Consumer Safety Desk

The Fake USPS Text Isn't After Your 30 Cents. It's Step One of a Chain That Took $25,600 From One Maryland Woman.

Recreation of the fake USPS redelivery-fee text message on a phone screen at 11:04 PM

The text looks routine. The website looks real. And the phone call that comes days later sounds exactly like your bank — because by then, they're reading your own details back to you.

★★★★★3,412 Ratings
Portrait of Dana Whitfield, consumer safety reporter

By Dana Whitfield
Consumer Safety Desk · Updated July 2026 · 6 min read

The Federal Trade Commission ranks fake package-delivery texts as the most reported text scam in America.

Estimated 6 Minute ReadPublished July 2026

The fee was thirty cents.

That's the number worth sitting with. Nobody loses their savings over thirty cents — which is exactly why, just after 11 p.m. on a Tuesday, Maya K., 34, typed her card number into a delivery page without thinking twice.

She was in bed. She was tired. And she was genuinely waiting for a package.

"USPS: Your package is on hold due to an unpaid redelivery fee ($0.30)."

This is not a rare message. The Better Business Bureau has warned about this exact text — a "slight redelivery fee, sometimes even just 30 cents" — and the Federal Trade Commission ranks fake package-delivery texts as the most reported text scam in America. Maya had probably ignored fifty messages like it.

She clicked the fifty-first because she really was waiting for a package.

The link opened a tracking page with the right colors, the right logo, a plausible tracking number. She entered her card, her name, her address, and tapped Pay.

The page showed an error.

Payment could not be processed. Please try a different card.

She sighed, reached for her other card, and typed that one in too.

Error again.

And here's the completely human part: she wasn't scared. She was annoyed. It was late, the fee was pocket change, the site was clearly glitching. I'll deal with it tomorrow, she thought, and went to sleep.

By morning she'd forgotten about it entirely.

Woman lying in bed at night reading the fake USPS redelivery text on her phone
The message arrived just after 11 p.m. — the hour these chains are timed for.
T

r/Scams

u/tired_in_texas · 3 mo ago

My gut dropped the second the bank called. Two days after I'd typed my card into a delivery page and forgotten about it.

2.4k💬 371 comments
r/Scams · posted 3 mo ago · paraphrased

That error message is the most underrated trick in the entire scam. A page that "fails" doesn't raise alarms — it collects a second card, sometimes a third, and buys the scammers something more valuable than money: time to prepare, while you go on with your week.

Because the text was never the scam. It was the start of one — a doorway into everything that comes next.

Fake USPS package redelivery payment page on a phone showing a card field and a 'payment could not be processed' error
The look-alike URL, the card field, the 'try a different card' error — the error is the harvest.

Two days later, "her bank" called

Thursday, mid-afternoon. Her phone rang, and the caller ID showed the name of her bank.

The man on the line was calm and professional — the slightly bored tone of someone who does this all day. He was calling from the fraud department. Had she recently entered her card details on a delivery website?

That was the moment her stomach dropped.

Incoming call screen showing First National Bank Fraud Department as the caller ID
Spoofing a bank's display name takes seconds. The call looks real because the scammers already have your details from the fake delivery page.

Because he was right. He knew about the delivery site. He read her the last four digits of her card — correctly. Her billing ZIP. The exact night it happened.

Two days ago she'd been annoyed at a glitchy website. Now her bank was calling about it.

The call didn't feel like a scam.

It felt like a rescue.

He explained that two larger charges were now being attempted with her card and the bank could block them — he just needed to verify her identity while he reversed the attempts.

A text code arrived. The message said not to share it.

"That warning is for account logins," he said smoothly. "We're not logging in. We're cancelling charges. I'll stay on the line."

That one sentence changes what the code means. She wasn't giving a stranger access anymore — she was helping her bank stop fraud.

She read him the first code.

Then the second code arrived, and something in the small print snagged her eye: authorize new payee.

Two bank verification code text messages, the second one authorizing a new payee, under a magnifying glass
The two codes, stacked. The second one's small print is the whole trap: authorize a new payee.

"Sorry — I want to call the branch first," she said. "I'll call you back."

His voice tightened. "Ma'am, if we don't complete this now, I can't guarantee we can stop the pending charges."

She hung up anyway. Not because she'd cracked the scam — because the pressure felt wrong, and calling your own bank felt like the boring, sensible thing to do.

That evening she called the number on the back of her card. The real fraud team told her two things.

There was no case under her name.

And earlier that day, someone had attempted a change on her account — an attempt that had needed exactly one code, and gotten it.

One more code, and this would be a very different story.

M

r/Scams

u/melissaQ83 · 5 mo ago

They give you a case number to add credibility, then transfer you to someone who says they need you to 'authorize the cancellation' of the charges.

2.1k💬 418 comments
r/Scams · posted 5 mo ago · paraphrased

Maya's story stops there. Jane Dean's didn't.

Maya got the boring, sensible instinct at the right moment. To understand what happens when the chain runs to the end, you have to hear about a different woman, in Maryland, whose version of this played out all the way.

Jane Dean, a retiree, told her local news station her chain started not with a text but with a call — "suspicious Amazon charges." The voice transferred her to a "bank investigator." And then came the instruction that defines this stage of the scam: your money isn't safe in your account. Withdraw it in cash so we can protect it. And don't tell anyone — it could compromise the investigation.

So she did what the calm, official voice said. She withdrew cash at one bank. Then at a second. The "investigator" gave her addresses where the cash was to be sent for "safekeeping" while they closed the case.

At the third bank, a manager stopped her at the counter. He knew her. "Jane. What's going on?"

She told him. He typed one of the addresses into his computer, turned the screen around, and showed her what she'd been sending her money to: an empty house on a construction lot.

"You're being scammed."

The warning was face-to-face. From a banker. With proof on the screen. And it still arrived $25,600 late.

Bank statement showing four large cash withdrawals circled in red totalling $25,600
Four cash withdrawals in three days — $25,600 gone from her account.

How far does it go? Ask Judith.

If $25,600 sounds like the ceiling, it isn't.

Judith Boivin, 81 — a retired therapist from the same county — followed a nearly identical script, run patiently over months by a man claiming federal authority. By the end she had handed over $595,958. And some cents, as she told AARP's fraud investigators — precise to the last drop, because it was everything. Her entire retirement, built across a working lifetime.

"I went into a kind of shock," she said of the day she learned the truth.

And for all those months, the people who loved her had no idea it was happening — because the very first instruction, back at the beginning of the chain, was the same one Jane got:

Don't tell anyone."$595,958. And some cents."
Older woman sitting by a window at home with her phone face-down on the table
Documented case: “$595,958. And some cents.”

Why being careful stopped working

If you're thinking I'd never fall for this — notice what actually failed in these three stories. It wasn't intelligence.

What actually failed

Spam filters failed. The text that reached Maya wasn't in junk. Messages timed to real life — a package you're actually expecting — sail through, because they look like messages you want.

The old tells failed. Bad grammar. Weird links. Foreign numbers. For years, those were the signals. Security researchers now report AI writing tools have erased them — today's scam texts read clean, local, natural. The fake page may be tidy. The caller may sound professional. The brand may be one you actually use. That doesn't make the scammer a genius. It means they're using what every modern business uses: templates, automation, timing — and leaked information.

Caller ID failed. It showed the bank's name because spoofing a display name is trivial.

Even human warnings failed. A banker with proof on his screen, face-to-face, arrived $25,600 late. The FTC's guidance arrived after $470 million in reported text-scam losses in a single year — and the FTC itself notes most victims never report at all.

Every one of those defenses shares one flaw: each sees a single step of a chain that runs across four channels. The filter sees a text. The browser sees a link. The bank sees a withdrawal. You hear a phone call.

The scammer is the only one who sees the whole chain.

That's not a carefulness problem. It's a visibility problem.

Diagram of the scam chain: text, site, wait, call, money, with three interception points
The chain: TEXT → SITE → WAIT → CALL → MONEY, with three interception points before any money moves.

The chain starts before the text — and that part, you can actually check

One more thing about Maya's text: it wasn't random.

Her email and phone number had appeared in data breaches — the kind attached to old shopping accounts, the kind almost everyone has and almost nobody checks. That's how the timing gets uncanny, and how a "fraud department" ends up knowing which card you used. When your information circulates, coincidences stop being coincidences.

N

r/Scams

u/notmy1strodeo · 6 wk ago

Yesterday I just started getting hundreds of verification codes from sites I don't even have an account for.

1.4k💬 266 comments
r/Scams · posted 6 wk ago · paraphrased

Here's the part most scam warnings never get to: you can see this layer. There's now a free, roughly 60-second check that scans known breach records for your email and shows you what of yours is already circulating — the exact fuel these chains run on. If a scammer could know it, you should know it first.

That free scan is part of TurtleShield — an app built around this exact chain.

Four channels. One defense.

TurtleShield's approach is called Four-Vector Defense, and it exists because of stories like the three above: it watches the four channels the chain uses, together, on one phone.

  • Suspicious texts — links scored before you tap, so the $0.30 fee is flagged at step one, not after your card is in.
  • Dangerous links & sites — the look-alike tracking page flagged as an impostor the moment it loads, "error message" and all.
  • Scam calls — the "fraud department" follow-up checked against known impostor patterns, so it arrives with a warning attached instead of your bank's borrowed credibility.
  • Exposed data — the breach records that made you a target, visible to you instead of only to them.

Look back at the chain diagram. Three of the five steps get intercepted before any money moves — and none of them requires you to out-think a professional script at 11 p.m., or to be sharper than Jane's banker.

Four-Vector Defense diagram: suspicious texts, dangerous links and sites, scam calls and exposed data mapped over the scam chain
The scammer sees the whole chain. Now you do too.

"So what do I actually do?"

"I just won't click links anymore." Jane never clicked a link. Her chain started with a phone call. The channels rotate; the chain is the constant.

"My phone already filters spam." So did Maya's. The dangerous message is the one built to pass the filter.

"I'd catch it next time." You'd catch this version. Delivery fees become toll fees, jury duty, fraud alerts. The shape survives every costume change — and it hunts moments, not people: tired, distracted, waiting on a package.

"Another app that wants my data?" The scan reads what's already exposed about you in known breach records and shows it to you, on your screen. It reveals circulation — it doesn't add to it.

Check what they already have — free, in about 60 seconds

Maya's chain started with her exposed data. Jane's started with a call that already knew too much. Judith's ran for months on information no one knew was out there.

So that's where protection starts: see it first.

  1. 1Enter your email
  2. 2Scan runs in under 60 seconds
  3. 3Your exposed data, revealed
Run my free scan →
  • ⏱️ Takes about a minute
  • 🙅 No sign-up required
  • 📧 Your email starts the scan
  • 🔒 100% private — nothing stored
  • 🔎 Checks known breach records
  • 💳 Free — no card, no trial

Your results appear on screen. Nothing is shared or sold.

TurtleShield is built to get ahead of the chain — to flag the text, the site, and the call while they're still just pixels on a screen, and to show you the exposure that put you on the list in the first place. Protection that starts before step one.

Every scam story you've ever read ends the same way: "be careful."

This is the button they never had.

Most people are more exposed than they think

Scan result · Columbus, OH

Email found in 7 known breaches

📧 Email in breach records🔑 2 passwords exposed

I had no idea my info was this available.

— scan result, M.R.

Illustrative result. Your scan shows your own exposure.

Scan result · Tempe, AZ

Email found in 3 breaches — including an old password still in use

🔑 Reused password exposed📧 Email in breach records

That password is still on two of my accounts.

— scan result, D.L.

Illustrative result. Your scan shows your own exposure.

Scan result · Rochester, NY

Phone number and email both circulating in breach records

📞 Number circulating📧 Email in breach records

So that's why the delivery texts always know my name.

— scan result, A.P.

Illustrative result. Your scan shows your own exposure.

The average reported loss in scams like these runs into the thousands. The scan that shows your exposure takes a minute — and costs nothing.

Run my free scan →
  • ⏱️ Takes about a minute
  • 🙅 No sign-up required
  • 📧 Your email starts the scan
  • 🔒 100% private — nothing stored
  • 🔎 Checks known breach records
  • 💳 Free — no card, no trial

Your results appear on screen. Nothing is shared or sold.

Reader Reactions

142 comments

LM

Linda M. · 2 days ago

My mother got the call part of this last month. A man who sounded like he worked at her bank, knew her card ending, the whole thing. She only stopped because my brother happened to be in the kitchen with her.

▲ Helpful (41)Reply
RT

Robert T. · 1 day ago

Same script my dad got. They never rush you at the start — that's what makes it work.

▲ Helpful (12)Reply
GK

Grace K. · 3 days ago

I got the exact 30-cent redelivery text last week. Deleted it, but I'll admit I was genuinely waiting on a parcel and almost tapped it.

▲ Helpful (28)Reply
DA

D. Alvarez · 4 days ago

Forwarded this to my whole family group chat. My aunt has clicked two of these already this year.

▲ Helpful (19)Reply
MW

Marcus W. · 5 days ago

The error-message trick got me. Entered two cards before I gave up. Cancelled both the next morning, but the article is right — the annoyance is the disguise.

▲ Helpful (63)Reply
PH

Patricia H. · 6 days ago

How do I check my own exposure? I've had the same email address since 2004 and I assume it's everywhere by now.

▲ Helpful (22)Reply
JW

J. Whitfield · 5 days ago

There's a free scan linked above that shows what's already out there for your email. Took me under a minute.

▲ Helpful (31)Reply
KO

Ken O. · 1 week ago

What gets me is the caller ID. Mine showed the bank's actual name. If that can be faked, what's left to trust?

▲ Helpful (37)Reply

Add a comment

Post comment
Run my free scan →
  • ⏱️ Takes about a minute
  • 🙅 No sign-up required
  • 🔒 100% private
  • 💳 Free — no card needed

Sources: FTC Consumer Alerts & Data Spotlights (text scams; $470M reported losses) · Better Business Bureau via CBS Pittsburgh (the 30-cent redelivery fee) · U.S. Postal Inspection Service (USPS sends no unsolicited tracking texts, never with links) · WMAR-2 / NBC4 Washington (Jane Dean, $25,600) · AARP Fraud Wars (Judith Boivin, $595,958) · public r/Scams threads (paraphrased, anonymized). Sponsored consumer-education article (advertorial) for TurtleShield. "Maya K." is a composite reconstructed from documented case patterns and public first-person accounts; Dean and Boivin cases are publicly reported.

This is sponsored consumer-education content (advertorial) and not an actual news article. Composite scenes reconstructed from documented cases and public accounts.