Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026

Here’s what you should know

February 6, 2026
Facebook X (Twitter) Instagram
Friday, February 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush
News

86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush

Team-CWDBy Team-CWDDecember 23, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


An 86% increase in malicious postal service websites over the past month has heightened the risk for consumers tracking holiday deliveries.

Cybercriminals are reportedly capitalizing on the seasonal spike in online shopping by sending convincing messages that appear to come from legitimate delivery companies, often warning of delayed or suspended packages.

The fake alerts typically arrive via text message or email and include links designed to steal personal or financial information. With shoppers expecting frequent updates, these scams are more likely to succeed during peak shipping periods.

Data published today by NordVPN showed that delivery services are being impersonated at rapidly growing rates, though the scale varies by brand. DHL was the most impersonated carrier overall, with fraudulent websites using its name increasing by 206% month-over-month (MoM).

DPD Group ranked second among targeted delivery brands, although the number of fake sites linked to it grew by a more modest 16%. The United States Postal Service (USPS) placed third but experienced the sharpest acceleration, with malicious websites imitating it rising by 850% in a single month.

“Scammers are evolving at an unprecedented pace, using AI not just to automate attacks but to make them deeply convincing,” says Marijus Briedis, chief technology officer at NordVPN.

“With the holiday shopping season in full swing, consumers must remain vigilant against increasingly sophisticated phishing schemes targeting delivery services.”

Rising Losses and Protection Strategies

Text-based delivery scams, known as smishing, are a major driver behind the trend. A NordVPN survey found that 38% of respondents had encountered delivery scams, many of which arrived directly on their phones. Text messages often bypass spam filters and are opened quickly, increasing the chance of impulsive clicks.

NordVPN also said that financial losses linked to these scams continue to climb.

Federal Trade Commission (FTC) data shows consumers lost $470m to text message fraud in 2024, five times more than in 2020.

Fake delivery notifications have become one of the most common and profitable scam formats during the holiday season.

Read more on delivery scams: Phishing Messages and Social Scams Flood Users Ahead of Christmas

Recent messages frequently claim packages are being held due to unpaid tariffs or customs fees. This tactic relies on urgency and fear of missing deliveries to push recipients into clicking harmful links.

NordVPN recommended several precautions to reduce exposure:

  • Avoid clicking tracking links in unsolicited texts or emails

  • Enter tracking numbers directly on official carrier websites or apps

  • Be cautious of messages demanding immediate action or payment

  • Inspect sender details closely for altered domains or subtle misspellings

  • Report suspicious messages to the carrier or the FTC instead of responding

“Becoming a victim of an impersonated fraudulent website isn’t just about losing money,” said Tomas Sinicki, managing director at NordProtect.

“It also exposes you to further risks of fraud and extortion.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleVolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption
Next Article Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector
Team-CWD
  • Website

Related Posts

News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
News

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

February 6, 2026
News

Chinese-Made Malware Kit Targets Chinese-Based Edge Devices

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Can password managers get hacked? Here’s what to know

November 14, 2025

It’s all fun and games until someone gets hacked

September 26, 2025

How the always-on generation can level up their cybersecurity game

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.