A delivery text asking you to pay fees, confirm an address or follow a shortened link may be smishing, meaning phishing by text message. Do not follow the link or call a number provided in the message. Report suspicious texts through 33700, the French reporting service. If you have already entered credentials, change the affected passwords. If you entered card details, contact your bank immediately through a trusted channel.
This guide explains how to recognise parcel scams in France, respond in three steps, and understand why your number may already be circulating after a data breach.
At a glance
- Parcel smishing uses a fake Chronopost, Colissimo, DHL or customs message and a malicious link.
- Three precautions: do not click, do not pay through the message, and never disclose verification codes, including bank codes.
- Report the text to 33700. Its website also provides an online reporting form.
- Your number may come from a breach, a broker or another source. Reducing public exposure can limit how easily it is reused.
How to recognise a fake delivery text
Common warning signs include:
- an unknown sender, foreign number or generic sender name;
- manufactured urgency, such as a final deadline, a returned parcel or a fine;
- a shortened link or domain that does not match the carrier's official website;
- mistakes or an awkward mix of languages;
- a request for a card payment, cryptocurrency or bank transfer to release a parcel.
Real carriers sometimes send texts too. If you are unsure, check tracking through their official website or app, opening it yourself rather than using the message's link.
What to do in three steps
- Stop. Do not click, reply or call the number in the text.
- Check independently. If you expect a parcel, open the retailer's or carrier's app, or type its website address yourself.
- Report and block. Report the text through 33700, block the sender and delete the message after keeping any evidence you need.
If you clicked or entered information
- Clicked only: close the page, check whether anything downloaded, update your phone and use its security tools where available. A click does not by itself prove that the phone is infected.
- Entered a password: change it through the genuine service, change it wherever you reused it and enable two-factor authentication.
- Entered card details: call your bank immediately, using the number on your card or its official app, not a number from the text.
- Shared a bank verification code: treat this as a potential ongoing fraud. Contact the bank urgently and report the incident to the police where appropriate.
Read what to do about a leaked password in five minutes if you use the same password elsewhere.
Why you receive these messages
Scammers use phone number lists obtained from breaches, brokers or stolen databases. They also send messages widely. Receiving one does not establish which source supplied your number, and you do not need to have ordered anything recently to be targeted.
Useful next steps:
- Check known breaches affecting your email with Have I Been Pwned. Available checks do not cover every leak or every phone number.
- Reduce public exposure by removing broker listings. For marketing calls in France, see the steps for unwanted calls and texts.
- Run a free scan of your public web footprint, brokers and known breaches.
Remember: parcel smishing relies on the fear of losing a delivery. An unexpected payment request deserves an independent check with the carrier, even if the message looks convincing.
How this relates to your digital footprint
These campaigns target millions of numbers. Removing your number and identity from public directories and people search sites reduces the information available for reuse. It cannot remove copies already stolen or stop all scams. Once you have reviewed your scan, you can request removal from the sources you select.
For a broader view of protection, scams and personal information, read the digital footprint and GDPR guide.
See also: Spam after a breach · Namesakes and identity confusion · Check for a data breach · Leaked passwords · The right to object



