Bewary Get Bewary
Scam patternPublished Oct 8, 2026

Is this package delivery text asking for a small fee a scam?

Bewary fraud research, published by Andrey Khayrullaev, founder. How we research scam patterns.

Example text message

USPS Notice: Your parcel is on hold due to incomplete address details. Redelivery tariff of $2.97 must be paid within 4 hours or the package will be returned. Confirm here: https://usps-redelivery-fee.com/track FedEx Delivery: We attempted delivery today. Customs balance $3.48 unpaid. Pay now to release package: https://fedex-parcel-update.net UPS: Your package cannot be delivered until postage correction of $1.99 is paid. Update delivery: https://ups-track-fee.info Sent from: 917-406-2819

SCAM

Scam. The tiny delivery fee text is built to collect card data, not move a package. The structural tell is the payment path: an unrequested SMS jumps from “package held” to a checkout page, with no verified tracking session, no account login you started, and no order page you already know. The $2.97 fee is bait for the full card number, expiry, security code, billing address, and any bank approval code that follows.

How to spot this scam

  • Refuse any delivery fee that starts inside a surprise text link.Why
  • Read the root domain at the end of the link before you touch it.Why
  • Treat the $1 to $5 delivery balance as the hook, not the charge.Why
  • Stop when the text says “your parcel” but gives no real tracking number.Why
  • Ignore the four-hour return threat and verify the shipment outside the text.Why
  • Quit the page if it asks for a full card to fix a delivery address.Why
  • Do not type a bank code into the courier page after the card form.Why
  • Distrust a delivery text sent from an ordinary personal-looking number.Why

What to do now

  1. Open your order confirmation or carrier app before touching the SMS link.Why
  2. Search the exact tracking number only if the text gives one.Why
  3. Forward the exact scam text to 7726 before deleting it.Why
  4. Screenshot the fake checkout if you already opened it.Why
  5. Freeze the card you typed into the fake delivery checkout.Why
  6. Tell the bank if you typed a one-time code into the courier page.Why
  7. Change only the account password you typed into that delivery page.Why

What it looks like on your phone

Recreated example of the scam text message: USPS Notice: Your parcel is on hold due to incomplete address details. Redelivery tariff of $2.97 must be paid
A representative example based on common reports. Exact wording varies.

Got a message like this? Check yours free

Paste any text, link, or number you are unsure about. Bewary gives you a straight answer in seconds, and the exact reason why.

Private. Never sold, never tied to you.

The detail behind this

The reasoning behind each line above, for when the immediate question is settled.

Why each of those gives it away

Refuse any delivery fee that starts inside a surprise text link.

Real shipping problems tie back to a shipment record, a sender, a retailer order, or an account session you opened yourself. The scam skips that chain and drops you straight into a courier-styled checkout because the checkout is the trap.

Read the root domain at the end of the link before you touch it.

In https://fedex-parcel-update.net, the root domain is fedex-parcel-update.net, not fedex.com. In https://usps-redelivery-fee.com/track, the root domain is usps-redelivery-fee.com, not usps.com. The brand word at the front is camouflage.

Treat the $1 to $5 delivery balance as the hook, not the charge.

A $2.97 tariff, $3.48 customs balance, or $1.99 postage correction feels too small to fight. The fake page then asks for the same card details needed for a much larger online purchase.

Stop when the text says “your parcel” but gives no real tracking number.

Mass-blast delivery texts stay vague on purpose: “package held,” “address incomplete,” “delivery failed.” A real shipment problem has an order, a sender, a tracking number, or a carrier notice you can match against something you bought.

Ignore the four-hour return threat and verify the shipment outside the text.

“Must be paid within 4 hours” is there to keep you out of the order page and away from the real tracking screen. Parcels do not need a mystery card payment from a local-looking SMS number to avoid instant return.

Quit the page if it asks for a full card to fix a delivery address.

A redelivery address correction and a customs charge are different jobs, but the fake page blends them into one form. That form wants name, phone, billing address, card number, expiry, security code, and email because those fields can be reused.

Do not type a bank code into the courier page after the card form.

That second screen is the dangerous part. The fake delivery site can trigger a real bank challenge, wallet add, or transaction check, then ask you to paste the one-time code back into the fake site as “verification.”

Distrust a delivery text sent from an ordinary personal-looking number.

A message from 917-406-2819 asking for a card payment has the wrong shape for a courier billing event. Criminals use cheap SMS routes and burner numbers, then swap them when blocks start landing.

Working through the steps

Open your order confirmation or carrier app before touching the SMS link.

Use the receipt, marketplace order page, or carrier app you already had before the text arrived. If there is a real hold, the same tracking number will show it there without needing the link from the message.

Search the exact tracking number only if the text gives one.

Copy the number by hand into the carrier app or the retailer order page, not into the link from the text. If the message has no tracking number, treat it as a spray-and-pray delivery blast.

Forward the exact scam text to 7726 before deleting it.

7726 is the carrier spam-reporting short code used for unwanted texts. Forwarding preserves the sender number and the lure link so the wireless abuse systems can block repeats faster.

Screenshot the fake checkout if you already opened it.

Capture the URL bar, the dollar amount, the card fields, and any bank-code screen. Those details help your bank understand this was a fake courier payment flow, not a normal failed purchase.

Freeze the card you typed into the fake delivery checkout.

Use your banking app or the service number printed on that card and say the card was entered into a fake package-fee page. Ask them to block the card, check pending authorizations, and look for wallet enrollment or online purchase attempts tied to that entry.

Tell the bank if you typed a one-time code into the courier page.

Say the code appeared after a fake redelivery or customs fee form. That detail changes the bank’s response because the code can approve a transaction, add the card to another wallet, or confirm a risky account action.

Change only the account password you typed into that delivery page.

Start with the retailer, carrier, or email account named on the fake form. If you only entered card details and a billing address, focus on the card first instead of wasting time changing unrelated passwords.

Sources and reporting

Use official channels to confirm a suspicious request and report fraud.