SmishingGuides

Fake parcel delivery texts impersonating NZ Post and Aramex

A held parcel, a small redelivery fee, a convincing link: how fake courier texts steal Kiwi card details, and how to check safely.

N
By NoCall team
NoCall Editorial
4 min read
#delivery scam#smishing#NZ Post#Aramex#parcel fraud#fake texts

Summarize this article with

"NZ Post: your parcel is held at the depot due to an unpaid $3.50 redelivery fee. Confirm your address here." The text looks routine, the link looks official, and you actually are waiting for a parcel. That plausibility is exactly why fake delivery texts are among the most successful scams in New Zealand. Behind the link sits a harvesting page built to steal your card details — or malware built to take over your phone and text everyone in your contacts next.

How the delivery scam works

The script is short and effective:

  1. The lure. A text impersonating NZ Post, CourierPost, Aramex, DHL, NZ Couriers, or Post Haste claims a parcel needs attention: a redelivery fee, address confirmation, customs charge, or a missed delivery.
  2. The link. A shortened or lookalike URL leads to a page dressed in the courier's branding, often with working tracking-number fields to feel legitimate.
  3. The harvest. You are asked for personal details and card numbers to pay a tiny fee. The fee is irrelevant — the goal is your card data, sometimes followed by a fake "verification" step requesting one-time codes.
  4. The malware variant. Some campaigns instead push an "app" to track your parcel. Installing it infects Android phones with malware that spreads by texting the same lure to all your contacts.

Scammers blast these texts to thousands of numbers at once. They do not know you are expecting a parcel — with online shopping this common, enough recipients will be.

Red flags in the message

Pause before tapping and check for these tells:

  • A link demanding payment or details. Real couriers do not collect surprise fees through text links. Any fee request arriving solely by text link is suspicious by definition.
  • Generic greeting and vague parcel. "Dear customer, your package" with no tracking number, sender name, or order reference. Genuine courier messages reference your actual consignment.
  • Sender oddities. Texts from random mobile numbers or email-style sender IDs rather than the courier's usual channels. Note that sender names can also be faked, so a familiar name alone proves nothing.
  • Urgency and threats. "Pay within 24 hours or your parcel is returned" — pressure to stop you checking.
  • Sloppy URLs. Shortened links, odd domains, or addresses that merely contain the courier's name alongside extra words. Couriers operate on their official domains, not lookalikes.

One flag is enough to treat the text as hostile. Genuine delivery issues survive a five-minute verification; scams do not.

How to check a real parcel safely

Never tap the link. Instead, verify through channels you choose:

  1. Use the courier's official app. NZ Post, Aramex, and the other major couriers all offer apps and tracking pages — open them yourself and enter your tracking number.
  2. Check with the sender. Your order confirmation email or the retailer's site shows the real tracking status and which courier holds the parcel.
  3. Type the address yourself. If you must use the web, type the courier's official address into your browser rather than following any link.
  4. Call on the official number. If something genuinely seems stuck, ring the courier's published customer-service line.

If nobody you ordered from can tie the message to a real consignment, the text was a scam. Forward it to 7726 and delete it.

The malware texts that spread through contacts

The nastiest delivery-adjacent campaigns do not want your card — they want your phone. Malware-laden texts, in the style of the Flubot waves that hit New Zealand, urge you to install a "voicemail" or "tracking" app from outside the official app stores. Once installed, the malware reads contacts and fires the same lure onward, which is why these texts sometimes appear to come from a friend's real number. Defences:

  • Never install apps from text links. Use the Google Play Store or Apple App Store only.
  • If a friend's number sends a bizarre link, call the friend another way before touching it — their phone may be infected.
  • Keep your phone's operating system and security updates current; they close the holes malware relies on.

If you tapped, paid, or installed

Move fast to limit the damage:

  1. Entered card details? Call your bank immediately, freeze the card, and dispute any charges. Watch statements closely for weeks.
  2. Entered login credentials? Change those passwords from another device and enable two-factor authentication.
  3. Installed an app from the link? Uninstall it, run a security scan, and consider a factory reset if anything behaves strangely — back up photos and data first.
  4. Report it. Forward the text to 7726, report the scam to Netsafe, and tell your bank and NZ Police if money moved.

Fake parcel texts thrive on the gap between ordering and delivery, when any logistics message feels plausible. Close that gap with one habit: courier news is only real when you see it in the courier's own app. Everything arriving by text link is guilty until proven innocent.

Sources and review

Reviewed:

Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.

Article details

Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.

Author: NoCall team4 min read

Received a suspicious call?

Look up the number in NoCall before sharing data, calling back, or clicking any link.

Search a phone number or a company name (Spark, Spark and One NZ...) to check if it has been reported as spam.