to nearly everyone, this pretext works across all employees, administrative staff, and customer support roles, not just finance teams.
What to Watch For
- An unexpected message about a delivery problem tied to a small, urgent fee
- A link that routes through a URL shortener before reaching the courier's supposed website
- A payment page that asks for far more information than a delivery fee would justify, including IBAN and full card numbers
- Sender addresses or linked domains that do not match the courier name used in the message
How to Build Resistance
Organizations and individuals can reduce risk from this type of scam with a few consistent habits. Verify any delivery claim independently by opening the courier's official app or typing its website address directly into a browser, then check the delivery using the tracking number provided. Always compare the sender's address and the linked domain against the courier's real domain, since a message can use a trusted courier's name while linking somewhere unrelated.
Treat any unexpected fee or promised refund as a potential lure, since scammers use small transactions to extract much more valuable financial data. A request for an IBAN alongside full card details is a strong warning sign, especially when tied to a minor delivery charge. If card or banking information was already submitted to a suspicious site, contact the bank or card provider immediately and monitor the account for fraudulent activity.
Key findings
- Campaigns impersonate well-known couriers and claim a delivery failed due to an invalid address or unpaid fees.
- A featured example impersonated Belgium’s bpost and demanded a small customs payment (€4.95) to encourage quick compliance.
- Links were routed through a URL shortener before redirecting to a fake bpost-branded site.
- The phishing site collected personal details first (name, phone, email, age), then requested IBAN and full card details.
- The fake site used reassuring security language (e.g., “Secure SSL connection,” “256-bit SSL,” “SEPA compliant”) to appear legitimate.
- Stolen card details may be used for fraud or sold; collected personal/banking data can enable more convincing follow-on scams.
Who’s being targeted
- Commonly targeted roles: All employees, Finance/AP, Executive assistants, Front desk/administrative staff, Customer support/helpdesk.
- Affected industries: Postal and courier services, Logistics and delivery, Consumers/households, Retail/e-commerce.
- Attack channels: email, website.
- Impersonated: bpost (Belgian postal service).
Red flags to watch for
- Unexpected small fee request tied to delivery urgency
- Link goes through a URL shortener before the courier site
- Website asks for excessive information (IBAN plus full card details) for a small customs fee
Frequently asked questions
How did the fake bpost customs fee scam work?
Victims received a message claiming a parcel could not be delivered until a small customs fee of €4.95 was paid. The link passed through a URL shortener before landing on a fake bpost-branded site that first collected personal details, then requested IBAN and full card information.
Why did this phishing scam seem trustworthy?
The fake site displayed reassuring security language such as claims of a secure SSL connection and SEPA compliance to make the payment page look legitimate, even though it was collecting sensitive banking data.
What should I do if I entered my card or bank details on a fake delivery site?
Contact your bank or card provider immediately and monitor your accounts for fraudulent activity.
How can I verify a delivery fee message is real?
Do not use links in the message. Instead, open the courier's official app or type its website address directly into your browser and check the delivery status with your tracking number.
Read the video transcript
You get an email from “bpost”: undelivered package, €4.95 customs due, click to pay now. You tap the link, it runs through a URL shortener, then lands on a perfect-looking bpost page asking for your name, phone, email… then IBAN and full card details. Here’s the tell: no real courier needs your IBAN and full card just to fix a €4.95 fee, especially after a URL shortener and an email from a non‑bpost domain. If you get a parcel fee message, ignore the link. Open the courier’s official app or type their website yourself and check the tracking number there.