Parcel delivery text scams succeed because they mimic an event the whole household — and half the office — is waiting for: a delivery. Training staff to spot them comes down to three tells drilled until they're reflexes: an unexpected tracking link, a fee to release the parcel, and a sender that doesn't match the carrier.
TL;DR
- Treat any tracking text you didn't expect as hostile until proven otherwise.
- A "small fee" to release or redeliver a parcel is the clearest scam marker in 2026.
- Check the sender against the carrier's real app or website — never through a link in the message.
- Drill report-first behaviour, because one reported scam text warns the whole team.
Why this matters
Australians receive a constant stream of genuine delivery notifications in 2026, which is exactly why fake ones work. The scam message claims a parcel is held, delayed or awaiting a tiny payment, and the link leads to a card-harvesting page or a malware install. Scamwatch, the ACCC's scam reporting service, keeps a running library of these patterns in its guide to spotting and avoiding scams, and the Australian Cyber Security Centre tracks smishing — scam SMS — as a growing threat alongside email phishing in its social engineering overview.
The business angle is what most training misses. Staff buy on company cards, reception signs for deliveries, and every employee with a phone is a valid target — the scam doesn't need your work email address, just your mobile number.
How the scam plays out
- A text arrives, often late afternoon, claiming a delivery was missed or a parcel is held at a depot.
- The message carries a link styled to look like a carrier's tracking page.
- The link asks for a small "redelivery fee" or "customs charge" — usually a few dollars.
- Card details entered go straight to the scammer, and the page may quietly push malicious apps or permission requests on phones that allow it.
- Repeat contact follows: the same number later runs gift card, tax debt or bank alert scams because it now knows the number is live and responsive.
The low amounts are the design, not a flaw. A $2.99 charge raises no alarms, triggers no fraud review, and validates the number for the next, larger pitch.
The three tells to drill
Tell 1: the unexpected link
You click tracking links for parcels you know you're waiting on. If no parcel is expected, no legitimate tracking text should arrive. Train the sequence: no expected delivery, no tap.
Tell 2: the fee
Carriers do not ask for card details over an unsolicited text link to release a parcel. Any amount — $1.99 or $49.99 — is a scam marker. Genuine customs or delivery charges appear through the retailer or the carrier's official channels, not a texted link.
Tell 3: the sender mismatch
Scam texts often arrive from plain numbers, odd international codes or sender IDs that look almost right. The check is quick and safe: open the carrier's official app or type its website address yourself, then look for the parcel there. Never verify through the link in the message — that is the trap testing whether you'll click.
Three drills that build the reflex
Drill 1: the plain tracking text
Send a simulated smishing text mimicking a missed-delivery notice. Debrief anyone who taps: the link they clicked is the exact mechanics of the real scam. Keep the simulation short and repeat it quarterly — the point is the reflex, not a course.
Drill 2: the fee version
Run the same text with a "$1.49 redelivery fee" on the landing page. This variant catches people who spotted the odd link but assumed a tiny charge is harmless. The debrief makes the point that the fee is the payload, not the link.
Drill 3: report-first
Measure who reports the simulated smish, not only who taps. Reporting is the behaviour that protects everyone else — a reported scam text can be flagged to the team within minutes. Scenario-based simulations of this kind are exactly what Cyber Aware's security awareness training runs, with report rates tracked per team through human risk reporting rather than a single blended score.
What to do when someone already tapped
Move fast and in order:
- Did they enter card details? Contact the bank immediately and cancel the card.
- Did the phone install anything or prompt for permissions? IT review before anything else gets tapped.
- Forward the message to Scamwatch so the number gets recorded.
- No blame in the debrief — the goal is that the next person reports within minutes instead of hiding it.
A 30-day rollout
- Week 1: brief the three tells in a team meeting. One slide, ten minutes.
- Week 2: run drill 1; follow up with a two-minute lesson for anyone who tapped.
- Week 3: run drills 2 and 3 together and measure report rates.
- Week 4: review by team, re-brief the outliers, and schedule the next quarterly cycle.
Use a phishing gap assessment first if you want a baseline: it shows which teams already report suspicious messages and which ones need the drills most.
Common mistakes
- Training only the front desk. Any employee with a mobile is a target; smishing does not check job titles.
- "Just don't click links." Too vague to act on. Give the three tells and the report habit instead.
- Blocking rather than reporting. Deleting the message protects one person; reporting it protects the whole team.
- Assuming SMS scams are a consumer problem. Company cards, corporate phone numbers and staff purchases make businesses prime targets.
FAQ
What does a parcel delivery scam text look like? It claims a delivery failed or a parcel is held, and links to a fake tracking page that asks for a small fee or card details. Real carriers don't request payment through unsolicited text links.
Is the small redelivery fee real? No. The fee is the point of the scam — a small enough charge to avoid fraud alerts, paid straight to the scammer along with your card details.
How do I check a delivery text safely? Open the carrier's official app or type the carrier's website address yourself and look for the parcel there. Never use the link inside the message.
Can scam texts infect a phone? Some can. Fake delivery pages may push permission requests or malicious apps, which is why a tapped link deserves an IT check even when no payment was made.
Should we report scam texts to anyone? Yes — report to Scamwatch so the number and pattern are recorded, and internally so your team knows the scam is circulating.
How often should we run smishing drills? Quarterly. Delivery scams rotate wording constantly, and short repeat drills keep the reflex current without pulling staff off the floor.
One last thing
The scam doesn't need your work email or your password — just your mobile number and a moment of inattention near a delivery date. Train the reflex on the whole team, because the phone in the pocket doesn't care what the job title is.