1. The documented fact
USPS shipped 6.8 billion packages in fiscal year 2025 — about 18.6 million parcels every single day, across the United States alone. Add UPS, FedEx, Amazon Logistics, and every regional carrier, and the true daily volume of packages in transit at any moment across the US is far higher still. A scam text sent at random, with zero targeting, mathematically lands on an enormous number of people who are, that same week, genuinely expecting a delivery.
2. The probability
This demonstration doesn't calculate the odds of a coincidence being noticed — it explains why a completely untargeted message reliably finds real recipients at scale.
Our calculation — coincidence, not targeting
The principle: with billions of packages moving through the postal and courier system at any given time, the probability that a randomly-selected phone number belongs to someone currently expecting a delivery is far from negligible — and it's the same probability for every single recipient of a mass-blast text.
What the scammer exploits: the scammer never needs your name, your carrier, or your tracking number. A generic "your package couldn't be delivered" text, blasted to millions of numbers, will land — by sheer volume — on hundreds of thousands of people who see it as a plausible coincidence rather than a random guess.
What changes if it knows your name: a message using your actual name, address, or a real order number is a different regime entirely — it means a data leak is involved, not mass probability. See our demonstration on what data leaks change.
Limits: we do not publish a single global conversion probability — that number would depend on campaign-specific data (list size, timing, carrier) that isn't publicly available. What we document is the volume that makes the coincidence reliable at scale, not a precise strike rate.
3. The mechanism
This scenario runs almost entirely on Credible Coincidence — the message arrives at a moment that feels too specific to be random — reinforced by Manufactured Urgency (act now or the parcel is returned) and Small First Step (a tiny redelivery or customs fee that only exists to capture your card details).
4. Across the English-speaking world
This isn't a US-only pattern — every major English-speaking market with high parcel volume reports the same scam as its top (or near-top) text-based fraud category:
United Kingdom
Fake delivery texts — a "missed parcel," a "redelivery fee," an "address problem" — made up more than half of all smishing attempts tracked over a 90-day period, well ahead of bank-impersonation texts in second place.
UK Finance, 2025. 🟡 relayed via industry press, not confirmed by primary citation in this pass.Australia
Australia Post processed over 100 million parcels in a single record Christmas peak period in FY2025, with parcel volumes continuing to grow year on year — the same structural condition (huge, constant delivery volume) that makes the scam work wherever it's replicated.
Australia Post, Annual Report FY2025. 🟡 relayed via industry press summary, not yet confirmed by primary citation.Canada
Canada Post itself publishes an explicit consumer warning distinguishing real delivery notices (a physical card left at your door) from fake emails and texts claiming a failed delivery attempt — an implicit admission of how common the impersonation has become.
Canada Post, official consumer guidance page. Accessed 20/07/2026.United States
Fake package-delivery messages are the single most reported text scam category tracked by the FTC, ahead of fake bank-fraud alerts, toll notices, and job offers.
FTC, "Top text scams of 2024." 🟡 primary page blocked in this pass, corroborated by AARP/FCC.5. The defense
🔗Never tap the link in the text
Open your carrier's official app or website yourself, and check your tracking with your own order number — never through a link received in a message.
💳No carrier asks for a fee by text link
Customs duties, redelivery fees, or address-correction charges are never collected through a payment link sent by SMS. If in doubt, contact the carrier directly through their official number.
🛡️See what single-channel tools miss
A protection that filters SMS and calls together — on the same device — catches the pattern that a text-only spam filter, working in isolation, cannot.
The takeaway
Scammers don't need to know you. The statistics already do.
Frequently asked questions
How do scammers know I'm expecting a package?
In the mass-blast version, they don't. USPS alone shipped 6.8 billion parcels in fiscal year 2025 — a random text lands, by sheer probability, on hundreds of thousands of people who really are expecting a delivery that week.
What should I do if I get a delivery text with a link?
Never tap the link. Open the carrier's official app or website yourself and check your tracking with your own order number.
Why is this the single most reported text scam across the US, UK, and Canada?
Because expecting a parcel is close to universal in a given week in any market with high e-commerce volume — the scam scales with parcel volume, not with targeting effort.
Rigor note. The USPS figure (6.8 billion, FY2025) is confirmed by direct citation from usps.com's official Postal Facts page. The FTC text-scam-loss figure ($470M, 2024) and the UK Finance / Australia Post figures are corroborated across multiple independent sources but their primary pages blocked automated verification in this pass — marked 🟡 accordingly, per our methodology. This page adapts — not translates — the French-language original demonstration (Faux colis, ARCEP data), replacing every figure with market-specific US/UK/AU/CA sources rather than reusing the French statistic.
From leak to scam
What changes when the fake delivery text knows your real name — and why that's a completely different threat than the mass-blast coincidence above.
Learn more
Egidio — The Threat Laboratory, "Why fake package texts work: the probability demonstration", egidio.app/en/laboratoire/mathematics-of-manipulation/fake-package/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.