FedEx Shipment Scheduled Email Scam: Fake Shipping Documents Login Trap

A shipment is apparently on its way, and a FedEx email offers the documents you need to follow it. The notification arrives looking pleasantly routine.

Before opening those documents, check how the message connects to an order you recognize. The next screen may matter more than the delivery update itself.

Illustrative FedEx shipment scheduled email with a shipping documents button

Overview

A Delivery Notice That Leads to a Document

The FedEx Shipment Scheduled for Delivery email scam begins with a familiar promise: a package is moving through a courier network and tracking information is available.

The documented notice describes an express service and presents a button for tracking and viewing shipping documents. Its subject says the shipment is in transit.

Following that button reportedly opens an imitation spreadsheet-sharing page. An Office-style prompt then requests credentials for the recipient’s email account.

That is not simply an unusual tracking layout. A shipping update has become a request to disclose the secret protecting a separate mailbox.

The Details That Distinguish This Version

This particular lure is about supposed shipping documents, not an established customs bill or a confirmed failed delivery. Keep that distinction when deciding what to check.

  • The email says a shipment has been scheduled.
  • Its status is described as in transit.
  • A combined tracking-and-documents button supplies the next action.
  • The destination imitates a shared Excel-style document.
  • An Office-like sign-in prompt asks for email credentials.

The reported destination is mail33.nostagra[.]top. That address is a sample indicator, not a complete description of every future copy of the message.

The visual examples here use fictional addresses to show the email and document detour. They are not original records of a customer’s shipment.

The Real Risk Is the Login Request

FedEx and Microsoft are legitimate companies whose identities are borrowed in the reported scam. Their names do not authenticate a page operated at an unrelated destination.

The available evidence concerns credential collection. It does not establish that this sample installs malware, creates a subscription, or charges a delivery fee.

A mailbox password can be valuable because email holds conversations and account-recovery messages. Exposure can therefore matter even when the supposed package never existed.

Receiving the notification alone does not demonstrate compromise. Your response should depend on whether you visited the page, entered information, approved access, or accepted a download.

How the FedEx Shipping Documents Scam Works

Step 1: An Ordinary Delivery Update Supplies the Hook

The message does not need to open with a dramatic threat. A parcel update is useful information, especially if you regularly receive online purchases or business deliveries.

That ordinary setting gives the sender an advantage. You may expect to click tracking links and may not remember which carrier every seller uses.

An unfamiliar shipment can also seem plausible if someone else in the household ordered it. Curiosity fills the gap that a recognizable order should have filled.

Instead of guessing, return to your purchase history or ask the expected sender. Establish the shipment first, before investigating through the email’s chosen route.

Step 2: Basic Status Information Makes the Notice Look Complete

A service label and transit status give the notification the shape of a normal courier email. They are easy to scan and require little interpretation.

However, those labels are simply text written by the sender. They do not show that a carrier scanned a parcel or scheduled a delivery.

A recipient address printed in the message is not authentication either. Anyone sending an email already knows where that particular message is going.

The useful comparison is with an independent order record. A status that cannot be connected to a real purchase should not justify submitting account credentials.

Step 3: Tracking and Documents Are Bundled into One Button

The invitation to view shipping documents provides a reason for leaving ordinary tracking. A document can sound relevant to an invoice, delivery instruction, or commercial shipment.

Bundling the two actions makes the transition easier to overlook. You clicked for a status update, but a protected file now seems like part of that task.

A seller might legitimately share documents through another service. That possibility should be confirmed with the seller, not assumed because the email uses shipping language.

Ask whether you expected a document at all. Package tracking and access to a shared spreadsheet are separate activities, even when presented under the same button.

Illustrative shared spreadsheet page with an Office-style sign-in prompt

Step 4: A Familiar Spreadsheet Screen Explains the Interruption

The described destination resembles an online Excel document with an Office-style login dialog. This gives the password request a familiar visual setting.

The appearance suggests the documents are already present, just hidden behind authentication. It encourages the reader to finish signing in rather than question the route.

Yet a spreadsheet grid is not proof that Microsoft hosts the page. Logos, menus, and login boxes can be reproduced as ordinary website content.

The real address bar and expected account workflow matter more. Stop if the supposed document service cannot be connected to a verified sender and legitimate sign-in destination.

Step 5: The Reader Submits Mailbox Credentials

The form’s purpose is to collect the email login entered into it. A counterfeit page can receive that information without ever opening a genuine shipping document.

An error or repeated request does not make the first submission safe. Do not try several passwords to discover which one the page wants.

If you supplied a password used only for another service, secure that service. If it was your mailbox password, prioritize the mailbox and any accounts sharing it.

The documented sample does not establish a particular method for stealing authentication sessions. Do not assume either that every protection fails or that one protection removes all risk.

Step 6: The Stolen Login May Be Used Beyond Shipping

Successful mailbox access may expose private correspondence, purchase records, and reset emails. An intruder might also send requests from an address your contacts already trust.

For a business, shipping conversations can contain customer details and payment discussions. Their contents may help someone construct a more targeted follow-up message.

These are possible consequences, not proof of what happened to every recipient. Actual sign-in records and account changes should guide the investigation.

The practical priority is to prevent access from continuing. A fictional parcel should not distract from a real password exposure.

How to Check the Shipment and the Sender

Match the Notice to an Actual Order

Open the retailer account or purchase confirmation you already trust. Find the carrier and tracking details there instead of taking them from the questionable notification.

If another person arranged the delivery, contact that person through an existing conversation. Ask which carrier they used and whether they sent any documents.

A missing match does not prove every unexpected parcel is fraudulent. It does mean the email has not supplied enough context to justify a sensitive login.

Track Through the Carrier’s Established Route

Use the official FedEx application or navigate independently to its tracking service. Enter a tracking number obtained from a trustworthy order record.

Basic tracking should not require handing your personal email password to an unrelated document page. A legitimate courier account, if needed, is a separate account.

Be careful with search advertisements offering delivery support. Use the carrier’s known website rather than calling the first number appearing beside a shipment-related search.

Inspect the Destination Before Any Sign-In

Where your mail client supports it, inspect the button’s address without opening it. A shipping label on the button does not identify the website behind it.

A padlock indicates an encrypted connection, not approval by FedEx or Microsoft. A malicious page can have encryption while still collecting information dishonestly.

If the destination is unfamiliar, do not visit it merely to see whether the logo looks right. Preserve the address for reporting and verify the shipment elsewhere.

Illustrative expanded shipment-email details showing an unrelated document destination

Keep Carrier, Seller, and Document Service Separate

The retailer knows what you bought. The carrier knows its delivery records. A document service controls a separate sharing and authentication process.

A genuine relationship among them should be explainable. The scam relies on the reader assuming that a recognizable name automatically vouches for the next screen.

Ask the appropriate party a specific question. Confirming an order with a seller does not automatically validate an unrelated page asking for your mailbox password.

What to Do If You Fell Victim to the FedEx Shipping Documents Email Scam

Start with your interaction, not the package story. You can take useful action without assuming that a charge, infection, or account takeover has already occurred.

  1. Stop the document workflow.

    Close the suspicious tab and avoid trying another account. Save the original email and note whether you entered credentials or approved anything.

    If you only read the message, report it as phishing. You do not need to complete its tracking instructions to protect a real shipment.

  2. Replace the password you disclosed.

    Reach the affected service from a trusted device through its normal sign-in route. Choose a unique replacement and change reused copies on other accounts.

    Be precise about the account involved. Entering a mailbox password requires email recovery, even though the original message appeared to concern FedEx.

  3. Review access that could remain active.

    Check recent security events, signed-in devices, recovery information, and authentication methods. End unfamiliar sessions using the provider’s available controls.

    For managed accounts, ask IT to revoke access where necessary. Do not assume a password change automatically removes every session or separately granted permission.

  4. Look for changes inside the mailbox.

    Inspect forwarding, filters, delegates, connected applications, and sent messages. Unexpected rules can redirect correspondence or hide replies from the account owner.

    Preserve suspicious evidence before changing it if your organization requires an investigation. Ask an administrator about unfamiliar integrations rather than deleting legitimate business tools blindly.

  5. Handle downloads as a separate exposure.

    If a file downloaded, do not open it to find out what it contains. If you already ran it, involve support and scan the device.

    Malwarebytes can help detect malicious software. A clean scan cannot retrieve a password already submitted to a website, so account-security work still matters.

  6. Reduce opportunities for another misleading redirect.

    Keep browser protections and updates enabled. AdGuard may filter some malicious pages and advertisements, depending on configuration, but it cannot guarantee every phishing destination is blocked.

    Remove any notification permission you granted to the suspicious site. A later browser alert is not automatically a message from FedEx or your installed security software.

  7. Report the impersonation and any actual losses.

    Use FedEx’s verified fraud-reporting route and your mail provider’s phishing option. Forwarding the original message preserves more useful information than copying its visible text alone.

    If you paid during a related interaction, contact the payment provider promptly. Describe the real transaction and preserve receipts rather than treating the email as proof of payment.

Is Your Device Infected? Run a Free Malware Scan

Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Anti-Malware Free — one of the most trusted malware removal tools available.

The free version detects and removes the most common threats, including:

  • Adware — the cause of those annoying pop-ups
  • Browser hijackers — unwanted redirects and changed homepages
  • Trojans and spyware — hidden programs stealing your data
  • Potentially unwanted programs (PUPs) — software you never asked for

👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The whole process takes about 5 minutes.

Malwarebytes for WindowsMalwarebytes for MacMalwarebytes for Android

Run a Malware Scan with Malwarebytes for Windows

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

When the scan finishes, click Quarantine to remove everything Malwarebytes found. That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.

If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future.
If you are still having problems with your computer after completing these instructions, then please follow one of the steps:

Run a Malware Scan with Malwarebytes for Mac

Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.

  1. Download Malwarebytes for Mac

    Click the button below to download the latest version of Malwarebytes for Mac.

    DOWNLOAD MALWAREBYTES FOR MAC (FREE)
    (The link opens in a new page where your download will start)
  2. Open the Malwarebytes setup file

    When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.

    Double-click on setup file to install Malwarebytes

  3. Follow the On-Screen Prompts to Install Malwarebytes

    The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.

    Click Continue to install Malwarebytes for Mac

    Click again on Continue to install Malwarebytes for Mac

    Click Install to install Malwarebytes on Mac

    When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.

  4. Select “Personal Computer” or “Work Computer”

    Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.
    Select Personal Computer or Work Computer mac

  5. Start the Scan

    Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.
    Click on Scan button to start a system scan Mac

  6. Wait for the Scan to Finish

    Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.
    Wait for Malwarebytes for Mac to scan for malware

  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.
    Review the malicious programs and click on Quarantine to remove malware

  8. Restart Your Mac

    Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.
    Malwarebytes For Mac requesting to restart computer

Once the scan is done, remove every threat it detected. Your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.

If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future.
If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.

Run a Malware Scan with Malwarebytes for Android

Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.

  1. Download Malwarebytes for Android.

    You can download Malwarebytes for Android by clicking the link below.

    MALWAREBYTES FOR ANDROID DOWNLOAD LINK
    (The above link will open a new page from where you can download Malwarebytes for Android)
  2. Install Malwarebytes for Android on your phone.

    In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

    Tap Install to install Malwarebytes for Android

    When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
    Malwarebytes for Android - Open App

  3. Follow the on-screen prompts to complete the setup process

    When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
    This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
    Malwarebytes Setup Screen 1
    Tap on “Got it” to proceed to the next step.
    Malwarebytes Setup Screen 2
    Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
    Malwarebytes Setup Screen 3
    Tap on “Allow” to permit Malwarebytes to access the files on your phone.
    Malwarebytes Setup Screen 4

  4. Update database and run a scan with Malwarebytes for Android

    You will now be prompted to update the Malwarebytes database and run a full system scan.

    Malwarebytes fix issue

    Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

    Update database and run Malwarebytes scan on phone

  5. Wait for the Malwarebytes scan to complete.

    Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Malwarebytes scanning Android for Vmalware

  6. Click on “Remove Selected”.

    When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
    Remove malware from your phone

  7. Restart your phone.

    Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.


After the scan, tap Remove Selected to delete all detected threats. Your Android phone is now clean — no more malicious apps, adware, or browser redirects.

If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:

Stay Protected: Block Ads and Malicious Sites

Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.

We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.

👉 Download AdGuard and browse safely

Keep a Genuine Delivery Problem Separate

You might have a real parcel in transit while receiving this fake notice. That coincidence is common enough that it should not settle the question of authenticity.

Similarly, a delayed package does not prove the suspicious document contains its missing details. Continue delivery support through the retailer or carrier’s verified records.

If the email includes information that genuinely matches an order, tell the relevant business. Accurate details deserve investigation, but do not authorize an unrelated login form.

For workplace deliveries, notify the team responsible for purchasing or receiving. They can confirm whether the document was expected and warn colleagues about matching messages.

Record when the email arrived and when you acted. That timeline helps separate the phishing attempt from any later account alerts or actual shipment updates.

Frequently Asked Questions

Is Every FedEx Shipment Email Fake?

No. FedEx sends legitimate delivery communications. This warning concerns the shipment-scheduled lure that redirects to an unrelated document page asking for email credentials.

Verify the order and tracking through an independent route rather than rejecting or trusting every email based on the brand alone.

Why Would Shipping Information Open an Excel-Style Page?

The document design gives the credential request a plausible setting. In this reported campaign, it is part of the phishing route, not authenticated package tracking.

If a real business intended to share a spreadsheet, confirm that request and its access process directly with the sender.

Does a Correct Email Address Make the Notice Genuine?

No. The sender already needed your address to deliver the email. Printing it in a shipment table does not establish knowledge of a real parcel.

Look for a verifiable relationship with an actual order, not merely personalization.

What If I Clicked but Did Not Enter Anything?

Close the page and check whether you downloaded a file or granted permissions. A click alone does not establish that your password was stolen.

Report the message and continue any genuine tracking through the carrier. Respond separately if the interaction involved additional actions.

Should I Cancel My FedEx Account?

Not simply because of this email. Secure whichever credentials you exposed and review that account’s activity.

If your actual FedEx account shows unauthorized changes, contact FedEx through a verified support route. Closing unrelated services will not secure an exposed mailbox.

Can the Email Prove That a Delivery Fee Is Owed?

No. This documented lure does not establish a real charge. Check genuine invoices or duties through the carrier and your order records.

Do not pay an unknown party merely to release the supposed documents or finish a process started by the suspicious notice.

The Bottom Line

The FedEx shipment-scheduled scam uses a delivery update to introduce an unrelated document login. Its familiar branding does not authorize collection of your mailbox password.

Match the shipment to a real order, track independently, and secure any credentials entered. Treat genuine delivery questions and account exposure as separate problems.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Yuguz.com EXPOSED – Fake or Real Store? Our Findings

Next

Puravogue.com EXPOSED – Real or Fake Store? Investigation