Blindfy — Digital Protection

Fake bank SMS: anatomy of the delivery scam

How "package held at the post office" texts feed mass banking fraud.

Audience: Professionals and Personal Brands · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

A professional receives an SMS from the "post office" asking for R$ 4.80 to release a package. After clicking and paying, the card is cloned and used for high-value purchases within minutes.

How the scam works

Attackers use phone lists obtained from leaks to blast SMS messages with a short link leading to a cloned bank or postal page that captures card data and CVV.

Common mistake

Trusting the bank's logo and name in the message without validating directly in the official app.

Impact

Direct loss of the card limit, a slow dispute with the bank and emotional strain for the professional.

What works

Continuous education, validating only through the official app and preventive blocking of suspicious short domains.

Protection checklist

  • Never click billing links in SMS
  • Validate deliveries in the official postal app
  • Set up card transaction alerts
  • Block the card immediately in case of fraud
  • Report the SMS to the telecom regulator
  • Save screenshots as evidence
  • Educate family members about the scam pattern

Editorial sources

The cheapest scam is the one that works best. Study the pattern before it finds you.

← All risk analyses · Blindfy initial assessment