chat Chat

How the India Post Delivery Scam Works and How to Avoid It

RBL Bank Oct 29, 2024

In today’s digital world, fraudsters are constantly finding new ways to exploit unsuspecting individuals. One of the latest scams involves impersonating India Post, a trusted national postal service, to deceive people into revealing personal information and making payments. This blog will help you understand the details of the scam and provide practical steps to protect yourself and your loved ones.

Understanding the India Post Delivery Scam

The India Post delivery scam is a phishing scam that begins with an SMS or phone call claiming that a package addressed to you could not be delivered due to an incomplete address. The message prompts you to click on a link to update your address within 12 hours. This sense of urgency is designed to create panic and compel you to take immediate action without thinking it through. Once you click the link, you are redirected to a fraudulent website where you are asked to provide personal information and make a small payment for the supposed redelivery of the package.

These scams are becoming increasingly common in India, and many people have fallen victim to them, believing they are interacting with a legitimate service. Fraudsters often disguise their messages and websites to look highly authentic, making it even harder for people to distinguish between real and fake communications.

Modus Operandi: How the Scam Works

Fraudsters use a variety of techniques to gain the trust of their victims. In the case of the India Post delivery scam, they combine phishing tactics with social engineering. Here’s a step-by-step breakdown of how the scam works:

1. The Fake SMS: The victim receives an SMS stating that a delivery attempt was made, but it failed due to an incomplete address. The message includes a link to "confirm" the address and gives the victim a short 12-hour window to act. This limited time frame creates a sense of urgency and pressure.

2. Follow-Up Phone Call: To make the scam more convincing, the fraudster may follow up with a phone call, posing as an India Post representative. They emphasise the importance of updating the address quickly and may even ask the victim to confirm personal details over the phone.

3. The Fraudulent Website: Once the victim clicks the link, they are taken to a fraudulent website that looks similar to the official India Post site. Here, the victim is asked to enter their personal information and make a small payment, typically INR 80 or INR 100, to cover the cost of redelivery. Payment is only accepted via credit or debit card, with no option for UPI or Cash on Delivery, further raising suspicion.

4. Data Theft and Malware: After the payment is made, fraudsters can steal the victim's sensitive information, such as card details, which can be used for unauthorised transactions. Additionally, visiting the fraudulent website may expose the victim's device to malware, which can further compromise personal data.

Key Red Flags to Watch Out For

It’s important to be aware of the warning signs that can help you identify such scams. Here are a few red flags:

  • Unsolicited SMS: If you have not ordered any package or are not expecting a delivery, receiving such a message should immediately raise concerns.
  • Urgency and Pressure: Legitimate organizations rarely, if ever, impose such short deadlines (e.g., 12 hours) for non-critical matters. Scammers use this tactic to panic victims into quick decisions.
  • Small Payments: Scammers often ask for seemingly insignificant amounts like INR 80 or INR 100, hoping that people won’t think twice about paying a small sum. However, even these minor transactions can lead to major financial losses if the fraudsters gain access to your payment information.
  • Card-Only Payments: The lack of UPI or Cash on Delivery options is another red flag. India Post, and most legitimate services, offer multiple payment methods to accommodate various customer preferences.

Precautionary Measures to Stay Safe

To safeguard yourself from such scams, it’s essential to adopt proactive security measures. Here’s what you can do:

  • Verify the Sender: Always check the sender's email address or the website domain before clicking on any links. Fraudulent messages often have slight differences from the official addresses. For example, instead of a legitimate ".gov.in" domain, a scam site might use ".com" or ".net" to deceive users.
  • Avoid Clicking Suspicious Links: Never click on a link in an unsolicited message, even if it appears to be from a trusted organization. Instead, visit the official website directly by typing the URL into your browser.
  • Use Trusted Channels for Verification: If you are unsure about the authenticity of a message or call, contact the organization directly using official customer service numbers listed on their website. Avoid relying on contact information provided in the suspicious message.
  • Enable Two-Factor Authentication (2FA): Ensure that all your financial accounts have 2FA enabled, as this adds an extra layer of security. Even if fraudsters gain access to your account details, they would need an additional code to complete any transaction.
  • Install Security Software: Use trusted antivirus or anti-malware software on all your devices to protect against potential security breaches. Regularly update your software to stay protected against the latest threats.

What to Do If You’ve Encountered the Scam

If you’ve interacted with a suspicious message, clicked on a link, or shared personal details, immediate action is crucial to minimise the damage:

  • Report the Scam: Report the fraudulent message or website to the national cybercrime helpline at 1930 or visit www.cybercrime.gov.in. Your report may help prevent others from falling victim to the scam.
  • Notify Your Bank: If you’ve made a payment or shared your card details, immediately contact your bank to block the card and report the unauthorised transaction. Most banks, including RBL Bank, have dedicated fraud response teams to assist in such cases.
  • Scan Your Device: If you clicked on a suspicious link, scan your device for malware using reliable security software. It’s also a good idea to change your passwords for any online accounts that may have been compromised.
National Cybercrime Reporting Portal

Conclusion

In today’s connected world, scams like the India Post delivery scam are becoming increasingly sophisticated. Fraudsters rely on creating urgency and confusion to trick people into revealing personal information. By staying vigilant, verifying the authenticity of messages, and reporting suspicious activity, you can protect yourself and help others avoid falling victim to these scams. RBL Bank is committed to keeping your personal information safe and urges all customers to exercise caution when receiving unsolicited messages or calls.

Click here to learn more about various types of fraud and how to protect yourself.


Disclaimer: Articles published on the website are merely indicative and suggestive in nature and do not amount to solicitation. The contents do not guarantee the desired returns and/or results. Reader is advised to exercise discretion and consult independent advisors for achieving desired result. Visitors to this blog/ website w.r.t products & services offered by RBL Bank Limited herein, shall ensure that the comments / feedback posted shall be restricted to the contents published herein and shall not contain such language that may be un-parliamentary or against any religion, caste, section of society, political view etc. While our endeavor is to publish the comments that are submitted, however, all comments/feedback shall be subject to internal review by RBL Bank Limited. We do not guarantee that the comments that are submitted will be published.

Tags


A newsletter from RBL Bank

Stay Informed on the most impactful business and financial news with analysis from our team

Archives: