{"id":399123,"date":"2026-08-03T03:20:00","date_gmt":"2026-08-03T03:20:00","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=399123"},"modified":"2026-08-03T03:20:00","modified_gmt":"2026-08-03T03:20:00","slug":"purolator-text-scam-fake-delivery-message","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/purolator-text-scam-fake-delivery-message\/","title":{"rendered":"Purolator Text Scam: How the Fake Delivery Message Steals Your Information"},"content":{"rendered":"<p>A text claiming that Purolator cannot deliver your package can feel perfectly timed, especially when you are already waiting for an online order. The message may look routine, but one rushed tap can lead to a convincing website built to collect your address, card details, passwords, or other sensitive information.<\/p><div id=\"mwtad1685661371\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The Purolator text scam is a form of SMS phishing, also known as smishing. This guide explains how to recognize the fake delivery notice, how the operation unfolds behind the screen, and what to do calmly and quickly if you have already interacted with it.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/purolator-text-scam-message.png\" alt=\"Example of a fraudulent Purolator delivery text message displayed on a smartphone\" title=\"\"><figcaption class=\"wp-element-caption\">Illustration of a fraudulent delivery text. The reserved .example address is nonfunctional and is shown for educational purposes.<\/figcaption><\/figure>\n<div id=\"mwtad2377376094\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<p>The Purolator text scam begins with an unexpected message that appears to come from the well-known Canadian courier. It usually claims that a parcel is waiting, a delivery attempt failed, or the shipping address is incomplete. To fix the supposed problem, the recipient is told to open a link and act before a short deadline expires.<\/p><div id=\"mwtad77495608\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>There may be no real package problem at all. The sender is not Purolator, and the link does not lead to a legitimate Purolator service. It opens a phishing website controlled by criminals, often designed to resemble a genuine tracking, address correction, or payment page.<\/p>\n<p>Purolator has issued an official warning about fraudulent text messages that impersonate the company and ask recipients to confirm address details. The company says these messages are not legitimate, and it has reported the smishing campaign to the Canadian Anti-Fraud Centre.<\/p>\n<h3>What the fake Purolator text may say<\/h3>\n<p>The wording changes from one campaign to another, but most versions use the same simple story. Something is allegedly preventing a parcel from reaching you, and only immediate action will keep it from being returned.<\/p><div id=\"mwtad754490117\" class=\"gas_fallback-ad_309686-ad_309691-placement_360569\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>A typical message may resemble the following:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>Purolator: We were unable to deliver your parcel because the address information is incomplete. Please update your delivery details within 24 hours: [fraudulent link]\n<\/blockquote>\n<p>Other variations may mention a missed delivery, an unpaid customs charge, a package held at a warehouse, or a small redelivery fee such as $1.99 or $2.99. The amount is intentionally low because the scammers want payment to feel easier than investigating the message.<\/p>\n<p>The small fee is rarely the real prize. The payment form can capture the card number, expiration date, security code, billing address, phone number, and email address. Those details are far more valuable to a criminal than the fee displayed on the page.<\/p>\n<h3>Why the message can feel so believable<\/h3>\n<p>Package delivery scams work because they fit naturally into daily life. Millions of people order groceries, electronics, clothing, prescriptions, and gifts online. A scammer does not need to know that you are expecting a parcel. Sending the same message to thousands of random phone numbers will inevitably reach many people who are.<\/p><div id=\"mwtad431613179\" class=\"gas_fallback-ad_381401-ad_309691-placement_360573\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The timing creates a powerful coincidence. If you placed an order yesterday, a delivery warning today feels connected to that purchase. The victim supplies the connection in their own mind, while the scammer only supplied a vague message.<\/p>\n<p>Modern sender spoofing can also make a message appear under a recognizable business name. In some situations, a fraudulent text may even appear in the same conversation as legitimate notifications. The <a href=\"https:\/\/www.cyber.gc.ca\/sites\/default\/files\/itsap.00.103-e_0.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Canadian Centre for Cyber Security<\/a> warns that spoofing trusted sender information can make smishing messages much harder to distinguish from real communication.<\/p>\n<p>A professional-looking page is not proof of authenticity either. Criminals can copy colors, page layouts, logos, shipping language, and tracking forms. They can also obtain HTTPS certificates, so a padlock in the browser only means the connection is encrypted. It does not prove the site belongs to Purolator.<\/p><div id=\"mwtad1074582342\" class=\"gas_fallback-ad_381404-ad_309691-placement_381406\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>Common warning signs of the Purolator text scam<\/h3>\n<p>You do not need to become a cybersecurity expert to recognize most fake delivery messages. Pause before tapping and look for several signs that commonly appear together:<\/p>\n<ul>\n<li><strong>The message is unexpected.<\/strong> You did not request text updates, or you are not expecting a Purolator delivery.<\/li>\n<li><strong>It creates urgency.<\/strong> The parcel will supposedly be returned, destroyed, or delayed unless you act within a few hours.<\/li>\n<li><strong>The link is not on purolator.com.<\/strong> It may use extra words, unusual hyphens, misspellings, a URL shortener, or an unfamiliar domain ending.<\/li>\n<li><strong>It asks for sensitive information.<\/strong> The page requests card details, banking information, account passwords, or an electronic money transfer.<\/li>\n<li><strong>It demands a surprise fee.<\/strong> A tiny redelivery, address correction, or customs charge is presented as the only way to release the package.<\/li>\n<li><strong>The tracking details are vague.<\/strong> The text may omit the sender, retailer, destination, or a tracking number you can verify independently.<\/li>\n<li><strong>The language pushes you toward the link.<\/strong> There is no safe option to verify the issue through the official website or app.<\/li>\n<\/ul>\n<p>Purolator advises customers to use <a href=\"https:\/\/www.purolator.com\/\" rel=\"nofollow noopener\" target=\"_blank\">purolator.com<\/a> directly when tracking a shipment or updating an address. The company also states that it does not request credit card details, banking information, account payment updates, or wire transfers through unsolicited texts, emails, social messages, or WhatsApp messages.<\/p>\n<p>If you genuinely expect a delivery, do not use the link, phone number, or contact information in the text. Open a new browser window, type purolator.com yourself, and enter the tracking number from your retailer&#8217;s order confirmation. You can also contact Purolator through the verified details on its official website.<\/p><div id=\"mwtad4279985396\" class=\"gas_fallback-ad_360582-ad_309691-placement_360581\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<div id=\"mwtad1669432523\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How The Scam Works<\/h2>\n<p>The Purolator text message scam is best understood as a sequence. Each screen asks for something small, making the next request feel like a natural part of solving the delivery issue. Here is how the scheme commonly unfolds.<\/p>\n<h3>1. Scammers distribute the bait by text message<\/h3>\n<p>The campaign starts with a large batch of SMS or iMessage messages sent to Canadian phone numbers. The list may come from an old data breach, a marketing database, automated number generation, or another criminal source.<\/p>\n<p>The scammers do not necessarily know your name, address, or shopping history. A generic delivery problem is broad enough to match many recipients. If personal information appears in the message, it may have been combined from previously leaked data to make the lure more persuasive.<\/p><div id=\"mwtad2194656004\" class=\"gas_fallback-ad_360567-ad_309691-placement_360771\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6224621518\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The sender name may show as Purolator, Delivery Notice, Parcel Service, or an ordinary phone number. Because sender information can be falsified, a familiar name at the top of the conversation should never be treated as proof.<\/p>\n<h3>2. The message creates a problem and a deadline<\/h3>\n<p>The text introduces a minor but urgent obstacle. Perhaps the street number is missing, the postal code is invalid, the delivery attempt failed, or a small balance remains unpaid. These explanations are deliberately plausible and easy to understand at a glance.<\/p>\n<p>Next comes the deadline. The package may supposedly be returned within 12 or 24 hours, or the recipient may be warned that another delivery attempt will not be made. This pressure is not just dramatic wording. It is a social engineering tool designed to interrupt careful thinking.<\/p><div id=\"mwtad2520503283\" class=\"gas_fallback-ad_360571-ad_309691-placement_360772\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5867729999\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>A person who believes a purchase is about to disappear is more likely to tap first and inspect later. The scammer wants the victim focused on saving the parcel, not checking who owns the linked website.<\/p>\n<h3>3. The link opens a Purolator lookalike website<\/h3>\n<p>The fraudulent link may be shortened to hide its destination or registered on a domain containing words such as purolator, parcel, delivery, track, update, or Canada. On a small phone screen, the address bar may be difficult to read, especially when the domain is long.<\/p>\n<p>The landing page often copies recognizable visual elements from the real courier. It may display a delivery progress bar, a Canadian flag, a fabricated tracking number, or a notice saying the address requires confirmation.<\/p><div id=\"mwtad3470629212\" class=\"gas_fallback-ad_360576-ad_309691-placement_360773\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6594472392\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Some fake sites are assembled from templates used for many courier brands. The criminals can replace one logo and color scheme with another while keeping the same data collection forms behind the page.<\/p>\n<p>The safest test is simple: the registered domain must be exactly purolator.com or a clearly legitimate subdomain ending in .purolator.com. A name such as purolator.delivery-update.example would not belong to Purolator because the actual registered domain is delivery-update.example.<\/p>\n<h3>4. The first form collects identity and contact details<\/h3>\n<p>Before asking for money, the fake page may request the recipient&#8217;s full name, home address, postal code, phone number, and email address. This step feels consistent with correcting a shipping label, which reduces suspicion.<\/p><div id=\"mwtad482925562\" class=\"gas_fallback-ad_360583-ad_309691-placement_360774\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8849826992\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>When submitted, the information can be transmitted directly to the scammers. Even if the victim stops before the payment screen, the data already entered may be stored and used in later fraud.<\/p>\n<div id=\"mwtad1452003902\" class=\"gas_fallback-ad_360584-ad_309691-placement_360775\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3952847241\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>A confirmed combination of name, phone number, email, and address can support more convincing phishing calls and messages. It may also be bundled with information from other breaches and sold to additional criminals.<\/p>\n<h3>5. A small payment request captures the card<\/h3>\n<p>The next page commonly claims that a small redelivery or processing fee is due. A charge of $1.99 or $2.99 appears harmless, particularly when compared with the value of the package the victim believes is waiting.<\/p>\n<p>The form asks for the cardholder name, card number, expiration date, security code, and billing address. Submitting the form gives the criminal enough information to attempt online purchases or sell the card details.<\/p>\n<p>The fake site may display an error after submission and ask the victim to try another card. This is a particularly damaging trick because one person may unknowingly expose two or three payment cards while trying to complete a payment that can never succeed.<\/p>\n<h3>6. The scam may attempt to capture a verification code<\/h3>\n<p>Some banks require an additional one-time code before approving a purchase. Criminals may trigger a real transaction in the background and then show a fake verification screen asking the victim to enter the code received by text or banking app.<\/p>\n<p>That code is not confirming a $1.99 delivery fee. It may be authorizing a much larger transaction, adding a card to a digital wallet, or approving access to an account. A one-time code should never be entered into a site reached through an unsolicited message.<\/p>\n<p>Read every verification notification carefully. The amount, merchant, location, or requested action may reveal what is really happening. If anything is unfamiliar, stop and contact the bank using the number printed on the physical card.<\/p>\n<h3>7. Stolen information is used for additional fraud<\/h3>\n<p>Once the data is collected, it can be used immediately or retained for later. Criminals may test the card with small purchases, attempt a larger transaction, target the victim with bank impersonation calls, or send another message claiming that suspicious activity must be reversed.<\/p>\n<p>This follow-up can be more convincing because the caller knows details the victim just entered. They may know the person&#8217;s name, card issuer, address, and the exact story that caused the compromise.<\/p>\n<p>In other cases, the collected information is sold through criminal marketplaces. A victim may therefore see fraudulent activity days or weeks later, even if nothing unusual happens immediately after visiting the fake Purolator page.<\/p>\n<h3>8. The phishing site disappears and returns under a new address<\/h3>\n<p>Fraudulent delivery websites are often temporary. Hosting providers, browser security services, and authorities may block one domain, but the operators can quickly register another and reuse the same website template.<\/p>\n<p>This is why memorizing one malicious address is not enough. The durable protection is to distrust unsolicited delivery links, verify shipments independently, and pay attention to the registered domain every time.<\/p>\n<div id=\"mwtad2314756536\" class=\"gas_fallback-ad_309748-ad_309691-placement_360588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What To Do If You Have Fallen Victim<\/h2>\n<p>If you clicked the link or entered information, take a breath. A fast, organized response can greatly reduce the damage. What matters most is what you shared, downloaded, or approved, so work through the following steps in order.<\/p>\n<ol>\n<li>\n<h3>Stop interacting with the message and fake website<\/h3>\n<p>Close the page and do not submit another form, download a file, call a number shown on the site, or reply to the original text. If the page says your payment failed, do not try a second card.<\/p>\n<p>Do not continue simply to see what happens. Every additional screen may request more information or attempt to persuade you to install an app, browser extension, device profile, or remote access tool.<\/p>\n<\/li>\n<li>\n<h3>Identify exactly what was exposed<\/h3>\n<p>Write down whether you only opened the link or also entered a name, address, password, card number, bank information, or one-time verification code. Note whether you downloaded anything or installed an application.<\/p>\n<p>Simply opening a page does not automatically mean your phone or bank account has been compromised. The risk rises substantially if you submitted information, approved a prompt, installed software, or granted permissions.<\/p>\n<\/li>\n<li>\n<h3>Contact your bank or card issuer immediately<\/h3>\n<p>If you entered any payment information, call the number printed on the back of the card or use the bank&#8217;s official mobile app. Explain that the card details were entered on a phishing website impersonating Purolator.<\/p>\n<p>Ask the issuer to block or replace the card, review pending transactions, and advise whether the account needs additional protection. If you entered a verification code, mention that clearly because a transaction or digital wallet enrollment may already have been authorized.<\/p>\n<p>Do not call a phone number from the suspicious text, fake website, or a follow-up caller. A criminal may impersonate the bank and offer to help with the very fraud they initiated.<\/p>\n<\/li>\n<li>\n<h3>Change any password you submitted<\/h3>\n<p>If the fake page asked you to sign in, change that password from the service&#8217;s official website or app. Use a clean device if you installed unknown software or believe your device may be compromised.<\/p>\n<p>Change the same password anywhere else you reused it. Start with your email account, banking services, mobile carrier, cloud storage, and shopping accounts because access to those services can help a criminal reset other passwords.<\/p>\n<p>Create a unique password for every account and enable multi-factor authentication. An authenticator app, passkey, or hardware security key is generally safer than relying only on SMS codes.<\/p>\n<\/li>\n<li>\n<h3>Secure your email and mobile account<\/h3>\n<p>Review your email account for unknown forwarding rules, recovery addresses, signed-in devices, and password reset messages. Remove anything you do not recognize and sign out of unfamiliar sessions.<\/p>\n<p>Contact your mobile carrier if you shared account credentials, a carrier PIN, or enough identity information to support a SIM swap. Ask the carrier to add or strengthen the account PIN and confirm that no unauthorized device or SIM change is pending.<\/p>\n<\/li>\n<li>\n<h3>Check the device for unwanted software or profiles<\/h3>\n<p>Purolator advises people who clicked a fraudulent link to run a malware scan. Keep the phone and its apps updated, then use a reputable mobile security product if one is available for your device.<\/p>\n<p>On Android, inspect recently installed apps and remove anything obtained through the fake page. Check accessibility, device administrator, notification access, and install-unknown-app permissions for entries you do not recognize.<\/p>\n<p>On an iPhone, review Settings for unfamiliar configuration profiles, VPN entries, calendar subscriptions, or apps. If the website instructed you to install a profile, remove it and contact Apple Support if you are unsure what permissions it granted.<\/p>\n<\/li>\n<li>\n<h3>Preserve evidence before deleting the text<\/h3>\n<p>Take screenshots of the message, sender information, website address, forms, and any transaction notices. Record the time, the information you entered, and the steps you have taken.<\/p>\n<p>Do not revisit a malicious site solely to collect evidence. Preserve what is safely available in your message history and browser history. These records may help your bank, mobile carrier, police, or fraud investigators.<\/p>\n<\/li>\n<li>\n<h3>Report the Purolator scam text<\/h3>\n<p>Forward the suspicious message to <strong>7726<\/strong>, which spells SPAM on a phone keypad, or use your messaging app&#8217;s built-in report function. This helps carriers identify and block active campaigns.<\/p>\n<p>Report the incident to the <a href=\"https:\/\/www.antifraudcentre-centreantifraude.ca\/report-signalez-eng.htm\" rel=\"nofollow noopener\" target=\"_blank\">Canadian Anti-Fraud Centre<\/a>. If money was lost, identity information was stolen, or threats were made, contact your local police agency as well.<\/p>\n<p>You can also notify Purolator through contact details obtained directly from its official website. Sharing the sender number, link, and screenshot can help the company investigate new impersonation campaigns.<\/p>\n<\/li>\n<li>\n<h3>Monitor financial and identity activity<\/h3>\n<p>Review card and bank transactions regularly, including small amounts that may be used to test whether an account is active. Turn on transaction notifications so an unfamiliar charge is noticed quickly.<\/p>\n<p>If sensitive identity information was disclosed, contact Equifax Canada and TransUnion Canada to discuss fraud alerts or other protective measures. Watch for unfamiliar credit applications, account changes, bills, and collection notices.<\/p>\n<p>Keep monitoring after the first few days. Stolen data may be resold or used later, so the absence of immediate fraud does not always mean the information was discarded.<\/p>\n<\/li>\n<li>\n<h3>Be alert for recovery and bank impersonation scams<\/h3>\n<p>Victims are sometimes contacted again by someone claiming to be a bank investigator, police officer, cybersecurity expert, or refund service. The caller may know accurate personal details because those details came from the phishing form.<\/p>\n<p>No legitimate helper needs your password, full card number, one-time code, cryptocurrency payment, gift card, or remote access to your device. End the call and contact the organization independently through a verified number.<\/p>\n<\/li>\n<\/ol>\n<div id=\"mwtad279056208\" class=\"gas_fallback-ad_318930-ad_309691-placement_360589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Bottom Line<\/h2>\n<p>The Purolator text scam turns an ordinary delivery concern into a hurried request for personal and financial information. The message may look polished, arrive at a believable time, and lead to a website that closely resembles the real courier, but the urgency and unfamiliar link are designed to keep you from checking carefully.<\/p>\n<p>Do not use links in unexpected delivery texts. Track the parcel by typing purolator.com into your browser or by opening the official app, and contact the company through independently verified details. If you already interacted with the scam, act promptly, protect your accounts, report the message, and remember that a calm response can still prevent a suspicious text from becoming a lasting financial problem.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A fake Purolator delivery text may ask you to update your address or pay a small fee. Learn how the scam works, how to spot it, and what to do if you clicked.<\/p>\n","protected":false},"author":1,"featured_media":399122,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[49],"tags":[3194,3192,3193,3195,3196],"class_list":["post-399123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","tag-package-delivery-scam","tag-purolator-scam","tag-purolator-text-scam","tag-smishing","tag-text-message-scam","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/399123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=399123"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/399123\/revisions"}],"predecessor-version":[{"id":399129,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/399123\/revisions\/399129"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/399122"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=399123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=399123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=399123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}