Phish of the Week: Fastway Couriers Impersonation â Parcel Delivery Scam
Attackers are impersonating Fastway Couriers, a real courier service operating across South Africa, with a shipping notification email that leads recipients through a fake customs verification and payment flow, resulting in direct payment card theft.
How the attack works:
The recipient receives an email branded as a shipping notification from Fastway Couriers, sent through Constant Contact, a legitimate email marketing platform. It uses the real parcel delivery company logo, and a festive, Christmas-themed design despite being sent months outside the holiday period. The email tells the recipient their order is on its way and includes a "Track My Order" button repeated throughout the message, alongside delivery guarantee language designed to mirror genuine courier marketing.
Clicking the "Track My Order" link leads to a page titled "Shipment Verification," which claims the recipient's shipment is pending receiver verification and requires action before customs clearance can proceed. The page asks the recipient to enter their full name, city, street address, postal code, and province, framed as mandatory information needed to release the parcel.
After submitting these details, the recipient is shown a "Processing Shipment" screen with a loading animation and fabricated shipment details. This step reinforces the impression that a genuine backend process is verifying the shipment before the recipient can proceed.
The final page presents a "Customs Payment" request for a small fee, framed as a mandatory customs clearance duty. It asks for full card information, giving attackers everything needed to make fraudulent charges on the recipient's card.
Why the attack works:
Each step of this attack reinforces the one before it. Sending the email through a legitimate third-party email platform helps the message bypass spam filters and appear in the inbox with fewer of the technical red flags that untrusted sending infrastructure would normally trigger.
The small payment amount is a deliberate choice. A fee this size feels low-risk, so recipients are less likely to pause and question the request the way they might for a larger sum.
The multi-step structure also works against the recipient's instinct to verify. By the time the payment page appears, the recipient has already entered personal information and watched a "verification" process complete, making it feel like they are simply finishing a process already in motion rather than starting a new, suspicious one.
How to spot similar attacks:
- The shipping notification is unsolicited and does not correspond to a parcel the recipient is actually expecting
- A Christmas-themed design appears months outside the holiday period, with no connection to an actual gifting or delivery season
- Status labels like "Pending receiver verification" are used to imply an official process without any account-specific detail
- A loading or "processing" screen displays generic shipment details rather than information tied to an actual order
- Payment or personal details are requested through a form hosted on a domain unaffiliated with the courier's official site
What is Phish of the Week?
Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.