www.malwarebytes.com 18 Sept 2026, 07:44 UTC

Fake bpost Sites Demand €4.95 While Stealing Banking Details

Fake bpost Sites Demand €4.95 While Stealing Banking Details
CyberSIXT Evidence Panel Source marked as original reporting

A parcel-delivery phishing campaign is impersonating courier services worldwide, including Belgium’s bpost, to steal personal and financial information. In the campaign analysed by Malwarebytes, emails claimed a package could not be delivered because €4.95 in customs duties had not been paid. The small fee was intended to make the request seem credible, while the linked website collected far more valuable information.

The link first passed through the URL-shortening service `hxxps://qr[.]paps[.]jp/1GWsa` before redirecting to fake bpost domains, including `bpost[.]center` and `bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/`. The fraudulent pages copied bpost branding and displayed invented assurances such as “256-bit SSL” and “SEPA compliant”. They requested a name, phone number, email address and age, followed by an IBAN, card number, expiry date and payment amount.

Malwarebytes also found a mistranslated button labelled “Indian search” instead of “Betaal” (“Pay”), although it warned that other phishing pages may contain no obvious errors. Stolen card details could be used for fraudulent purchases or sold, while the wider information could support later scams.

People should verify delivery claims through the courier’s official app or website, rather than using message links, and check both the sender and destination domain. Anyone who submitted banking details should contact their bank or card provider immediately, freeze the card if possible, monitor accounts for unfamiliar transactions and change any password entered on the site.

View full article

Article by CyberSIXT