Received a delivery text or unexpected QR code?

Do not click, scan, reply, or pay through the message. Open the retailer or courier’s official app yourself, type the known website into your browser, or use the tracking number from your genuine order confirmation. A small redelivery fee can be bait for stealing card details and passwords.

The message arrives at exactly the right moment.

You ordered medicine, a gift, or something for the house. Then your phone says delivery failed because the address is incomplete. The fee is only $1.79, the logo looks familiar, and the message arrives while you are expecting a parcel.

That is what makes delivery-text scams so effective.

The $1.79 delivery fee that was not really about the fee

Imagine a 73-year-old grandmother named Carol waiting for a prescription and a parcel from her daughter.

At 8:42 in the morning, she receives this text:

“Delivery attempted. Your package is being held because the street number is missing. Update your details and pay the $1.79 redelivery fee today to prevent return.”

Carol taps the link. A convincing delivery page asks for her name, address, telephone number, and card details. The payment fails, and minutes later someone claiming to be from her bank calls with details of the attempted charge.

The caller says criminals are trying to take over her account. To stop them, he asks Carol to read a six-digit verification code.

Fortunately, she remembers the family rule taped beside her phone:

“Unexpected message, unexpected call: stop and verify through a number you already trust.”

Carol ends the call and uses the number on the back of her card. The bank confirms that the delivery page was fraudulent and blocks the card.

This illustrative story reflects official warnings. The small fee may be only the first step; the real target can be card details, passwords, identity information, device access, or a follow-up bank impersonation scam.

What smishing and quishing mean

Smishing is phishing through a text message. Quishing uses a QR code to hide a destination until it is scanned. The code may appear in a message, parcel, car park, poster, invoice, or over a genuine code.

QR codes themselves are not dangerous. They are simply a convenient way to open information. The danger is where the code sends the phone and what the website asks the user to do.

The UK National Cyber Security Centre notes that QR codes in ordinary settings such as restaurants are usually safe, but codes in emails, messages, car parks, stations, and other open spaces deserve more caution. A criminal can use a QR code to disguise a harmful link that might otherwise look suspicious.

Why these scams target older adults

These scams reach every age group. Older adults may feel extra pressure because deliveries can include medicines, groceries, mobility products, and gifts. They may also receive parcels ordered by relatives or be unsure which courier a retailer selected.

Criminals do not need to know that a parcel exists. Mass messages inevitably reach many people who are waiting for something.

The message uses ordinary human reactions:

  • relief that the parcel has been found
  • fear that medicine or an important item will be returned
  • politeness toward an apparent service provider
  • frustration with delivery problems
  • willingness to pay a small amount to solve the issue quickly

The solution is not to stop using deliveries or QR codes. It is to separate every unexpected message from the genuine account or service it claims to represent.

Six common QR code and delivery-text scams

1. The missed-delivery or incomplete-address text

The message says the parcel needs an address update, new delivery time, or postage payment. The Postal Inspection Service says unsolicited USPS tracking messages with unfamiliar links are smishing; USPS tracking is initiated by the customer and basic tracking is free.

2. The tiny redelivery fee

A charge of $1, £1, or a similarly small amount lowers suspicion. The criminal may collect the card number, security code, billing address, telephone number, and name. The card can then be used for larger transactions or linked to another scam.

The fee may fail deliberately so a fake bank representative can call and claim the card is under attack.

3. The unexpected parcel with a QR code

An unordered package may include a card asking you to scan a code to identify the sender, register a warranty, or arrange a return. The FTC and Postal Inspection Service warn that this may lead to a fake site stealing passwords or payment details.

4. The QR code covering a genuine code

A criminal can place a sticker over a genuine parking, payment, menu, or information code. Look for peeling edges, mismatched colours, poor alignment, or an obvious overlay.

5. The “download our delivery app” message

The text says an app is required for tracking. A website download may install malware capable of accessing personal information and banking details.

6. The delivery scam that becomes a bank call

After the victim enters card information, a caller claims to be from the bank. The caller may know enough recent details to sound genuine and may ask for a verification code, remote access, or a transfer to a “safe account.”

Review what banks will never ask you to share by phone. A genuine fraud team does not need the victim to read out a one-time code or move money because of an incoming call.

Eight warning signs of QR code and delivery-text scams

1. The message was unexpected

A genuine delivery update normally connects to an order you recognise. An unexpected text should not become trustworthy simply because you happen to be waiting for another parcel.

2. It demands immediate action

The package will supposedly be destroyed, returned, charged storage fees, or permanently lost unless you act today. Urgency is intended to prevent independent checking.

3. The link or sender looks unusual

The message may use an international number, ordinary mobile number, or a domain with extra letters, hyphens, misspellings, or an unfamiliar ending. A convincing address is not proof.

4. A small fee is required

The amount feels harmless, but the request for card information matters more than the fee.

5. The message asks for information the courier should already have

Be cautious when a supposed delivery company needs the full name, complete address, date of birth, card details, account password, Social Security number, or National Insurance number to deliver an ordinary parcel.

6. The QR code creates pressure before showing the destination

The code is presented as the only way to prevent a penalty or recover a package. It hides the destination until the camera reads it.

7. The website requests a login or app download

A delivery page should not require access to email, banking, Apple, Google, or social-media accounts. Do not install an app from a link or QR code in an unexpected message.

8. A follow-up caller claims to fix the problem

The caller may mention the exact small payment and say the card is compromised. That knowledge may have come from the fake delivery page. End the call and contact the bank independently.

Family rule: No unexpected delivery text, QR code, or parcel notice is used to make a payment or sign in. Open the genuine retailer or courier account separately.

Real delivery updates compared with scams

Situation Safer, genuine pattern Scam warning
Order Matches a purchase in your genuine account Vague “package waiting” message with no recognised order
Tracking You enter the number in an official app or website The text insists that its link is the only tracking route
Address problem The issue is visible in the genuine retailer or courier account The site requests extensive identity and card information
Payment Any legitimate charge is confirmed through an official channel A tiny urgent fee must be paid through the message
QR code The purpose and destination fit the physical setting Unexpected code, sticker overlay, urgent threat, or login request
Follow-up You contact the organisation using verified details A caller asks for codes, remote access, or a money transfer

How to verify a parcel safely

  1. Do not use the message. Do not click its link, call its number, or reply.
  2. Open the retailer’s official app or website yourself. Check the order history and delivery status.
  3. Use the genuine tracking number. Copy it from the original order confirmation, not the suspicious message.
  4. Contact the courier independently. Use a saved number, printed receipt, official app, or website typed directly into the browser.
  5. Ask the sender. A family member who sent a gift can confirm it through a separate conversation.
  6. Allow the parcel to wait. A real delivery problem can survive a few minutes of verification.

“I do not pay delivery charges through unexpected texts. I will check the order in the official app.”

This rule avoids judging whether every logo or web address looks perfect.

How to scan QR codes more safely

  • Use the camera or QR scanner built into the phone rather than downloading an unknown scanner app.
  • Look at the link preview before opening it.
  • Do not continue if the address is misspelled, shortened, unrelated to the situation, or unfamiliar.
  • Inspect physical codes for stickers or signs of replacement.
  • Do not scan unexpected codes received by text, email, post, or inside an unordered parcel.
  • Never use a QR code to enter banking credentials or approve an urgent payment unless you independently verified the process.
  • When possible, open the organisation’s official app instead.

Europol recommends checking whether the link preview looks suspicious or out of place. ENISA identifies quishing as a modern form of phishing.

A family protection plan for older adults

Preserve independence by building a safer route rather than discouraging online ordering.

Set up one delivery folder in email and one trusted note containing:

  • the main retailers used by the household
  • official courier apps or bookmarked websites
  • the bank’s number from the card
  • one trusted family contact
  • a reminder never to pay through an unexpected message

Turn on spam filtering and junk reporting. In the US and UK, suspicious texts can generally be forwarded to 7726. Enlarge display settings when reduced vision makes link previews difficult to read.

For mild memory difficulties, place this card near the phone:

DELIVERY TEXT?

Do not click or pay. Open the shop or courier app yourself. Call ____________________ when unsure.

Older adults living alone should have two trusted contacts. Cross-border families can keep a shared list of genuine gifts and deliveries.

The same family habit helps with fake technical support calls, bank impersonation, and AI emergency scams: stop the first contact and verify through a route chosen before the pressure begins.

What to do after clicking, scanning, or paying

You clicked or scanned but entered nothing

Close the page. Do not download anything or approve permissions. Update the phone and browser, run security checks, and watch for follow-up contact.

The Postal Inspection Service advises people who interacted with a suspicious USPS-related URL to notify their financial institution, even when they did not press the final submit button.

You entered a password

From a trusted device, change the password immediately and update any account using the same password. Turn on two-factor authentication and review active sessions and recovery details.

You entered card or bank information

Contact the bank or card issuer using the number on the card or official app. Ask it to block or replace the card, monitor transactions, and explain whether additional account protection is required.

Do not trust a caller who contacts you after the payment. End the call and reconnect with the bank independently.

You installed an app

Disconnect the device from the internet and do not use it for banking. Contact a trusted technician through an official route, especially if the app gained accessibility, administrator, screen-sharing, or financial permissions.

Read the recovery steps in the guide to recognising fake technical support calls if anyone obtained remote access.

You sent money

Contact the payment provider immediately and ask whether the transaction can be stopped, recalled, frozen, disputed, or traced. Preserve the message, sender number, QR code, web address, receipts, and screenshots.

In the United States, report scam texts through the phone’s junk-reporting feature or forward them to 7726. USPS-related smishing and quishing can be reported to the Postal Inspection Service. Report fraud to the FTC and internet-enabled crime to IC3.

In the United Kingdom, Ofcom advises forwarding suspicious texts to 7726. Report financial loss to Report Fraud; in Scotland, use Police Scotland’s reporting route.

In Europe, report the incident to the national police or cybercrime service and contact the relevant bank or payment provider. Europol and ENISA recommend using official websites and apps instead of links supplied in unexpected messages.

Quick QR code and delivery-text scam checklist

  • Was the message or parcel unexpected?
  • Does it create a deadline or threat of return, storage charges, court action, or loss?
  • Does it require a small payment through the message?
  • Is the sender number or web address unfamiliar?
  • Does the page request more information than a courier should need?
  • Is a QR code the only route offered?
  • Does the physical code look like a sticker placed over another code?
  • Are you asked to download an app outside the official app store?
  • Does a follow-up caller request a verification code or bank transfer?
  • Can the delivery be confirmed inside the genuine retailer or courier account?

One unusual detail may have an innocent explanation. Several warning signs appearing together should stop the interaction.

Frequently asked questions

Are all delivery texts scams?

No. Retailers and couriers send genuine updates. The safer approach is to avoid acting through an unexpected message and verify the delivery inside the genuine retailer or courier account.

Why do scammers ask for such a small redelivery fee?

A small amount reduces suspicion. The main goal may be collecting the card number, security code, billing address, telephone number, or other information for a larger fraud.

Is it dangerous simply to scan a QR code?

Scanning usually displays or opens a link. The greater risk comes from opening a malicious destination, entering information, downloading software, or granting permissions. Check the preview before continuing.

What if I really am expecting a parcel?

Open the retailer’s order history or the courier’s official app. Use the tracking number from the original purchase confirmation. Do not use the link in the unexpected text.

Should I reply STOP to a suspicious delivery text?

No. Ofcom advises not replying to messages from unknown senders because a reply can confirm that the number is active. Use the phone’s report-junk feature or forward the message to 7726.

Can a fake delivery text lead to a bank impersonation call?

Yes. Card and contact details entered on the fake page can make the follow-up caller sound convincing. End the call and contact the bank using the number on the card or official app.

The parcel can wait while you verify

Delivery-text scams targeting older adults work because the story is ordinary.

People really do miss parcels, addresses can be incomplete, and QR codes are widely used.

The safest habit is not to decide whether the message looks perfect. It is to refuse its route.

Do not click the delivery link.

Do not scan the unexpected code.

Do not pay the small fee through the message.

Open the official account yourself and check.

A genuine parcel can wait while you verify it. A scam depends on convincing you that it cannot.

Build the Complete Family Protection Plan

My full-color guide, Protect Aging Parents from AI Voice Clones, Fake Bank Calls and Online Scams, includes realistic scenarios, ready-to-use scripts, checklists, emergency-response pages, and a practical 7-Day Family Protection Plan.

View the Family Guide

About the author

Michael Onoja is a Microsoft MVP, technology leader, software engineer, researcher, and published author. He writes about AI safety, digital trust, cybersecurity, and practical ways families can protect one another from emerging online threats.

Review how to protect aging parents from AI voice scams, learn what banks will never ask by phone, or read how investment scams target retirees.

This article provides general educational information and is not legal, financial, technical, medical, postal, or law-enforcement advice. Reporting services, delivery procedures, and technology settings can change. Verify important information through official organisations.

Tags: