A message reading some variation of 'your parcel could not be delivered, click here to reschedule' or 'customs duty pending, pay now to release your package' is, according to cybercrime reporting data, the single most common phishing vector reaching Indian phones — arriving via SMS, WhatsApp, and occasionally email, timed deliberately around major shopping periods when genuine delivery notifications are expected.

The script's effectiveness comes from exploiting an existing expectation rather than creating a new one — unlike a cold scam message, a fake delivery notification arrives into a context where the recipient may genuinely be expecting a parcel, lowering the scepticism that would normally greet an unexpected message asking for payment or personal details.

TRUVEXA's analysis of these message scripts identifies a consistent structure: an urgent but plausible logistics problem, a very short link (often using a URL shortener to obscure the actual destination), and a request that combines small payment (making the ask feel low-risk, 'just ₹10 redelivery fee') with capturing card details on a fake payment page that harvests the full card number, CVV and OTP.

The tell that distinguishes these from genuine courier communications is specific: legitimate logistics companies in India — India Post, Blue Dart, Delhivery, DTDC — do not request card payment via SMS link for redelivery fees, and any message demanding 'customs duty' payment via a personal link rather than through the courier company's official app or website should be treated as fraudulent by default.

The financial damage in these cases typically occurs not from the small stated fee but from the payment page itself, which is designed to capture full card credentials for later unauthorised use — meaning the actual harm often occurs days or weeks after the original message, at which point the connection to the fake delivery SMS is not obvious to the victim.

If you have received a delivery or customs message asking for payment and are unsure whether it is genuine, do not click the link — instead check tracking status directly through the courier's official app, and if you have already engaged with such a message, TRUVEXA can analyse the conversation for the specific phishing script markers documented here.

Analyse Your Own Conversation
3 free analyses to start. No credit card required. Results in under 30 seconds.