A message says a parcel could not be delivered. It asks you to reply with one character, reopen the message, and pay a tiny redelivery charge.
The courier delivery iMessage scam feels like a routine delivery problem. That is exactly why this campaign has been so effective.

Overview
The message arrives through iMessage, not ordinary SMS
The courier delivery iMessage scam begins with an unsolicited message from a foreign telephone number or a random-looking email address. It claims that a package is waiting, an address is incomplete, or a delivery attempt failed.
The message often looks more polished than the old misspelled parcel texts. It may show a delivery number, a believable deadline, and the name of a courier that operates in the recipient’s area. None of those details proves that a real parcel exists.
A particularly important clue is the instruction to reply with “Y,” “1,” or another character. The reply is not harmless confirmation. It changes how the conversation is treated and helps the criminal move the recipient toward a live phishing link.
A small fee hides a much larger theft
The page reached from the message asks for a modest redelivery or address-correction fee. Because the charge is so small, many people enter a card without giving the site the same scrutiny they would give a large purchase.
The amount on the page is a pretext. The valuable information is the card number, expiration date, security code, bank login, and one-time password entered during “verification.” That data can authorize transactions far beyond the displayed fee.
In some cases, the stolen information is used to add the card to a mobile wallet or provision a bank token on an unfamiliar device. The victim may not notice until larger unauthorized payments appear.
This is a documented mass phishing campaign
This is not a complaint about a slow courier. In an August 2026 advisory, the Singapore Police Force said more than 30,000 iMessage accounts linked to the wider campaign had been detected and disrupted since June.
Police estimated that messages impersonating courier companies had caused about $2.2 million in losses. The warning described foreign numbers, random email IDs, lookalike delivery sites, small payment requests, stolen credentials, and unauthorized transactions.
Common warning signs include:
- an unexpected delivery problem arrives through iMessage;
- the sender is a foreign number or an unrelated email address;
- you must reply before the link becomes usable;
- the URL resembles a courier domain but is not an exact match;
- a small redelivery fee requires full card or bank credentials;
- the page asks for a one-time password to “confirm” the fee;
- the message threatens return, disposal, or extra charges within hours;
- the parcel cannot be found in the courier’s official app or site.
Why Replying to the Message Matters
Many recipients assume the single-letter reply is an unusual but harmless delivery instruction. It is actually part of the scam’s design. A link from an unknown iMessage sender may not initially behave like a normal clickable link.
Police said scammers use the reply request to work around that friction. Once the recipient interacts with the sender, the embedded address can become clickable. The criminal has turned a safety warning into a fake verification step.
The reply also tells the sender that the account is active and that someone is reading. That can invite follow-up messages, calls, or new phishing attempts tailored to the delivery story.
A real courier does not need you to change a messaging safety state before you can manage a parcel. If a shipment is genuine, its tracking number should work after you independently open the courier’s official app or type its known website address.
Do not copy the message’s number into a search engine and assume the first result is safe. Search advertisements can lead to more impersonation pages. Use an app already installed or a bookmarked site when possible.

How the Courier Delivery iMessage Scam Works
Step 1: Criminals send parcel notices at enormous scale
The scammers do not need to know whether every recipient is expecting a package. Online shopping makes the claim statistically useful. Enough people have a delivery in progress that a generic warning will feel personal.
Sender accounts can use overseas telephone numbers or email addresses filled with random characters. The visible text borrows familiar courier language, while a generated tracking reference adds an appearance of specificity.
Step 2: The message creates a believable delivery problem
The supposed issue may be an incomplete street number, failed signature, unpaid customs charge, damaged label, or full pickup locker. Each version gives the recipient a reason to act before the package is allegedly returned.
The deadline is usually short. That pressure discourages the recipient from checking a purchase confirmation, opening the official tracking service, or asking another household member whether a parcel is expected.
Step 3: A reply activates the next part of the trap
The message tells the recipient to send “Y” or “1,” close the conversation, and open it again. The instruction sounds like a technical requirement from the courier, but it serves the attacker’s delivery method.
Once the recipient has interacted, the phishing link can be easier to open. The scammer also receives a strong signal that this address belongs to a responsive target.
Step 4: A lookalike site displays the invented parcel
The link opens a page styled like a delivery portal. It may show a logo, tracking timeline, depot location, or partial address. These elements are page decoration and can be copied in minutes.
The domain is the more useful evidence. Added words, substituted letters, unusual endings, or unrelated subdomains reveal that the site is not controlled by the company it imitates.
Step 5: The site asks for a token payment
A fee such as $1.99 or $2.45 feels too small to be dangerous. The form nevertheless requests every card field needed for online use, sometimes followed by online banking credentials.
The screen may say the first attempt failed and ask the victim to try another card. That lets the criminals collect several payment methods from one person.
Step 6: The one-time code approves something else
A bank code arrives while the fake page displays a loading animation. The page labels it as confirmation for the tiny charge, but the underlying request may involve a larger payment, digital wallet enrollment, or a new trusted device.
Read the bank’s real code message carefully. The merchant, amount, device, and action described there matter more than the explanation shown on the courier page.
Step 7: Unauthorized transactions reveal the theft
The fake site may show a delivery confirmation and tell the victim to wait. Meanwhile, the criminals test the card, access the bank account, or transfer funds through a newly provisioned wallet.
Victims often discover the truth through a bank alert rather than a courier update. By that point, the parcel story has done its job and the phishing domain may already be replaced.
The Tiny Fee Is a Security Test, Not a Purchase
A genuine low-value charge can still require authentication, but a criminal uses the small amount to lower resistance. The victim focuses on whether the fee seems reasonable instead of whether the website is authorized to collect it.
Some pages intentionally trigger several prompts. A rejected card is presented as a technical error, and the visitor is encouraged to enter another. The goal is not to complete delivery; it is to expand the set of stolen credentials.
The most dangerous prompt may arrive outside the page. A push notification can ask whether to add a card to a mobile wallet, approve a new device, or authorize a transfer. Never approve it merely because the timing matches the fake fee.
A real courier can explain a charge through a verified account and provide a normal invoice. It will not need your bank password, full digital token setup, or an unexplained mobile-wallet enrollment to collect a minor delivery fee.
Company, Address, and Fulfillment Checks
The tracking number must work independently
Open the courier’s known website or app without using the message. Enter the tracking number there. A graphic timeline on the linked page is not evidence because the scammer controls every status displayed.
If you ordered from a retailer, check the order page as well. The retailer should identify the actual carrier and provide the same tracking reference.
The sender does not establish the courier’s identity
A familiar company name inside the message is easy to type. Expand the sender details and examine whether the telephone country code or email domain has any legitimate connection to that courier.
Even a locally formatted number can be spoofed or obtained for a campaign. Verification must happen through a channel you choose, not by replying to the same conversation.
The payment domain must exactly match
Preview the destination before opening it. Look beyond the first familiar word. A courier name followed by extra terms, a different domain ending, or a long unrelated hostname is not the official site.
A padlock only means the connection is encrypted. Criminal phishing pages routinely use HTTPS, so the padlock does not verify the company behind the form.
A real redelivery should appear in the account
If a delivery can be rescheduled, that option should appear after signing in through the official service. The address, shipment, sender, and available dates should agree with the original order.
Do not accept a confirmation page inside the suspicious site as fulfillment. Check the real tracking record for a saved change or call the courier using a published number.
What to Do if You Have Fallen Victim to This Scam
- Call the card issuer or bank immediately. Use the number on the card or inside the official banking app. Explain that credentials were entered on a courier phishing page.
- Freeze and replace the exposed card. Ask whether it was added to a mobile wallet or another device, and request removal of any enrollment you do not recognize.
- Review pending and completed transactions. Dispute unauthorized activity and keep the case number. Continue checking because criminals may wait before using stolen details.
- Secure online banking. Change the password from a trusted device, revoke unfamiliar sessions, remove unknown payees, and lower transfer limits while the bank investigates.
- Tell the bank about any code you entered. The code may have approved a wallet, device, or transfer rather than the displayed fee. The exact text of the bank message can help identify the action.
- Change reused passwords. If the fake page collected an email or account password, replace it everywhere it was reused and enable multifactor authentication.
- Report the message in the app. Apple explains how to report junk and filter unknown senders. Reporting does not automatically block the sender, so block it separately.
- Report the fraud. US victims can use ReportFraud.ftc.gov and IC3.gov. Also report the impersonation to the real courier and local authorities.
- Preserve evidence. Save the full message, sender details, link, page screenshots, transaction alerts, and bank correspondence before deleting anything.
- Check the device if a file or profile was installed. Run a Malwarebytes scan and remove unknown configuration profiles or apps. A scan cannot cancel stolen credentials, so complete the bank steps too.
- Use protection as a second layer. AdGuard can block many known phishing and malicious advertising domains, but it cannot make an unverified delivery link safe or reverse a payment.
- Ignore recovery callers. Anyone demanding a fee, crypto payment, or remote access to recover the money may be running a second scam.
Frequently Asked Questions
Why does the message ask me to reply with Y or 1?
The interaction can make a link from an unknown iMessage sender clickable and signals that your account is active. A real courier should not require this workaround.
What if I really am waiting for a package?
Open the retailer order page or the courier’s official app independently. Match the carrier and tracking number there without using the message link.
Is a $1.99 redelivery fee safe to pay?
The amount does not make the form safe. The page may use the fee to steal card details, banking credentials, and authentication codes for a much larger action.
Does the blue iMessage bubble prove the sender is real?
No. It only indicates the route used to send the message. Criminals can operate iMessage accounts with foreign numbers or email addresses.
Can reporting the message protect my card?
Reporting helps platforms identify abuse, but it does not secure a card already entered. Contact the issuer and replace the card immediately.
Can the courier recover money stolen by the fake site?
The impersonated courier usually never received the payment. Recovery must be pursued quickly through the bank, card issuer, payment service, and law enforcement.
The Bottom Line
The courier delivery iMessage scam turns an ordinary parcel delay into a route around messaging safeguards and into a convincing payment form. The small fee is bait; the card, bank login, and one-time code are the real targets.
Do not reply, do not use the embedded link, and do not judge the page by its logo. Verify every delivery inside the courier’s official app or website, reached on your own.