India Post Delivery Scam SMS: How the Fake Address Update Link Drains Your Bank Account
- The SMS is Fake: India Post never sends SMS alerts asking users to update residential addresses via links or pay online redelivery fees.
- The Threat: Tapping the link either loads a cloned phishing portal that hijacks bank OTPs or triggers an Android APK trojan that intercepts incoming 2FA SMS.
- The Official Standard: Official India Post notifications use registered TRAI DLT headers (e.g.,
CP-INDPOST) and link strictly toindiapost.gov.in. - First Action: Never pay the ₹5 fee. If debited, dial the National Cyber Crime Helpline at 1930 immediately to freeze recipient accounts.
If your phone just pinged with a text message stating your package cannot be delivered due to an incorrect house number or missing street details, you are not alone. During peak shopping events like Flipkart’s Big Billion Days and Amazon’s Great Indian Festival, logistics networks handle upwards of 12 million shipments daily. Fraud syndicates capitalize on this volume by deploying automated smishing (SMS phishing) attacks, with the India Post delivery scam SMS leading the count.
These messages look official, convey manufactured urgency, and frequently trap buyers who have genuine orders in transit. Entering your details or paying a nominal ₹5 redelivery fee can lead to immediate bank account compromise.

The Anatomy of the Attack: What Arrives on Your Device
Smishing campaigns use SIM farms, spoofed gateways, or compromised third-party routing infrastructure to send messages resembling this layout:
While India Post is the primary brand exploited, the same operational templates are mirrored across private carriers, generating related alerts such as a fake blue dart address update link complaint or fraudulent Ekart logistics notices.
The Fraud Vector: Phishing vs. Android Trojan
When a user taps the included link, the scam branches into two distinct exploitation methods depending on the backend infrastructure set up by the attacker.
- Cloned India Post / Courier UI
- Prompts for address + ₹5–₹25 fee
- Real-time automated OTP relay
- Direct download of sideloaded app
- Demands SMS & Accessibility rights
- Silently intercepts 2FA OTPs in background
1. The Spoofed Portal & Real-Time OTP Relay
The URL routes the user to a server hosted on cheap, generic top-level domains (e.g., .top, .icu, .vip, .xyz, or .cc). The site displays an interface that mimics the Department of Posts: familiar red-and-yellow color schemes, national emblems, and an active tracking window.
- Information Harvesting: The site requests your full name, mobile number, full residential address, and postal PIN code.
- The Nominal Fee: To process the “rescheduled attempt,” the portal demands a token charge between ₹5 and ₹25.
- The Interception Engine: When you submit your debit card credentials or UPI details, an automated script behind the scenes passes those inputs into a high-value merchant transaction (often ₹10,000 to ₹50,000) or sets up an auto-debit e-mandate.
- The Screen Mirror: You are shown an OTP submission screen that looks identical to a bank 3D-Secure portal. Thinking the OTP confirms a ₹5 payment, entering the code authorizes the attacker’s high-value transaction instead.
2. The Sideloaded .apk Payload (Android Trojan)
In several variants, tapping the link initiates an automatic download of an application package file, such as IndiaPost_Service.apk or Postal_Tracker.apk.
- The browser warns that the file may be harmful, but the accompanying page instructs the victim to bypass Android’s security warnings.
- Once installed, the malicious package requests RECEIVE_SMS, READ_SMS, and Accessibility Service permissions.
- With accessibility granted, the malware can inspect UI elements, interact with device settings, and grant itself further privileges without user prompts.
- When financial fraud is initiated against the victim’s accounts, the application silently intercepts incoming banking verification OTPs, suppresses notification alerts, and forwards the credentials to an external server or Telegram bot.
Received a Suspicious Link or Courier SMS?
Do not tap unverified URLs. Run any website link, APK download, or parcel alert through our threat database first.
Genuine Postal Protocols vs. Fraudulent SMS Traps
Legitimate logistics carriers adhere to strict operational guidelines under India’s commercial communication framework. Comparing these logistics standards helps verify whether an alert is real.
| Operational Indicator | Fraudulent “India Post” SMS | Authentic Logistics Providers (India Post, Blue Dart, Delhivery) |
| Sender ID / Header | Standard 10-digit mobile number (+91 9xxxx xxxxx) or international country code (+63, +84, +1) | Registered DLT alphanumeric header conforming to TRAI guidelines (e.g., AD-INDPOST, BP-BLDART, VK-EKART) |
| Domain Architecture | Uses external extensions: indiapost-update.top, indiapost.gov.in.services-in.cc | Exclusively hosted on the official national portal: indiapost.gov.in |
| Fee Structure | Demands a ₹5 to ₹25 payment to re-deliver or avoid warehouse returns | No fee. Address corrections and standard re-attempts carry zero online processing charges |
| Delivery Workflow | Threatens immediate return within 12–24 hours | Carriers mandate 3 independent physical attempts across 48 to 72 hours before initiating Return to Origin (RTO) |
4 Technical Rules to Avoid Delivery Phishing
1. Verify Directly Inside Originating Marketplaces
If you purchased items through Amazon, Flipkart, or a direct-to-consumer store, never rely on third-party SMS alerts to monitor transit. Go to your active app, open Your Orders, and check the status directly. If an address issue or delivery failure actually occurred, the merchant platform will display the update and allow modifications directly inside its secured environment.
2. Verify TRAI DLT Headers
Under the Telecom Regulatory Authority of India (TRAI) guidelines, all commercial and transactional SMS messages must be dispatched through Distributed Ledger Technology (DLT) platforms with authorized headers.
- Legitimate commercial headers contain a prefix denoting the access provider and service area, followed by a hyphen and a registered 6-character sender ID (e.g.,
CP-INDPOST). - If a delivery failure notification arrives from a standard 10-digit personal phone number, it has bypassed corporate compliance and is unauthorized.
3. Parse the Domain Name Hierarchy
Scammers often embed legitimate brand names as subdomains within a third-party root domain to mislead users reading quickly on mobile displays.
- Look at the final part of the web address immediately preceding the first single forward slash (
/). - In the string
[https://indiapost.gov.in.reschedule-parcel.top/login](https://indiapost.gov.in.reschedule-parcel.top/login), the actual domain isreschedule-parcel.top. - The true official website for India Post tracking is strictly:
[https://www.indiapost.gov.in](https://www.indiapost.gov.in)
4. Keep Android Unknown App Installations Disabled
Prevent mobile malware payloads from executing by ensuring sideloading permissions remain off. Check your device:
Settings → Apps → Special App Access → Install Unknown Apps
Verify that Google Chrome, WhatsApp, Telegram, and your local file manager are marked as “Not Allowed”.
Incident Response: What to Do If You Clicked or Paid
If you submitted financial information or downloaded an unknown file, fast containment during the initial window is essential for fund recovery.
Step 1: Disconnect and Sanitize Your Device
- If an
.apkfile was installed, enable Airplane Mode immediately to cut mobile data and Wi-Fi connections. - Go to Settings → Apps → All Apps. Look for suspicious entries with generic labels (such as Service, Update, Tracking, or blank names).
- If the Uninstall button is grayed out, navigate to Settings → Security → Device Admin Apps, revoke permissions for the suspicious tool, and proceed with removal.
Step 2: Implement Financial Freezes
- Access your online banking from an alternate device or call your bank’s emergency hotline to permanently block the compromised debit or credit card.
- Reset your primary UPI application PINs (Google Pay, PhonePe, Paytm).
- Request a temporary block on internet banking services if account credentials were submitted on the phishing page.
Step 3: Dial 1930 for the National Cyber Crime Network
The Ministry of Home Affairs operates the National Cyber Crime Helpline: 1930 (formerly known as the Citizen Financial Cyber Fraud Reporting and Management System or CFCFRMS).
- Call 1930 immediately.
- Provide the operator with your full name, phone number, bank name, account number, transaction timestamp, and the 12-digit UPI Transaction ID or Bank Reference Number (UTR / RRN).
- The 1930 infrastructure works alongside major Indian banks, card payment gateways, and wallet providers. It can trigger an inter-bank alert to freeze the fund transfer path across downstream beneficiary accounts before cash is withdrawn at an ATM or moved into mule wallets.
Critical Details Required for Calling 1930 (CFCFRMS)
When reporting financial loss to the 1930 National Cyber Crime Reporting Helpline, speed is paramount. Have these 5 specific data points written down before calling so the operator can immediately initiate an inter-bank freeze across the recipient mule accounts:
- Victim Account Details: Your full name, bank name, account number, and debit card number (last 4 digits).
- Transaction Timestamp: The exact date, hour, and minute the money was debited (as stated in your official bank debit alert SMS).
- Exact Amount Debited: The precise amount in Rupees (e.g., ₹24,999, not “around 25 thousand”).
- The 12-Digit Reference Number (UTR / RRN): The Unique Transaction Reference (UTR) for NEFT/RTGS/IMPS or the Retrieval Reference Number (RRN) found inside your UPI app or bank statement.
- Recipient Identifiers (If Available): The receiver UPI ID (VPA), merchant name, or beneficiary account number shown in your transaction receipt.
Copy-Paste Email Template for Bank Nodal Grievance Officer (RBI 72-Hour Notice)
Important: To preserve your Zero-Liability rights under RBI circular RBI/2017-18/15 DBR.No.Leg.BC.78/09.07.005/2017-18, you must officially notify your bank in writing within 3 working days of the unauthorized transaction.
Copy, fill out the brackets, and email this directly to your bank’s customer care and Principal Nodal Officer:
