Global Parcel‑Delivery Phishing Campaign Harvests Card and Bank Details
What Happened – Fraudsters are sending fake parcel‑delivery emails that mimic national couriers (USPS, bpost, Chronopost, etc.). The messages claim a small customs fee is due and direct recipients through a URL‑shortener to a counterfeit courier site that collects personal data, credit‑card numbers and IBANs.
Why It Matters for Trust & Control Assurance
- This is a classic phishing‑as‑delivery attack that tests whether an organization’s users can identify and block social‑engineering attempts – a core control‑area for any continuous control‑assurance program.
- Evidence of regular security‑awareness training, simulated phishing exercises and documented incident‑response playbooks provides a defensible audit trail across frameworks such as NIST CSF 2.0 and ISO 27001.
Who Is Affected – Retail & e‑commerce, logistics & courier services, financial institutions that process consumer payments, and any organization with employees handling delivery notifications.
Recommended Actions
- Deploy or refresh a security‑awareness training program that includes real‑world parcel‑delivery phishing simulations.
- Enforce email‑authentication standards (DMARC, SPF, DKIM) and monitor for spoofed courier domains.
- Require users to verify delivery notices via official carrier apps or websites, never through links in unsolicited emails.
- Capture and retain evidence of phishing attempts (email headers, URLs) for audit readiness.
Technical Notes – The campaign uses a URL‑shortening service (e.g., qr.paps.jp) that redirects to multiple look‑alike domains (e.g., bpost.be-pakje-ontvangen-nl-recevoir-colis-fr.my.id). The fake pages display bogus “256‑bit SSL” and “SEPA compliant” badges to create a false sense of security. No specific CVE is involved; the threat vector is social engineering via phishing.
Source: Malwarebytes Labs – Fake parcel delivery messages steal your card and bank details