Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Global Parcel Delivery Phishing Campaign Harvests Card and Bank Details

Fraudsters impersonate national couriers in email scams that direct victims to counterfeit sites collecting credit‑card and banking information. The attack highlights the need for robust security‑awareness training and verifiable email‑authentication to satisfy audit‑readiness requirements.

LiveThreat™ Intelligence · 📅 September 19, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
malwarebytes.com

Global Parcel‑Delivery Phishing Campaign Harvests Card and Bank Details

What Happened – Fraudsters are sending fake parcel‑delivery emails that mimic national couriers (USPS, bpost, Chronopost, etc.). The messages claim a small customs fee is due and direct recipients through a URL‑shortener to a counterfeit courier site that collects personal data, credit‑card numbers and IBANs.

Why It Matters for Trust & Control Assurance

  • This is a classic phishing‑as‑delivery attack that tests whether an organization’s users can identify and block social‑engineering attempts – a core control‑area for any continuous control‑assurance program.
  • Evidence of regular security‑awareness training, simulated phishing exercises and documented incident‑response playbooks provides a defensible audit trail across frameworks such as NIST CSF 2.0 and ISO 27001.

Who Is Affected – Retail & e‑commerce, logistics & courier services, financial institutions that process consumer payments, and any organization with employees handling delivery notifications.

Recommended Actions

  • Deploy or refresh a security‑awareness training program that includes real‑world parcel‑delivery phishing simulations.
  • Enforce email‑authentication standards (DMARC, SPF, DKIM) and monitor for spoofed courier domains.
  • Require users to verify delivery notices via official carrier apps or websites, never through links in unsolicited emails.
  • Capture and retain evidence of phishing attempts (email headers, URLs) for audit readiness.

Technical Notes – The campaign uses a URL‑shortening service (e.g., qr.paps.jp) that redirects to multiple look‑alike domains (e.g., bpost.be-pakje-ontvangen-nl-recevoir-colis-fr.my.id). The fake pages display bogus “256‑bit SSL” and “SEPA compliant” badges to create a false sense of security. No specific CVE is involved; the threat vector is social engineering via phishing.

Source: Malwarebytes Labs – Fake parcel delivery messages steal your card and bank details

📰 Original Source
https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →