Beware the USPS Text Scam
FRUAD
Your phone pings with an incoming text. You swipe it open to find a message from the USPS. They’re texting to let you know that the scheduled delivery time for your package has been changed. Unfortunately, though, the message is not from the USPS and you’ve just been targeted.
How the scam plays out
In the USPS “smishing” (SMS phishing scam) ruse, a target will receive a text message like the one described above. The message prompts the victim to click on a link to reschedule the delivery. However, if the victim follows the instructions, they’ll be falling victim to a text scam.
The United States Postal Inspection Service (USPIS) is warning of an uptick in smishing scams that use the USPS as a cover, tricking unsuspecting individuals into downloading malware onto their phones or sharing personal information with scammers who they assume is the USPS. The scammer will then go on to empty the victim’s accounts or steal their identity.
People who’ve recently made online purchases and are expecting a package delivery within the next few days are especially vulnerable to this scam. To most, the text looks legitimate, and with just one careless click, the fraudster has access to the victim’s device and personal information.
However, with one crucial bit of information, you can protect yourself from one of these USPS smishing scams: The USPS never sends out unsolicited text messages about a package. The company will only send a message when a consumer has signed up for alerts about a package’s delivery. If you have not signed up for messages from the USPS, and you receive a text like the one described above, you know you’re being targeted.
What to do if you receive one of these texts
If you’re sent a smishing text scam, the USPIS recommends taking the following steps:
- Verify the sender. Confirm the identity of the message sender by checking to see if you actually have a delivery schedule change with the USPS. Don’t call the number that sent the text. Instead, check your original purchase receipt for tracking information or reach out to your local USPS office directly.
- Don’t reply or click on links. Replying to the message or downloading an embedded link can install malware onto your phone.
- Save a screenshot of the text to share with law enforcement agencies and then delete the message.
- Block the number and update the security on your device. Prevent a recurrence of the notification by putting the number on your “Do Not Call” list and beefing up the security settings on your phone.
- Keep personal information personal. Never share sensitive information, like your Social Security Number or financial account details, with an unverified contact.
Report the scam
Do your part to stop fraud from happening by reporting it to the proper authorities.
First, you can report smishing scams that impersonate the USPS to the Inspection Service Cybercrime Team at the USPIS by email. Take a screenshot of the text and send it to spam@uspis.gov. Make sure your screenshot shows the number of the sender as well as the date it was sent. You’ll also need to include your name in the email so the team can reach you, along with any other relevant details about the scam, such as money you may have lost, links you may have downloaded, and personal information you may have shared. The USPIS will contact you if it needs any additional information to help nab the scammers.
You can also report it to the Federal Trade Commission at FTC.gov and let your friends and family know about the circulating scam.
Stay alert and stay safe!