The package delivery text scam is now the single most commonly reported type of text-based fraud in America, per the FTC’s own data — more common than fake job offers, fake fraud alerts, or fake unpaid tolls. It works precisely because almost everyone is expecting some kind of package at nearly any given moment these days, which makes the underlying premise instantly, effortlessly believable to the average recipient. Here’s the official USPS guidance quoted verbatim, real FTC loss figures pulled directly from primary sources, and a real, named, prosecuted federal case tied specifically to this exact fraud pattern.


Table of Contents
The Real Numbers: FTC Data on Text Scams
$470 Million in Losses, 2024
The FTC’s official April 2025 report found American consumers reported a combined $470 million in direct financial losses to text-message-originated scams during 2024 alone — five times higher than 2020, even as the total number of reports actually declined. Roughly 247,000 separate text-fraud reports were filed with the FTC over the course of 2024 alone, per the agency’s own tally. Fake package delivery notifications were the single most commonly reported text scam type, ahead of fake job offers, fake fraud alerts, and fake unpaid-toll texts. (FTC, April 2025)
Why This Peaks Around the Holidays
USPS itself delivered roughly 16 billion individual mail items and packages combined during the 2025–2026 holiday shipping season, according to USPS’s own official newsroom data release. (USPS Newsroom, Jan 2026) More real packages physically in transit at once simply means more people plausibly expecting a delivery at any given moment — exactly the larger, more target-rich attack surface that makes this specific scam format so consistently effective during peak holiday shipping periods each year.
Official USPS Guidance, Word for Word
The One Fact That Exposes Almost Every Fake Text
The US Postal Inspection Service states this directly on its own official page: “USPS will not send customers text messages or e-mails without a customer first requesting the service with a tracking number, and it will NOT contain a link.” (USPIS, official) That second half is the single most practical test available: if any text about a package contains a clickable link, and you didn’t specifically opt in first with a real, actual tracking number, it fails USPS’s own clearly stated policy immediately and completely — no further analysis of the message’s wording or urgency is even needed at that point.
USPIS’s Recommended Response Steps
The Postal Inspection Service’s official guidance breaks the response into six steps: Think (verify the sender’s identity, ask yourself why they’d need this information); don’t reply or click any links (a link can install malware or redirect you to a convincing fake site); report it (to the impersonated organization and to law enforcement); delete and block the sender (most carriers support blocking via 611); protect your data generally (“treat your personal information like cash,” in USPIS’s own words); and monitor your accounts and bills afterward for any signs of misuse.
A Real, Named, Prosecuted Case
Raimond Cabrera De Leon, Guilty Plea, July 2026
Raimond Cabrera De Leon, 33 years old, pleaded guilty on July 16, 2026, in federal court in the District of New Jersey, to a formal charge of conspiracy to receive and transport stolen goods across state lines. He was part of an international ring that stole more than $1.5 million in electronics shipments from FedEx and a major cellular carrier by scraping public tracking-system data through automated scripts and bribing corrupt carrier employees.
Thirteen individuals in total were formally charged as part of the broader ring; New Jersey authorities alone identified more than 400 separate targeted package thefts involving cellular devices specifically during 2024, prompting the formation of a dedicated multi-agency task force combining the Union County Prosecutor’s Office, the New Jersey State Police, and the FBI’s Newark field office working together. (Department of Justice, District of New Jersey)
Why This Case Is Relevant Even Though It’s Not Pure Smishing
This particular ring combined automated data scraping and insider bribery with actual physical theft rather than pure SMS phishing for stolen credentials — worth being precise about this distinction, since it isn’t a perfectly one-to-one match for every single fake tracking text you personally might receive on your own phone. But it demonstrates something genuinely important beyond its specific technical details: organized, well-resourced, multi-person criminal groups are actively targeting the exact same underlying package-tracking ecosystem that ordinary smishing texts also exploit, treating shipment tracking data as a real, monetizable asset worth building dedicated criminal infrastructure and insider relationships around.
Why This Particular Scam Format Works So Well


USPS Informed Delivery
USPS’s own genuinely free service, Informed Delivery, shows real scanned images of your actual incoming mail alongside current package status, all directly available at informeddelivery.usps.com — a legitimate way to check what’s actually arriving without ever needing to click a link in a text message.
Type the Tracking Number Directly
A standard USPS tracking number runs 20–22 digits long. Rather than clicking any link at all, copy the number if one is actually given in the text, and type it directly into usps.com, fedex.com, or ups.com yourself using your own browser — if the text is fake, the real tracking site will simply show no matching record found, immediately exposing the scam without you ever having exposed any personal information in the process.
How and Where to Report It
- Forward the text to 7726 (“SPAM”) — your carrier may reply asking for the sender’s number to help trace and block it.
- Email spam@uspis.gov specifically for USPS-impersonating texts, including the message body, sender number, date, and a screenshot.
- File a report at ReportFraud.ftc.gov, the FTC’s general consumer complaint portal, which walks you through the sender number and message text.
- The FCC also accepts complaints about unwanted robocalls and texts through its own consumer complaint portal.
Beyond USPS: FedEx and UPS Impersonation
- Don’t enter any information on the page that loads, even if it looks convincing — close it immediately if you haven’t typed anything yet.
- If you already entered payment or login details, contact your bank or card issuer immediately to flag the transaction and consider a card replacement.
- Change the password on any account whose credentials you may have entered, ideally using a password manager going forward so you’re not manually typing credentials into pages at all — see our password manager comparison.
- Watch for follow-up phishing attempts — scammers who successfully phish once often sell or reuse the confirmed-working contact information for further targeting.
Package Delivery Text Scam: Frequently Asked Questions
Does USPS ever send legitimate text messages?
Yes, but only if you specifically opted in using a real tracking number first, and per USPS’s own official policy, those legitimate texts will never contain a link. Any unsolicited package text with a link fails this test immediately.
How much money have people lost to text scams like this?
The FTC reported $470 million in losses to text-message scams in 2024, a five-fold increase since 2020, with fake package delivery notifications the single most commonly reported text scam type.
What should I do with a suspicious package delivery text?
Don’t click any link or reply. Forward it to 7726, and for USPS impersonation specifically, email spam@uspis.gov with the message details. Verify any real delivery directly through USPS Informed Delivery or by typing the tracking number into the carrier’s official site yourself.
Are people actually prosecuted for package delivery scams?
Yes — a real July 2026 case saw a defendant plead guilty in New Jersey federal court as part of a 13-person ring that stole over $1.5 million in shipments by scraping tracking data and bribing carrier employees, alongside a dedicated law enforcement task force formed specifically to address the pattern.
What if I already clicked the link in a fake delivery text?
Don’t enter any information if the page is still loading. If you already entered payment or login details, contact your bank immediately and change any reused passwords, ideally moving to a password manager to prevent manually typing credentials into unverified pages going forward.
Are FedEx and UPS delivery texts scammed the same way as USPS?
Yes — the same core test applies. Both companies generally require opt-in before sending automated text updates, and an unsolicited text with a link claiming to be from either carrier deserves the same default suspicion as a fake USPS text.
Why do package delivery scams work so well compared to other text scams?
Almost everyone is plausibly expecting a delivery at any given time, which makes the premise instantly believable without the scammer needing to know anything specific about the target — unlike a scam requiring a more elaborate, specific pretext.

