The parcel-delay text is the commodity tier of SMS scams. The sophisticated versions exploit shortcode trust, live OTP relay infrastructure, and psychological state manipulation with surgical precision.
Before dissecting the advanced techniques, it's worth understanding why the parcel-delay text has been running successfully for five years with almost no variation. The answer is base rates. At any moment, a meaningful percentage of any country's population is expecting a delivery. The message doesn't need to be targeted — it just needs to hit often enough that recipients self-select into plausibility.
The fake Royal Mail, FedEx, or UPS text works because the attacker is playing a probability game. One in eight recipients just ordered something yesterday. One in fifteen is currently tracking a parcel. The irrelevant ones delete the message. The relevant ones click.
Most UK and Australian mobile operators allow businesses to register an alphanumeric sender ID — so instead of seeing +447700000000, users see HMRC or Barclays or Royal Mail. The problem: these sender IDs are not cryptographically verified. Some carriers check against a registered sender ID database; many don't.
+447700000000
HMRC
Barclays
Royal Mail
This means an attacker who routes messages through certain grey-route SMS providers can send messages with sender ID NatWest without any authorisation from NatWest. The recipient's phone threads this fake NatWest message into the same conversation thread as legitimate NatWest bank messages, because Android and iOS group by sender ID string.
NatWest
Legitimate NatWest SMS (2021): "Your card ending 4821 was used..." Legitimate NatWest SMS (2022): "Login attempt detected..." Fraudulent SMS (today): "Unusual activity. Verify: natwest-secure.app"
All three appear in the same thread. There's no visual signal that the third is different. This is the mechanism behind some of the most successful banking smishing campaigns of the last three years.
Effective smishing doesn't rely on a single urgency signal — it stacks three or four psychological triggers simultaneously:
Threat to existing assets. Loss aversion is more powerful than equivalent gain potential. "Your account will be suspended" or "We've identified a fraudulent transaction" triggers immediate action. The user's mental state shifts from rational evaluation to threat response.
Legitimacy markers. The last four digits of an account number, a name, a postcode. Enough personalisation to make the threat feel specific. This data often comes from prior data breaches available for purchase on forums — knowing someone's email address and phone number is often enough to make a message feel targeted.
Time pressure with a specific window. "You have 2 hours to respond" is more effective than "urgent." A defined deadline prevents the user from sleeping on it or asking a colleague. Attackers have tested these windows — 24 hours is too long, "immediately" feels theatrical, 2–4 hours is the sweet spot.
Friction removal. The link goes directly to a convincing fake login page with all fields pre-populated except the password. Every removed decision point is a conversion opportunity the attacker is claiming.
This is where the industrialisation of smishing becomes clear. Intercepting a username and password is no longer enough for most financial accounts — 2FA via SMS OTP is widespread. The response is OTP relay panels: real-time interception infrastructure that bridges the victim to the attacker's session.
The flow:
The entire relay completes in under 60 seconds. The victim has no indication that anything unusual has happened — the phishing page typically shows a "verification complete" message and redirects to the real bank's login page.
Commercial OTP relay panels are sold as services with monthly subscriptions, branded dashboards, and customer support. The infrastructure is fully industrialised.
Before any link analysis, the message text often contains structural tells:
.app
.info
.link
.uk.co
If a text message contains a link and triggers any sense of urgency about money, accounts, or deliveries, treat it as suspect until proven otherwise. Open the relevant account directly, using the app or a bookmarked URL, not the link in the message.