USPS fake delivery scam uses QR codes and bogus ZIP code claims to steal personal data

,
 May 1, 2026

Customers across the country are receiving fraudulent notices claiming the U.S. Postal Service failed to deliver their packages, and cybersecurity experts say the scam has gotten more sophisticated, using QR codes and phony ZIP code errors to harvest payment details, login credentials, and personal information.

The scheme works like this: a message arrives telling the recipient that USPS tried to deliver a package but couldn't because of an "invalid ZIP code." The notice urges the customer to scan a QR code or click a link to reschedule delivery. Anyone who follows those instructions lands on a fake site designed to look official, and gets prompted to hand over sensitive data.

Online safety firm McAfee flagged the tactic as the latest upgrade to a common scam that steals personal information. The company shared an example of the fraudulent notice, which reads: "Delivery attempt failed, action required. We have received your package at a USPS facility. However, we were unable to complete delivery due to an invalid ZIP code."

The language is deliberately bland and official-sounding. That's the point. It mimics the kind of routine notification millions of Americans receive from legitimate carriers every day.

How the scam hooks its victims

McAfee experts offered blunt advice for anyone who gets one of these messages:

"If you receive something like this, pause. Do not scan the code."

The warning is simple, but the threat behind it is not. The QR code redirects users to a site that requests credit card numbers, passwords, or other personal details under the guise of confirming delivery information. Once entered, that data goes straight to the fraudsters running the operation.

McAfee advised customers to go directly to the official USPS website to check the status of any package rather than trusting a link or QR code embedded in an unsolicited message. That one step, typing the address yourself instead of scanning a stranger's code, is the difference between checking on a parcel and handing your financial life to a criminal.

This kind of fraud is not new, but the scale and coordination behind it have grown far beyond what most consumers imagine. It's no longer a lone grifter sending out a few hundred texts from a burner phone.

A massive, organized smishing operation

A security researcher named Grant Smith pulled back the curtain on just how large these USPS-impersonation campaigns have become. Smith investigated a fake USPS delivery text, then hacked into the scammers' own infrastructure and collected evidence he turned over to USPS investigators and a U.S. bank. What he found was staggering: 1,133 fraudulent domains tied to the campaign, with 438,669 unique credit cards entered and more than 1.2 million pieces of victim information collected.

Read those numbers again. Nearly half a million credit card entries. More than a million pieces of stolen data. All funneled through fake websites dressed up to look like the Postal Service.

Cybersecurity firm Resecurity identified the group behind the operation as the "Smishing Triad," which allegedly sells a ready-made smishing kit on Telegram and sends an estimated 50,000 to 100,000 scam messages daily. The United States Postal Inspection Service confirmed that Smith's information "is being used as part of an ongoing investigation."

The sheer volume tells you this is an industrial-scale fraud ring, not a cottage industry. And the fact that the kit is sold on Telegram means any low-level criminal with a few dollars and a phone can spin up a new campaign overnight.

A pattern Americans should recognize

The USPS delivery scam fits a broader pattern of government-impersonation fraud that has accelerated in recent years. The IRS has warned about AI-powered tax scams that exploit filing-season anxiety in much the same way these fake delivery notices exploit package-tracking habits.

Criminals understand that Americans trust official-looking communications from federal agencies. They exploit that trust ruthlessly. A message that says "USPS" or "IRS" or "Social Security Administration" triggers a reflexive response, people click before they think.

Retirees and older Americans are especially vulnerable. Social Security imposter email scams have surged, using the same playbook: an urgent-sounding message, an official logo, and a demand for immediate action.

The common thread in all of these schemes is that the criminals are betting you won't slow down long enough to verify. They manufacture urgency, a failed delivery, an overdue tax payment, a suspended benefit, and count on you to react instead of investigate.

What USPS customers should do

McAfee's guidance boils down to a few commonsense steps. Do not scan QR codes from unsolicited messages. Do not click links in texts or emails claiming to be from USPS. Go directly to the official USPS website and enter your tracking number there. If you don't have a tracking number, you probably don't have a package waiting.

The IRS recently updated its "Dirty Dozen" list of tax scams, and consumer fraud warnings from federal agencies have become a near-constant drumbeat. That drumbeat exists because the problem keeps growing.

Several open questions remain. It is unclear exactly when McAfee issued its latest warning, how the fake notices are delivered, whether by text, email, or physical mail, and how many customers have been targeted in the current wave. USPS itself has not issued a public statement about this specific iteration of the scam, at least not one cited in the available reporting.

What is clear is that the infrastructure behind these attacks is massive, well-funded, and constantly evolving. The Smishing Triad's Telegram-based kit means new domains can replace shut-down ones almost instantly, turning enforcement into a game of whack-a-mole.

Meanwhile, USPS has been busy issuing warnings of its own on other fronts, but the agency's silence on this particular scam wave, or at least the absence of a visible public response, leaves customers relying on private-sector cybersecurity firms for guidance.

That gap matters. When criminals impersonate a federal agency at industrial scale, the agency itself ought to be the loudest voice in the room telling Americans what's real and what isn't.

The bottom line is older than the internet: if a stranger hands you a code and tells you to scan it right now, the only smart move is to put your phone down and verify for yourself. Urgency is the con artist's oldest friend.

About Alex Tanzer

Become Wealthier... 
In Just 5 Minutes Per Day

Subscribe to Capital Digest and get fast, actionable insights on markets, money, and opportunity — straight to your inbox.