The DNSC has renewed its warning about an active scam via text message and WhatsApp carried out in the name of courier companies—here's how it works and what simple rule keeps your team safe.
The National Cyber Security Directorate (DNSC) is once again drawing attention to a fraud campaign that uses text messages and WhatsApp messages sent in the name of well-known courier companies. According to Bitdefender data cited by the DNSC, over one million Romanians have been targeted by such messages. The scheme does not exploit any technical vulnerabilities—it relies solely on the recipient’s haste and trust.
The message is designed to seem legitimate: it states that a package is held at the warehouse, that delivery cannot be completed, or that a small fee still needs to be paid, and it includes a link. The link leads to a fake page, carefully copied from the courier’s real website, where the victim is asked to provide personal information and, most importantly, credit card details to “pay the fee.” Once entered, this information goes directly to the attackers.
For a company, the risk isn't just personal. Employees receive these messages on their work phones, and just one person entering their card information on a fake website can create a security breach—especially if that same phone also contains their work email, company apps, or access to shared accounts. A fraud that seems like a minor, personal incident can thus also compromise the company’s data.
This safety tip can be summed up in a few words and is easy to remember: no courier company will ever ask you to pay a fee via a link sent in a text message or on WhatsApp. If you’re actually expecting a package and receive a message like this, don’t click the link. Open the courier’s app yourself or type the website address into your browser and check the package’s status there, through the official channel.
If an employee has already entered their card information on such a page, the bank must be called immediately to block the card, and the incident can be reported to the DNSC. The five minutes you spend explaining this rule to your team are worth much more than they seem: they turn a well-crafted scam into a message that anyone can recognize and delete.
Sources:
- DNSC / Bitdefender (via Go4it) | https://www.go4it.ro/securitate-informatica/alerta-de-securitate-cibernetica-peste-un-milion-de-romani-vizati-de-mesaje-false-regarding-package-delivery-19284420
- Newsweek Romania | https://newsweek.ro/actualitate/peste-un-milion-de-romani-prinsi-in-capcana-coletelor-escrocii-le-au-cerut-bani-prin-mesaje-false
This article was generated with AI assistance.