Most of us have seen the text by now.
“Your package could not be delivered. Please confirm your address and pay a small redelivery fee.” It arrives with a tracking number that looks real, a company name that feels familiar, and a link that seems urgent. The message usually shows up right when you’re expecting something—Amazon, Target, a birthday gift, or school supplies.
The problem isn’t that the text is clever. The problem is how quickly it can move from a $3 “redelivery fee” to a stolen bank login, a drained account, or a full identity foothold.
Here’s how the chain usually works, and where ordinary families can break it.

The Typical Attack Path
The text or email lands
It often comes from a number that looks local or uses a well-known carrier name (UPS, FedEx, USPS, Amazon). The language is polite, slightly urgent, and free of obvious spelling mistakes.You tap the link
The page that opens looks almost identical to a real tracking or payment portal. It may even show a plausible package status.You’re asked for a small payment or “verification”
Common requests include a redelivery fee, an address confirmation, or a quick login to “release” the package. Some versions ask you to enter card details; others push you to a fake login page for your email, bank, or shopping account.The real goal is rarely the $3
Once you enter credentials or payment information, the attacker has what they actually wanted: a working username and password, a session cookie, or enough personal data to attempt account recovery elsewhere. The small fee is just the bait that makes the request feel reasonable.The follow-on damage begins
With a valid login, the attacker can change recovery email addresses, add their own phone number, or quietly drain gift cards and saved payment methods. In some cases they use the compromised account to reset passwords on other services that share the same email.
What the Attacker Needed
A phone number or email address (often bought in bulk or scraped from previous breaches)
A believable carrier or retailer name
A cloned or lightly modified landing page
Enough urgency to keep you from pausing
They did not need advanced hacking skills. They needed you to treat a text message like a trusted notification.
Where Families Can Interrupt the Chain
The strongest interruption points are early and simple:
Never pay a delivery fee or confirm personal details through a link that arrived by text or email.
Open the official carrier or retailer app (or type the real website address yourself) and check the tracking number there.
If the message claims to be from a company you actually use, call the phone number printed on a recent package or on the company’s official site—not the number in the text.
Treat any request for a “small fee” or “account verification” as a red flag until you have independently verified it.

Five-Minute Actions You Can Take Today
Open your phone’s messaging app and scroll for any recent delivery texts. If any contain links you already tapped, change the password on the account you may have entered and turn on multifactor authentication if it isn’t already active.
For your most important accounts (email, banking, primary shopping), confirm that multifactor authentication is enabled and that recovery phone numbers and emails are still yours.
Tell the other adults in the house the same rule: real carriers do not ask for payment or login credentials through a text link.
If you have older relatives who receive packages, send them a quick note with the same advice. One short conversation can prevent a much longer cleanup.
A fake package text is not a sophisticated cyber attack. It is a well-designed interruption of a normal household routine. The good news is that the same routine gives you easy places to stop it.
Five minutes now beats five hours later.
No notes on this sheet yet.