Threat Advisory

Parcel Delivery Phishing Campaigns Impersonate Couriers Globally

Threat: Phishing Campaign
Targeted Region: United States, France
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Parcel delivery phishing campaigns have been observed worldwide, often impersonating local courier services. These messages typically claim that a package cannot be delivered due to an invalid address or unpaid customs duties, prompting recipients to visit fake courier websites and provide personal and financial information. The campaigns are highly targeted, with scammers using various tactics to convince victims into divulging sensitive data. The phishing scheme involves redirecting users through a URL-shortening service before landing on a fake bpost site that mimics the legitimate website's branding.

The page displays security claims such as 'Secure SSL connection' and '256-bit SSL,' which are false indicators of security. Users are then prompted to provide their name, phone number, email address, age, IBAN, card number, expiry date, payment amount, full card details, and bank information.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Parcel delivery phishing campaigns have been observed worldwide, often impersonating local courier services. These messages typically claim that a package cannot be delivered due to an invalid address or unpaid customs duties, prompting recipients to visit fake courier websites and provide personal and financial information. The campaigns are highly targeted, with scammers using various tactics to convince victims into divulging sensitive data. The phishing scheme involves redirecting users through a URL-shortening service before landing on a fake bpost site that mimics the legitimate website's branding.

The page displays security claims such as 'Secure SSL connection' and '256-bit SSL,' which are false indicators of security. Users are then prompted to provide their name, phone number, email address, age, IBAN, card number, expiry date, payment amount, full card details, and bank information.[emaillocker id="1283"]

Once submitted, this data may be used for fraudulent purchases or sold to other criminals. These campaigns have been observed in multiple regions worldwide, including the United States, France, Spain, Italy, the Netherlands, and Belgium. The scammers' tactics are designed to deceive victims into divulging sensitive financial information, which can lead to further scams and financial losses.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Collection T1005 Data from Local System -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu