The Fake USPS Text Isn't After Your 30 Cents. It's Step One of a Chain That Took $25,600 From One Maryland Woman.

The text looks routine. The website looks real. And the phone call that comes days later sounds exactly like your bank — because by then, they're reading your own details back to you.

By Dana Whitfield
Consumer Safety Desk · Updated July 2026 · 6 min read
The Federal Trade Commission ranks fake package-delivery texts as the most reported text scam in America.
The fee was thirty cents.
That's the number worth sitting with. Nobody loses their savings over thirty cents — which is exactly why, just after 11 p.m. on a Tuesday, Maya K., 34, typed her card number into a delivery page without thinking twice.
She was in bed. She was tired. And she was genuinely waiting for a package.
"USPS: Your package is on hold due to an unpaid redelivery fee ($0.30)."
This is not a rare message. The Better Business Bureau has warned about this exact text — a "slight redelivery fee, sometimes even just 30 cents" — and the Federal Trade Commission ranks fake package-delivery texts as the most reported text scam in America. Maya had probably ignored fifty messages like it.
She clicked the fifty-first because she really was waiting for a package.
The link opened a tracking page with the right colors, the right logo, a plausible tracking number. She entered her card, her name, her address, and tapped Pay.
The page showed an error.
Payment could not be processed. Please try a different card.
She sighed, reached for her other card, and typed that one in too.
Error again.
And here's the completely human part: she wasn't scared. She was annoyed. It was late, the fee was pocket change, the site was clearly glitching. I'll deal with it tomorrow, she thought, and went to sleep.
By morning she'd forgotten about it entirely.

r/Scams
u/tired_in_texas · 3 mo ago
My gut dropped the second the bank called. Two days after I'd typed my card into a delivery page and forgotten about it.
That error message is the most underrated trick in the entire scam. A page that "fails" doesn't raise alarms — it collects a second card, sometimes a third, and buys the scammers something more valuable than money: time to prepare, while you go on with your week.
Because the text was never the scam. It was the start of one — a doorway into everything that comes next.

Two days later, "her bank" called
Thursday, mid-afternoon. Her phone rang, and the caller ID showed the name of her bank.
The man on the line was calm and professional — the slightly bored tone of someone who does this all day. He was calling from the fraud department. Had she recently entered her card details on a delivery website?
That was the moment her stomach dropped.

Because he was right. He knew about the delivery site. He read her the last four digits of her card — correctly. Her billing ZIP. The exact night it happened.
Two days ago she'd been annoyed at a glitchy website. Now her bank was calling about it.
The call didn't feel like a scam.
It felt like a rescue.
He explained that two larger charges were now being attempted with her card and the bank could block them — he just needed to verify her identity while he reversed the attempts.
A text code arrived. The message said not to share it.
"That warning is for account logins," he said smoothly. "We're not logging in. We're cancelling charges. I'll stay on the line."
That one sentence changes what the code means. She wasn't giving a stranger access anymore — she was helping her bank stop fraud.
She read him the first code.
Then the second code arrived, and something in the small print snagged her eye: authorize new payee.

"Sorry — I want to call the branch first," she said. "I'll call you back."
His voice tightened. "Ma'am, if we don't complete this now, I can't guarantee we can stop the pending charges."
She hung up anyway. Not because she'd cracked the scam — because the pressure felt wrong, and calling your own bank felt like the boring, sensible thing to do.
That evening she called the number on the back of her card. The real fraud team told her two things.
There was no case under her name.
And earlier that day, someone had attempted a change on her account — an attempt that had needed exactly one code, and gotten it.
One more code, and this would be a very different story.
r/Scams
u/melissaQ83 · 5 mo ago
They give you a case number to add credibility, then transfer you to someone who says they need you to 'authorize the cancellation' of the charges.
Maya's story stops there. Jane Dean's didn't.
Maya got the boring, sensible instinct at the right moment. To understand what happens when the chain runs to the end, you have to hear about a different woman, in Maryland, whose version of this played out all the way.
Jane Dean, a retiree, told her local news station her chain started not with a text but with a call — "suspicious Amazon charges." The voice transferred her to a "bank investigator." And then came the instruction that defines this stage of the scam: your money isn't safe in your account. Withdraw it in cash so we can protect it. And don't tell anyone — it could compromise the investigation.
So she did what the calm, official voice said. She withdrew cash at one bank. Then at a second. The "investigator" gave her addresses where the cash was to be sent for "safekeeping" while they closed the case.
At the third bank, a manager stopped her at the counter. He knew her. "Jane. What's going on?"
She told him. He typed one of the addresses into his computer, turned the screen around, and showed her what she'd been sending her money to: an empty house on a construction lot.
"You're being scammed."
The warning was face-to-face. From a banker. With proof on the screen. And it still arrived $25,600 late.

How far does it go? Ask Judith.
If $25,600 sounds like the ceiling, it isn't.
Judith Boivin, 81 — a retired therapist from the same county — followed a nearly identical script, run patiently over months by a man claiming federal authority. By the end she had handed over $595,958. And some cents, as she told AARP's fraud investigators — precise to the last drop, because it was everything. Her entire retirement, built across a working lifetime.
"I went into a kind of shock," she said of the day she learned the truth.
And for all those months, the people who loved her had no idea it was happening — because the very first instruction, back at the beginning of the chain, was the same one Jane got:
Don't tell anyone."$595,958. And some cents."

Why being careful stopped working
If you're thinking I'd never fall for this — notice what actually failed in these three stories. It wasn't intelligence.
What actually failed
Spam filters failed. The text that reached Maya wasn't in junk. Messages timed to real life — a package you're actually expecting — sail through, because they look like messages you want.
The old tells failed. Bad grammar. Weird links. Foreign numbers. For years, those were the signals. Security researchers now report AI writing tools have erased them — today's scam texts read clean, local, natural. The fake page may be tidy. The caller may sound professional. The brand may be one you actually use. That doesn't make the scammer a genius. It means they're using what every modern business uses: templates, automation, timing — and leaked information.
Caller ID failed. It showed the bank's name because spoofing a display name is trivial.
Even human warnings failed. A banker with proof on his screen, face-to-face, arrived $25,600 late. The FTC's guidance arrived after $470 million in reported text-scam losses in a single year — and the FTC itself notes most victims never report at all.
Every one of those defenses shares one flaw: each sees a single step of a chain that runs across four channels. The filter sees a text. The browser sees a link. The bank sees a withdrawal. You hear a phone call.
The scammer is the only one who sees the whole chain.
That's not a carefulness problem. It's a visibility problem.

The chain starts before the text — and that part, you can actually check
One more thing about Maya's text: it wasn't random.
Her email and phone number had appeared in data breaches — the kind attached to old shopping accounts, the kind almost everyone has and almost nobody checks. That's how the timing gets uncanny, and how a "fraud department" ends up knowing which card you used. When your information circulates, coincidences stop being coincidences.
r/Scams
u/notmy1strodeo · 6 wk ago
Yesterday I just started getting hundreds of verification codes from sites I don't even have an account for.
Here's the part most scam warnings never get to: you can see this layer. There's now a free, roughly 60-second check that scans known breach records for your email and shows you what of yours is already circulating — the exact fuel these chains run on. If a scammer could know it, you should know it first.
That free scan is part of TurtleShield — an app built around this exact chain.
Four channels. One defense.
TurtleShield's approach is called Four-Vector Defense, and it exists because of stories like the three above: it watches the four channels the chain uses, together, on one phone.
- Suspicious texts — links scored before you tap, so the $0.30 fee is flagged at step one, not after your card is in.
- Dangerous links & sites — the look-alike tracking page flagged as an impostor the moment it loads, "error message" and all.
- Scam calls — the "fraud department" follow-up checked against known impostor patterns, so it arrives with a warning attached instead of your bank's borrowed credibility.
- Exposed data — the breach records that made you a target, visible to you instead of only to them.
Look back at the chain diagram. Three of the five steps get intercepted before any money moves — and none of them requires you to out-think a professional script at 11 p.m., or to be sharper than Jane's banker.

"So what do I actually do?"
"I just won't click links anymore." Jane never clicked a link. Her chain started with a phone call. The channels rotate; the chain is the constant.
"My phone already filters spam." So did Maya's. The dangerous message is the one built to pass the filter.
"I'd catch it next time." You'd catch this version. Delivery fees become toll fees, jury duty, fraud alerts. The shape survives every costume change — and it hunts moments, not people: tired, distracted, waiting on a package.
"Another app that wants my data?" The scan reads what's already exposed about you in known breach records and shows it to you, on your screen. It reveals circulation — it doesn't add to it.
Check what they already have — free, in about 60 seconds
Maya's chain started with her exposed data. Jane's started with a call that already knew too much. Judith's ran for months on information no one knew was out there.
So that's where protection starts: see it first.
- 1Enter your email
- 2Scan runs in under 60 seconds
- 3Your exposed data, revealed
- ⏱️ Takes about a minute
- 🙅 No sign-up required
- 📧 Your email starts the scan
- 🔒 100% private — nothing stored
- 🔎 Checks known breach records
- 💳 Free — no card, no trial
Your results appear on screen. Nothing is shared or sold.
TurtleShield is built to get ahead of the chain — to flag the text, the site, and the call while they're still just pixels on a screen, and to show you the exposure that put you on the list in the first place. Protection that starts before step one.
Every scam story you've ever read ends the same way: "be careful."
This is the button they never had.
Most people are more exposed than they think
Email found in 7 known breaches
“I had no idea my info was this available.”
— scan result, M.R.
Illustrative result. Your scan shows your own exposure.
Email found in 3 breaches — including an old password still in use
“That password is still on two of my accounts.”
— scan result, D.L.
Illustrative result. Your scan shows your own exposure.
Phone number and email both circulating in breach records
“So that's why the delivery texts always know my name.”
— scan result, A.P.
Illustrative result. Your scan shows your own exposure.
The average reported loss in scams like these runs into the thousands. The scan that shows your exposure takes a minute — and costs nothing.
- ⏱️ Takes about a minute
- 🙅 No sign-up required
- 📧 Your email starts the scan
- 🔒 100% private — nothing stored
- 🔎 Checks known breach records
- 💳 Free — no card, no trial
Your results appear on screen. Nothing is shared or sold.
Reader Reactions
142 comments
Linda M. · 2 days ago
My mother got the call part of this last month. A man who sounded like he worked at her bank, knew her card ending, the whole thing. She only stopped because my brother happened to be in the kitchen with her.
Robert T. · 1 day ago
Same script my dad got. They never rush you at the start — that's what makes it work.
Grace K. · 3 days ago
I got the exact 30-cent redelivery text last week. Deleted it, but I'll admit I was genuinely waiting on a parcel and almost tapped it.
D. Alvarez · 4 days ago
Forwarded this to my whole family group chat. My aunt has clicked two of these already this year.
Marcus W. · 5 days ago
The error-message trick got me. Entered two cards before I gave up. Cancelled both the next morning, but the article is right — the annoyance is the disguise.
Patricia H. · 6 days ago
How do I check my own exposure? I've had the same email address since 2004 and I assume it's everywhere by now.
J. Whitfield · 5 days ago
There's a free scan linked above that shows what's already out there for your email. Took me under a minute.
Ken O. · 1 week ago
What gets me is the caller ID. Mine showed the bank's actual name. If that can be faked, what's left to trust?
Add a comment
Post comment- ⏱️ Takes about a minute
- 🙅 No sign-up required
- 🔒 100% private
- 💳 Free — no card needed
Sources: FTC Consumer Alerts & Data Spotlights (text scams; $470M reported losses) · Better Business Bureau via CBS Pittsburgh (the 30-cent redelivery fee) · U.S. Postal Inspection Service (USPS sends no unsolicited tracking texts, never with links) · WMAR-2 / NBC4 Washington (Jane Dean, $25,600) · AARP Fraud Wars (Judith Boivin, $595,958) · public r/Scams threads (paraphrased, anonymized). Sponsored consumer-education article (advertorial) for TurtleShield. "Maya K." is a composite reconstructed from documented case patterns and public first-person accounts; Dean and Boivin cases are publicly reported.
This is sponsored consumer-education content (advertorial) and not an actual news article. Composite scenes reconstructed from documented cases and public accounts.