Fake shipment tracking scams are growing rapidly across the Middle East and Africa (MEA), according to new research published by Group-IB on March 30, 2026. The cybersecurity firm identified a coordinated campaign exploiting parcel delivery anxiety to steal banking credentials, personal data, and one-time passwords from residents.
Global parcel volume has surpassed 161 billion shipments annually, creating a large pool of potential victims. Researchers found that the campaign intensified between December 2025 and February 2026, with Egypt and South Africa among the most affected countries in the region.
How the Fake Shipment Tracking Scams Work
The scheme typically begins with an anonymous SMS claiming a delivery has failed or a package has been returned. Victims receive a link urging them to pay handling fees or update their address information. However, the link leads to a phishing page designed to appear as an official courier portal.
Technical analysis by Group-IB reveals that attackers use WebSockets to log keystrokes — including card numbers, CVV codes, and OTPs — in real time as victims type them. This real-time exfiltration method makes the theft nearly instantaneous.
Phishing-as-a-Service Infrastructure Behind the Campaign
Many of the fraudulent sites share infrastructure linked to Darcula, a Phishing-as-a-Service (PhaaS) platform. Darcula offers over 20,000 counterfeit domains and 200 phishing templates, enabling low-skill attackers to launch sophisticated campaigns at scale.
Furthermore, attackers use illegal SMS gateways to merge fraudulent messages into legitimate message threads from trusted postal services. This technique, known as Sender ID Spoofing, makes fraudulent messages nearly indistinguishable from genuine courier communications.
Industries Most Targeted in MEA
Postal and delivery services represent the most frequently abused category in the MEA region. Financial services rank second, followed by telecommunications, mobility services, and e-commerce platforms. The broad reliance on parcel delivery in daily life exposes a wide segment of the population to this threat.
“As online shopping and logistics services are deeply embedded in everyday activities, a broad segment of the population is exposed to this threat.”
Group-IB Research Team
Protective Measures for Individuals and Businesses
Group-IB researchers recommend that individuals never click on tracking links sent via SMS or WhatsApp. Instead, users should manually visit the courier’s official website and enter their tracking number directly. Legitimate delivery companies do not use random mobile numbers or private email addresses.
Moreover, users should treat any message demanding immediate payment for an address update as suspicious. Scammers frequently use low-cost domain extensions such as .xyz, .sbs, .top, and .click. Reporting suspicious messages to local cybersecurity authorities helps protect other potential victims.
For businesses, Group-IB recommends implementing DMARC, SPF, and DKIM email authentication protocols to reduce brand impersonation. Companies should also deploy Digital Risk Protection services to monitor and remove fraudulent domains. Providing a public tracking verification tool on official websites adds an additional layer of consumer protection.
Background on Group-IB
Group-IB was established in 2003 and is headquartered in Singapore. The firm operates Digital Crime Resistance Centers across the Americas, Europe, MEA, Central Asia, and Asia-Pacific. It collaborates with international law enforcement agencies including INTERPOL, Europol, and AFRIPOL.





