Fake bank SMS: anatomy of the delivery scam
How "package held at the post office" texts feed mass banking fraud.
Audience: Professionals and Personal Brands · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
A professional receives an SMS from the "post office" asking for R$ 4.80 to release a package. After clicking and paying, the card is cloned and used for high-value purchases within minutes.
How the scam works
Attackers use phone lists obtained from leaks to blast SMS messages with a short link leading to a cloned bank or postal page that captures card data and CVV.
Common mistake
Trusting the bank's logo and name in the message without validating directly in the official app.
Impact
Direct loss of the card limit, a slow dispute with the bank and emotional strain for the professional.
What works
Continuous education, validating only through the official app and preventive blocking of suspicious short domains.
Protection checklist
- Never click billing links in SMS
- Validate deliveries in the official postal app
- Set up card transaction alerts
- Block the card immediately in case of fraud
- Report the SMS to the telecom regulator
- Save screenshots as evidence
- Educate family members about the scam pattern
Editorial sources
- Banco Central do Brasil — Orientações oficiais sobre golpes e Pix
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
The cheapest scam is the one that works best. Study the pattern before it finds you.