The package delivery text scam is now the single most commonly reported type of text-based fraud in America, per the FTC’s own data — more common than fake job offers, fake fraud alerts, or fake unpaid tolls. It works precisely because almost everyone is expecting some kind of package at nearly any given moment these days, which makes the underlying premise instantly, effortlessly believable to the average recipient. Here’s the official USPS guidance quoted verbatim, real FTC loss figures pulled directly from primary sources, and a real, named, prosecuted federal case tied specifically to this exact fraud pattern.


Table of Contents
The Real Numbers: FTC Data on Text Scams
$470 Million in Losses, 2024
The FTC’s official April 2025 report found American consumers reported a combined $470 million in direct financial losses to text-message-originated scams during 2024 alone — five times higher than 2020, even as the total number of reports actually declined. Roughly 247,000 separate text-fraud reports were filed with the FTC over the course of 2024 alone, per the agency’s own tally. Fake package delivery notifications were the single most commonly reported text scam type, ahead of fake job offers, fake fraud alerts, and fake unpaid-toll texts. (FTC, April 2025)
Why This Peaks Around the Holidays
USPS itself delivered roughly 16 billion individual mail items and packages combined during the 2025–2026 holiday shipping season, according to USPS’s own official newsroom data release. (USPS Newsroom, Jan 2026) More real packages physically in transit at once simply means more people plausibly expecting a delivery at any given moment — exactly the larger, more target-rich attack surface that makes this specific scam format so consistently effective during peak holiday shipping periods each year.
Official USPS Guidance, Word for Word
The One Fact That Exposes Almost Every Fake Text
The US Postal Inspection Service states this directly on its own official page: “USPS will not send customers text messages or e-mails without a customer first requesting the service with a tracking number, and it will NOT contain a link.” (USPIS, official) That second half is the single most practical test available: if any text about a package contains a clickable link, and you didn’t specifically opt in first with a real, actual tracking number, it fails USPS’s own clearly stated policy immediately and completely — no further analysis of the message’s wording or urgency is even needed at that point.
USPIS’s Recommended Response Steps
The Postal Inspection Service’s official guidance breaks the response into six steps: Think (verify the sender’s identity, ask yourself why they’d need this information); don’t reply or click any links (a link can install malware or redirect you to a convincing fake site); report it (to the impersonated organization and to law enforcement); delete and block the sender (most carriers support blocking via 611); protect your data generally (“treat your personal information like cash,” in USPIS’s own words); and monitor your accounts and bills afterward for any signs of misuse.
A Real, Named, Prosecuted Case
Raimond Cabrera De Leon, Guilty Plea, July 2026
Raimond Cabrera De Leon, 33 years old, pleaded guilty on July 16, 2026, in federal court in the District of New Jersey, to a formal charge of conspiracy to receive and transport stolen goods across state lines. He was part of an international ring that stole more than $1.5 million in electronics shipments from FedEx and a major cellular carrier by scraping public tracking-system data through automated scripts and bribing corrupt carrier employees.
Thirteen individuals in total were formally charged as part of the broader ring; New Jersey authorities alone identified more than 400 separate targeted package thefts involving cellular devices specifically during 2024, prompting the formation of a dedicated multi-agency task force combining the Union County Prosecutor’s Office, the New Jersey State Police, and the FBI’s Newark field office working together. (Department of Justice, District of New Jersey)
Why This Case Is Relevant Even Though It’s Not Pure Smishing
This particular ring combined automated data scraping and insider bribery with actual physical theft rather than pure SMS phishing for stolen credentials — worth being precise about this distinction, since it isn’t a perfectly one-to-one match for every single fake tracking text you personally might receive on your own phone. But it demonstrates something genuinely important beyond its specific technical details: organized, well-resourced, multi-person criminal groups are actively targeting the exact same underlying package-tracking ecosystem that ordinary smishing texts also exploit, treating shipment tracking data as a real, monetizable asset worth building dedicated criminal infrastructure and insider relationships around.
Why This Particular Scam Format Works So Well


USPS Informed Delivery
USPS’s own genuinely free service, Informed Delivery, shows real scanned images of your actual incoming mail alongside current package status, all directly available at informeddelivery.usps.com — a legitimate way to check what’s actually arriving without ever needing to click a link in a text message.
Type the Tracking Number Directly
A standard USPS tracking number runs 20–22 digits long. Rather than clicking any link at all, copy the number if one is actually given in the text, and type it directly into usps.com, fedex.com, or ups.com yourself using your own browser — if the text is fake, the real tracking site will simply show no matching record found, immediately exposing the scam without you ever having exposed any personal information in the process.
How and Where to Report It
- Forward the text to 7726 (“SPAM”) — your carrier may reply asking for the sender’s number to help trace and block it.
- Email spam@uspis.gov specifically for USPS-impersonating texts, including the message body, sender number, date, and a screenshot.
- File a report at ReportFraud.ftc.gov, the FTC’s general consumer complaint portal, which walks you through the sender number and message text.
- The FCC also accepts complaints about unwanted robocalls and texts through its own consumer complaint portal.
Beyond USPS: FedEx and UPS Impersonation
- Don’t enter any information on the page that loads, even if it looks convincing — close it immediately if you haven’t typed anything yet.
- If you already entered payment or login details, contact your bank or card issuer immediately to flag the transaction and consider a card replacement.
- Change the password on any account whose credentials you may have entered, ideally using a password manager going forward so you’re not manually typing credentials into pages at all — see our password manager comparison.
- Watch for follow-up phishing attempts — scammers who successfully phish once often sell or reuse the confirmed-working contact information for further targeting.
Package Delivery Text Scam: Frequently Asked Questions
Does USPS ever send legitimate text messages?
Yes, but only if you specifically opted in using a real tracking number first, and per USPS’s own official policy, those legitimate texts will never contain a link. Any unsolicited package text with a link fails this test immediately.
How much money have people lost to text scams like this?
The FTC reported $470 million in losses to text-message scams in 2024, a five-fold increase since 2020, with fake package delivery notifications the single most commonly reported text scam type.
What should I do with a suspicious package delivery text?
Don’t click any link or reply. Forward it to 7726, and for USPS impersonation specifically, email spam@uspis.gov with the message details. Verify any real delivery directly through USPS Informed Delivery or by typing the tracking number into the carrier’s official site yourself.
Are people actually prosecuted for package delivery scams?
Yes — a real July 2026 case saw a defendant plead guilty in New Jersey federal court as part of a 13-person ring that stole over $1.5 million in shipments by scraping tracking data and bribing carrier employees, alongside a dedicated law enforcement task force formed specifically to address the pattern.
What if I already clicked the link in a fake delivery text?
Don’t enter any information if the page is still loading. If you already entered payment or login details, contact your bank immediately and change any reused passwords, ideally moving to a password manager to prevent manually typing credentials into unverified pages going forward.
Are FedEx and UPS delivery texts scammed the same way as USPS?
Yes — the same core test applies. Both companies generally require opt-in before sending automated text updates, and an unsolicited text with a link claiming to be from either carrier deserves the same default suspicion as a fake USPS text.
Why do package delivery scams work so well compared to other text scams?
Almost everyone is plausibly expecting a delivery at any given time, which makes the premise instantly believable without the scammer needing to know anything specific about the target — unlike a scam requiring a more elaborate, specific pretext.
Related Guides
- How to Spot and Avoid Phishing Scams
- AI Voice Cloning Scams: How to Protect Your Family
- Best Password Managers of 2026: Honest Comparison
- Two-Factor Authentication: The Essential Guide
FAQ: Package Delivery Text Scam
What does a package delivery text scam look like?
A typical package delivery text scam says something like: “Your USPS package could not be delivered. Reschedule: [fake link].” The URL leads to a phishing page that steals your card or login details. A real package delivery text scam indicator: the sender number is a random mobile number, not a verified short code (USPS uses 28777; FedEx uses 48773).
What should I do if I clicked a package delivery text scam link?
If you clicked a package delivery text scam link but did not enter any information, you are likely safe. Close the tab immediately and run a malware scan with Malwarebytes. If you entered card details, call your bank immediately to freeze the card. For a package delivery text scam where you submitted login credentials, change those passwords immediately and enable two-factor authentication.
How do I report a package delivery text scam?
Forward the package delivery text scam message to 7726 (SPAM) — this is the carrier reporting number that works on AT&T, Verizon, and T-Mobile. Also report to the FTC at reportfraud.ftc.gov. For USPS-branded package delivery text scam messages, report at postalinspectors.uspis.gov. Reporting helps carriers block the sending numbers faster.
Final Warning: Package Delivery Text Scam Prevention
The package delivery text scam works because people expect delivery notifications and are less suspicious when a text arrives around an expected package. The rule: never click tracking links in SMS messages. Go directly to USPS.com, FedEx.com, or UPS.com and enter your tracking number there. A package delivery text scam cannot steal anything if you never click the link it provides.
Enable two-factor authentication on accounts that could be targeted after a package delivery text scam — especially email, banking, and shopping accounts. See also: how to avoid phishing scams.
Sources: FTC Consumer Information on Smishing; USPS Postal Inspection Service fraud reports; FTC Scam Reporting.
Package Delivery Text Scam: Prevention Checklist
Use this checklist to stay protected from every package delivery text scam variant: (1) Never click links in unsolicited delivery texts — go directly to the official carrier website. (2) Verify the sender number against the official carrier contact page. (3) Report any package delivery text scam to the FTC at reportfraud.ftc.gov. (4) If you clicked a package delivery text scam link, run a malware scan immediately and change passwords for any accounts accessed on that device.
A package delivery text scam often triggers during high shopping periods (Black Friday, Christmas). Scammers buy ad space and send package delivery text scam messages at scale during these windows. Setting up real delivery alerts directly through your carrier app eliminates the need to evaluate whether any text is a package delivery text scam.
What to Do After Clicking a Package Delivery Text Scam Link
If you fell for a package delivery text scam: disconnect from Wi-Fi immediately, run antivirus scan, monitor bank accounts for 90 days, and place a fraud alert with credit bureaus. See our best identity theft protection and best antivirus 2026 for post-scam recovery tools.

