Over the last few years, scammers have increasingly relied on phishing emails posing as legitimate notifications from delivery companies like DHL, FedEx, and UPS. One common tactic is to send emails with subject lines like “Incoming Package Notification” or “Shipping Documents” pretending to be from DHL. These fraudulent emails aim to steal sensitive personal and financial information from unsuspecting recipients.
This article will provide an in-depth look at the DHL incoming package notification email scam – how it works, what to do if you receive one, and how to stay safe from this and other phishing attacks. With online shopping and deliveries surging in popularity, it’s important to understand these scams to avoid falling victim.
Overview of the DHL Incoming Package Notification Scam
The DHL incoming package notification scam is a phishing attack where scammers send fake emails pretending to be from the logistics company DHL. The emails claim that the recipient has an incoming package and provide a tracking number. They then direct the victim to a fake DHL website to fill in personal information or download malware.
This scam works because many people are expecting deliveries from DHL and other carriers. Seeing an unsolicited “shipping notification” email appears legitimate at first glance. However, telltale signs like poor spelling/grammar, odd links, and generic greetings like “Dear customer” indicate it’s a scam.
While this scam spoofs DHL specifically, variations target other delivery companies like FedEx and UPS. The PayPal shipping notification scam works similarly. Scammers register lookalike domains and create convincing fake notifications emails.
Objectives of the Scammers
The core objectives of the DHL package notification scam are:
- Phishing for personal information like names, addresses, phone numbers, etc. This can enable identity theft.
- Spreading malware by getting victims to download fake tracking apps or infected document attachments. This gives the scammers access to login credentials, financial information, and other sensitive data.
- Generating fraudulent wire transfers by tricking recipients into paying for non-existent shipping fees, customs charges, etc.
In summary, the scammers aim to steal identities, hijack accounts, drain bank balances, and access confidential information using the fake DHL emails and websites. Staying vigilant is crucial to avoid falling into these traps.
How the DHL Incoming Package Notification Scam Works
Now let’s examine the step-by-step process of how the DHL incoming package notification scam unfolds:
1. Scammers Send Fake Shipping Notification Emails
The scammers begin by sending out mass emails posing as DHL notifications. The subject line often says something like “DHL Delivery” or “DHL Shipping Information.”
The body copy is short and urges the recipient to take action right away. It mentions an incoming package, includes a fake tracking number, and provides a link to check shipping status.
Poor spelling/grammar, unusual links, and generic greetings like “Dear customer” indicate it’s an illegitimate email.
Here is one variant for this email scam:
Subject: Shipping Documents // Arrival Notice // Awb #xxxxxxxx
INCOMING PACKAGE NOTIFICATION
Dear customers,
This is to let you know you have an incoming message
registered package in your email xxxxxxx
Please follow our website below to track your shipment..
Thank you for using Delivery on Demand.
DHL Express – Perfection. Easy delivery
2. Recipients Open Email and Click Links
Many recipients will open the email, especially if they’re expecting a real DHL delivery. Seeing words like “incoming package” and what looks like a tracking number adds legitimacy.
They click on the link provided, which seems to go to the official DHL website but actually takes them to a fake phishing site. The URL may be misspelled or slightly different.
3. Fake DHL Site Asks for Personal Information
On the fake DHL tracking website, victims are prompted to enter details like their name, address, phone number, account passwords, etc. to view delivery status.
An official DHL site would never ask for this info to check a tracking number. But the phishing site claims it’s needed for verification or shipping purposes.
4. Scammers Collect and Use Personal Data
When victims enter their personal info, the scammers capture it. They use these details for identity theft, accessing accounts, or selling on the dark web.
In some cases, the fake site prompts a software download instead, infecting the victim’s device with malware. This allows the scammers to access everything on that device.
5. Fake Site Asks for Money
In addition to stealing personal information, some fake DHL notification emails claim additional money is owed for shipping fees, customs charges, etc.
Victims are instructed to wire the funds quickly or risk delays receiving their “package.” Scammers pocket the money, leaving victims out of pocket.
What to Do If You Get a Fake DHL Email
If you receive an unsolicited DHL notification email, especially with poor grammar/spelling, take these steps:
Look for Red Flags
Closely inspect the email sender, subject line, and content:
- Generic greetings like “Dear customer” instead of your name
- Suspicious links that don’t match DHL’s domain
- Odd spelling/grammar mistakes
- Requests for personal info or money
- Mentions of unexpected incoming packages
These are clear red flags of a scam.
Do Not Click Links or Attachments
Don’t click on any links, download attachments, or enter information on linked sites. They likely take you to phishing sites to steal your data or infect your device with malware.
Check the Sender’s Email Address
Even if the “From” name says DHL, check the sender’s actual email address. Scammers often spoof legitimate business names.
But on closer inspection, the address comes from non-DHL domains. This indicates a fake.
Search Sender/Subject Online
Copy and paste the sender’s email address and the subject line into a search engine. Append terms like “scam” or “fraud.” This can surface warnings if others have reported the same fake message.
Forward to DHL Fraud Email
Forward the phishing email to DHL at abuse@dhl.com. This alerts them to new scam variants using their brand. You can also report phishing emails to the FTC.
Contact Legit DHL If Unsure
If you’re expecting a package and receive a questionable email, contact DHL directly through their official site. Verify if they sent the message and whether you have a delivery incoming.
Never call numbers listed in suspicious emails—they direct to scammers posing as DHL.
Is Your Device Infected? Check for Malware
If your device is running slowly or acting suspicious, it may be infected with malware. Malwarebytes Anti-Malware Free is a great option for scanning your device and detecting potential malware or viruses. The free version can efficiently check for and remove many common infections.
Malwarebytes can run on Windows, Mac, and Android devices. Depending on which operating system is installed on the device you’re trying to run a Malwarebytes scan, please click on the tab below and follow the displayed steps.
Scan your computer with Malwarebytes for Windows to remove malware
Malwarebytes stands out as one of the leading and widely-used anti-malware solutions for Windows, and for good reason. It effectively eradicates various types of malware that other programs often overlook, all at no cost to you. When it comes to disinfecting an infected device, Malwarebytes has consistently been a free and indispensable tool in the battle against malware. We highly recommend it for maintaining a clean and secure system.
Download Malwarebytes for Windows
You can download Malwarebytes by clicking the link below.
MALWAREBYTES FOR WINDOWS DOWNLOAD LINK
(The above link will open a new page from where you can download Malwarebytes)-
Install Malwarebytes
After the download is complete, locate the MBSetup file, typically found in your Downloads folder. Double-click on the MBSetup file to begin the installation of Malwarebytes on your computer. If a User Account Control pop-up appears, click “Yes” to continue the Malwarebytes installation.
Follow the On-Screen Prompts to Install Malwarebytes
When the Malwarebytes installation begins, the setup wizard will guide you through the process.
-
You’ll first be prompted to choose the type of computer you’re installing the program on—select either “Personal Computer” or “Work Computer” as appropriate, then click on Next.
-
Malwarebytes will now begin the installation process on your device.
-
When the Malwarebytes installation is complete, the program will automatically open to the “Welcome to Malwarebytes” screen.
-
On the final screen, simply click on the Open Malwarebytes option to start the program.
-
Enable “Rootkit scanning”.
Malwarebytes Anti-Malware will now start, and you will see the main screen as shown below. To maximize Malwarebytes’ ability to detect malware and unwanted programs, we need to enable rootkit scanning. Click on the “Settings” gear icon located on the left of the screen to access the general settings section.
In the settings menu, enable the “Scan for rootkits” option by clicking the toggle switch until it turns blue.
Now that you have enabled rootkit scanning, click on the “Dashboard” button in the left pane to get back to the main screen.
Perform a Scan with Malwarebytes.
To start a scan, click the Scan button. Malwarebytes will automatically update its antivirus database and begin scanning your computer for malicious programs.
-
Wait for the Malwarebytes scan to complete.
Malwarebytes will now scan your computer for browser hijackers and other malicious programs. This process can take a few minutes, so we suggest you do something else and periodically check the status of the scan to see when it is finished.
-
Quarantine detected malware
Once the Malwarebytes scan is complete, it will display a list of detected malware, adware, and potentially unwanted programs. To effectively remove these threats, click the “Quarantine” button.
Malwarebytes will now delete all of the files and registry keys and add them to the program’s quarantine.
-
Restart your computer.
When removing files, Malwarebytes may require a reboot to fully eliminate some threats. If you see a message indicating that a reboot is needed, please allow it. Once your computer has restarted and you are logged back in, you can continue with the remaining steps.
Your computer should now be free of trojans, adware, browser hijackers, and other malware.
If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future.
If you are still having problems with your computer after completing these instructions, then please follow one of the steps:
- Run a computer scan with ESET Online Scanner
- Ask for help in our Windows Malware Removal Help & Support forum.
Scan your computer with Malwarebytes for Mac to remove malware
Malwarebytes for Mac is an on-demand scanner that can destroy many types of malware that other software tends to miss without costing you absolutely anything. When it comes to cleaning up an infected device, Malwarebytes has always been free, and we recommend it as an essential tool in the fight against malware.
-
Download Malwarebytes for Mac.
You can download Malwarebytes for Mac by clicking the link below.
MALWAREBYTES FOR MAC DOWNLOAD LINK
(The above link will open a new page from where you can download Malwarebytes for Mac) -
Double-click on the Malwarebytes setup file.
When Malwarebytes has finished downloading, double-click on the setup file to install Malwarebytes on your computer. In most cases, downloaded files are saved to the Downloads folder.
-
Follow the on-screen prompts to install Malwarebytes.
When the Malwarebytes installation begins, you will see the Malwarebytes for Mac Installer which will guide you through the installation process. Click “Continue“, then keep following the prompts to continue with the installation process.
When your Malwarebytes installation completes, the program opens to the Welcome to Malwarebytes screen. Click the “Get started” button.
-
Select “Personal Computer” or “Work Computer”.
The Malwarebytes Welcome screen will first ask you what type of computer are you installing this program, click either Personal Computer or Work Computer.
-
Click on “Scan”.
To scan your computer with Malwarebytes, click on the “Scan” button. Malwarebytes for Mac will automatically update the antivirus database and start scanning your computer for malware.
-
Wait for the Malwarebytes scan to complete.
Malwarebytes will scan your computer for adware, browser hijackers, and other malicious programs. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
-
Click on “Quarantine”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes has detected. To remove the malware that Malwarebytes has found, click on the “Quarantine” button.
-
Restart computer.
Malwarebytes will now remove all the malicious files that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your computer.
Your Mac should now be free of adware, browser hijackers, and other malware.
If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future.
If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.
Scan your phone with Malwarebytes for Android to remove malware
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
-
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
MALWAREBYTES FOR ANDROID DOWNLOAD LINK
(The above link will open a new page from where you can download Malwarebytes for Android) -
Install Malwarebytes for Android on your phone.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.
When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
-
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
Tap on “Got it” to proceed to the next step.
Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
Tap on “Allow” to permit Malwarebytes to access the files on your phone. -
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.
Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.
-
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
-
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
-
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
Your phone should now be free of adware, browser hijackers, and other malware.
If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
- Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
- Ask for help in our Mobile Malware Removal Help & Support forum.
Protect Yourself from Future Scams
Here are some tips to avoid falling victim to similar phishing scams impersonating shipping companies:
- Never click links or call numbers in unexpected emails claiming to be from delivery firms. Always contact them directly using official channels to verify.
- Enable two-factor authentication where possible to protect accounts even if passwords are compromised.
- Carefully check email addresses, URLs, grammar, branding, and other details for red flags before interacting with messages.
- Be wary of emails asking you to pay additional shipping fees, customs duties, taxes, etc. Many scammers exploit this trend.
- Hover over links to preview their real destination before clicking. Check for misspellings or non-company URLs.
- Report suspicious emails to companies being spoofed and to anti-fraud agencies like the FTC. This helps curb scam prevalence.
Frequently Asked Questions about the DHL Incoming Package Notification Scam
1. What is the DHL incoming package notification scam?
The DHL incoming package notification scam is a phishing scam where recipients receive fraudulent emails claiming to be from DHL about an incoming package delivery. The emails include fake tracking numbers and direct victims to phishing sites to steal personal information or infect devices with malware.
2. How do I recognize a fake DHL email?
Fake DHL emails have several red flags to watch for:
- Generic greetings like “Dear Customer” instead of your name
- Odd links that don’t match DHL domain names
- Spelling/grammar mistakes
- Requests for personal info or bank details
- Mentions of incoming packages you don’t expect
3. What are the objectives of the DHL package scam?
The objectives are:
- Phishing for personal info to enable identity theft
- Spreading malware by getting victims to download infected files
- Generating fraudulent wire transfers by tricking people to pay fake fees
4. What happens if I click on links in the fake DHL emails?
The links take you to convincing but fake DHL websites to steal your personal information or infect your device with malware. Never click links in suspicious emails claiming to be from DHL.
5. Should I call the number listed in the fake DHL emails?
No, never call the number in emails you suspect are scams. The numbers connect you to scammers impersonating DHL. Only call official DHL numbers listed on their real website.
6. What should I do if I receive a suspicious DHL email?
- Check for red flags indicating a scam
- Verify the sender email address is from DHL
- Search online to see if others flagged the same email
- Forward it to DHL fraud/abuse email
- Report phishing emails to the FTC
7. How can I protect myself from the DHL package scam?
- Never open links or attachments in unexpected shipping emails
- Enable two-factor authentication on accounts
- Carefully inspect emails for phishing red flags
- Don’t pay any fees mentioned in suspicious emails
- Hover over links to check destinations before clicking
- Report phishing emails to help curb scams
8. What should I do if I already entered my information on a fake site?
If you entered any personal information, contact your bank, freeze your credit, change passwords, scan your device for malware, and monitor for signs of identity theft. Acting quickly can limit the damage.
The Bottom Line
The DHL incoming package notification phishing scam is widespread but avoidable if you know the red flags like poor spelling, odd links, generic greetings, and requests for personal information or money. Verify any suspicious delivery emails directly with customer service before acting.
Be cautious of all unsolicited messages claiming to be from shipping companies. Scammers exploit the surge in e-commerce deliveries. But vigilance and awareness of their tactics can keep you safe from fraud. Don’t provide information or open attachments/links in any suspicious emails.