Parcel delivery messages feel ordinary now. Singapore households shop through marketplaces, SMEs send products by courier, and many people expect daily updates from logistics providers. That familiarity is exactly why courier phishing scams work: the message arrives when the recipient is already expecting something, and the requested fee is small enough to feel harmless.
The latest courier iMessage phishing wave deserves attention because it is not simply an old SMS scam with a new coat of paint. SPF's July 2026 advisory described messages sent through Apple iMessage, foreign-number senders and random email addresses, with links that mimic courier websites. The scam is designed to bypass the mental checks many people reserve for banking messages. It says the parcel address is invalid, delivery has failed, or a small redelivery fee is due. The victim clicks, enters details, approves a transaction, and only later discovers unauthorised card or bank activity.
This article explains how the courier iMessage phishing scam works in Singapore, why Apple users and frequent online shoppers are being targeted, what SMEs should teach staff who handle deliveries, and what to do if you have already entered your card details. The core rule is simple: do not treat a tiny fee as low-risk when the payment page is reached through an unsolicited link.
How This Scam Works in Singapore
The scam usually begins with a message that appears to come from a courier company. The brand name may be familiar: SingPost, Ninja Van, J&T Express, DHL or another logistics provider used by Singapore shoppers and SMEs. SPF reported that some messages came from numbers with the +212 country code or from email addresses made of random letters and numbers, yet the body of the message was written to look like a normal delivery update.
The hook is urgency. The message says the parcel cannot be delivered because the address is invalid, incomplete or requires confirmation. The recipient is told to update the delivery address within 24 hours, reply with a letter to receive a link, or open a separate link. These steps create a small sense of procedure. It feels less like a demand and more like a routine customer-service correction.
Once the victim clicks, the phishing page closely resembles the courier's website. It may use colours, layout, parcel icons and domain names that are near enough to look legitimate on a mobile screen. The page then asks for a small redelivery or handling fee. SPF noted examples of fees ranging from a few cents to less than two dollars. That tiny amount is strategic. Victims are less likely to question a 60-cent delivery charge than a S$600 transfer.
The real target is not the fee. The real target is the card number, expiry date, CVV, personal details and one-time authentication step. Victims may be asked to approve the transaction with their digital token. In some cases, SPF said victims' credit cards were subsequently added to Google Pay or Apple Pay without their knowledge. That changes the risk profile completely: a one-dollar payment attempt can become a channel for repeated unauthorised transactions.
For Singapore SMEs, the same pattern can hit finance, admin and operations staff. A company may be expecting courier deliveries, replacement devices, marketing materials, customer returns or supplier samples. A busy employee may treat the message as a low-value logistics issue and use a corporate card to clear the supposed fee. The exposure is then not just personal money; it may include business card limits, customer data, delivery records and internal processes.
The scam also exploits a blind spot in Singapore's anti-scam habits. Many residents know to be cautious about bank SMSes and government impersonation calls. Fewer people apply the same caution to delivery updates. Scammers understand this. They choose a situation where clicking feels normal, payment feels small, and delay feels inconvenient.
Real-World Impact and Statistics
SPF warned on 15 July 2026 that at least 43 cases had been reported since 24 June 2026, with total losses above S$259,000. At least 20 reports were lodged on 13 July alone, showing how quickly a phishing wave can spike when the same template reaches many recipients.
The situation escalated further in early August. Recent Singapore coverage reported more than S$1.2 million lost since 24 June across at least 251 courier iMessage phishing cases. That jump matters because it suggests the scam remained active after the initial advisory and continued to find victims despite public warnings.
Courier phishing sits within a broader phishing problem. ScamShield highlights phishing scams as one of Singapore's major scam threats, with S$39.9 million lost through phishing scams in the latest public figures on its website. ScamShield also currently warns users about scammers impersonating delivery companies and sending messages that lead to fake sites asking for personal details.
CSA Singapore's latest cyber landscape update adds useful context. CSA reported about 4,800 phishing attempts in Singapore in 2025, down from about 6,100 in 2024, but also warned that AI is making phishing lures more convincing, scalable and harder to dismiss at a glance. Even when total phishing attempts fall, the remaining attacks can become more polished, more targeted and more effective.
MAS has also placed scam prevention into the financial sector's shared responsibility framework and broader anti-scam measures. For consumers, this means banks and payment providers have duties around controls such as transaction alerts and risk monitoring. It does not mean victims can ignore warnings or approve suspicious payment requests without consequence. In phishing cases, the victim's own authorisation step often becomes the critical moment.
Legally, these scams may involve several areas of Singapore law depending on the conduct: cheating and dishonestly inducing delivery of property, unauthorised access or misuse of computer systems, personal data misuse, and money mule offences when stolen funds are routed through local accounts. The Computer Misuse Act is relevant when criminals gain unauthorised access to accounts or systems. The PDPA is relevant for organisations that mishandle personal data or fail to protect customer information, although the primary criminal act here is the scammer's deception.
The target groups are broad. Frequent online shoppers are obvious targets, especially around sales periods. Seniors may be vulnerable if they are less familiar with iMessage sender behaviour or domain spoofing. Young adults may be vulnerable because they transact quickly on phones and are used to paying small app-based fees. SMEs are vulnerable because courier messages often blend into normal operations.
How to Protect Yourself
Start with the channel. Courier companies in Singapore generally use official app notifications, registered sender IDs, email from known domains, direct calls, SMS or WhatsApp from delivery personnel. SPF has specifically warned about courier impersonation through Apple iMessage. Treat courier-related iMessages from unknown numbers, foreign numbers or random email addresses as suspicious until verified through another channel.
Check the link before you tap. A fake courier domain may add extra words, change one letter, use a strange country domain, or place the courier name before an unrelated domain. On a phone, criminals rely on the fact that people see only part of the URL. Do not rely on the logo or page design. Type the courier's official website into your browser, use the courier's official app, or check the tracking number from the original seller platform.
Do not pay redelivery fees through unsolicited links. If a courier says payment is required, verify it through the courier's official app, website or customer service line. For online marketplace purchases, check the order page inside the marketplace rather than a link from a message. If the parcel is cash-on-delivery or has legitimate GST or handling requirements, the courier should be able to explain it through official channels.
Use ScamShield actively. Install the ScamShield app, use its checking features, and call the ScamShield Helpline at 1799 if you are unsure. ScamShield's ACT framework is useful: Add security features, Check for scam signs with official sources, and Tell authorities, family and friends. For courier phishing, "Check" is the most important step because one independent verification can break the scam chain.
Strengthen card and banking controls. Enable transaction notifications, set lower card limits for online spending, disable overseas card usage when not needed, and use virtual cards or low-limit cards for online purchases if your bank offers them. Set PayNow and internet banking limits based on real need, not maximum convenience. Turn on multi-factor authentication and never approve a transaction you did not initiate on an official site.
For Apple users, remember that iMessage is not proof of legitimacy. A blue bubble only shows the message used Apple's system. It does not prove the sender is a courier, a bank or a government agency. Treat unknown iMessage delivery alerts the same way you would treat a suspicious email.
For SMEs, write a simple internal rule: staff must not enter corporate card details through links in courier messages. Delivery issues should be checked through the original order system, the supplier, or the courier's official portal. Corporate cards should have spending limits, alerts and named owners. A second person should review any unusual payment request, even if the amount is small.
What to Do If You Are Targeted
If you received the message but did not click, take a screenshot, block the sender, and report it through ScamShield. Do not reply, even if the message asks you to reply with "Y" or another letter. Replying may confirm that your number is active.
If you clicked but did not enter details, close the page immediately. Clear the browser tab, avoid downloading anything, and run a security check on your device if you are worried. Do not return to the link to "check again"; phishing pages are designed to become more persuasive the longer you engage.
If you entered card details or approved a transaction, call your bank immediately using the number on the back of your card or the bank's official app. Ask the bank to block or replace the card, review recent transactions, remove unauthorised Apple Pay or Google Pay tokenisation if suspected, and activate any fraud controls available. Speed matters because stolen card details can be tested or used quickly.
If money has been lost, call the ScamShield Helpline at 1799 for guidance and make a police report. For urgent police assistance, dial 999. You can also provide scam information through SPF's I-Witness portal or the Police Hotline at 1800-255-0000 where appropriate. Keep screenshots, sender details, links, bank transaction references, device notifications and any courier tracking information.
If you used a corporate card or device, inform your employer immediately. The company may need to freeze the card, notify finance, review other staff messages, check whether customer or supplier information was exposed, and preserve evidence. For SMEs, silence is expensive. A small fake redelivery fee can become an accounting, cybersecurity and customer-trust issue.
If you entered passwords reused elsewhere, change them immediately from a clean device. Enable multi-factor authentication where available. If the phishing page requested Singpass, bank login or email credentials, treat it as high risk and contact the relevant institution.
Common Mistakes to Avoid
The first mistake is assuming small payments are safe. Scammers use tiny fees because the fee is bait, not the prize. The card credentials and authentication step are what matter.
The second mistake is trusting a familiar brand name in the message. Anyone can type "SingPost", "DHL", "Ninja Van" or "J&T Express" into a phishing message. The brand name is not verification.
The third mistake is judging a mobile site by appearance. Phishing pages can copy layouts and images well enough to pass a quick glance. Verification should be based on the domain, source channel and official app or order record.
The fourth mistake is approving a bank prompt without reading it. If your banking app asks you to approve a transaction, card tokenisation or account action that you did not start through an official channel, stop immediately.
The fifth mistake is waiting to see whether more transactions appear before calling the bank. Once card details are exposed, the right response is immediate containment, not observation.
The sixth mistake is treating courier phishing as only a consumer issue. SMEs that ship goods, handle returns or receive supplier samples may have more frequent courier interactions and larger card limits. They need process controls, not just staff awareness posters.
FAQ
Are courier companies in Singapore really using iMessage for delivery payments?
You should not assume so. SPF has warned specifically about phishing scams impersonating courier companies through Apple iMessage. If payment or address confirmation is requested, verify through the courier's official app, official website, original seller platform or customer service line.
Why do scammers ask for such a tiny redelivery fee?
The small amount lowers your guard. The scammer wants your card details, personal information and transaction approval. A fee below S$2 can still expose you to far larger unauthorised transactions.
What should I do if my card was added to Apple Pay or Google Pay without permission?
Call your bank immediately. Ask the bank to block the card, remove unauthorised digital wallet tokens, review recent transactions and issue a replacement card if needed. Preserve screenshots and make a police report if money was lost.
Can ScamShield check courier phishing links?
ScamShield provides checking and reporting features, and the 1799 helpline can guide you if you are unsure. You should still verify directly with the courier or seller instead of relying on any single tool.
Are iPhones safe from phishing scams?
iPhones have security features, but phishing is mainly a deception problem. If a victim voluntarily enters card details and approves a transaction on a fake site, the device being an iPhone does not remove the risk.
What should SMEs tell employees about courier scam messages?
Tell staff never to enter corporate card details through links in courier messages. Delivery problems should be checked through the original order record, supplier contact, official courier portal or finance team. Corporate cards should have alerts and sensible limits.
Which Singapore agencies are relevant if I fall victim?
For immediate uncertainty, call ScamShield at 1799. For urgent police help, call 999. Report fraudulent transactions to your bank immediately. For cyber incidents affecting a business system, SingCERT under CSA may also be relevant.
Conclusion
Courier iMessage phishing scams work because they hide inside ordinary routines. A failed-delivery alert, a familiar courier name and a tiny redelivery fee can feel too mundane to question. That is the trap.
Singapore residents and SMEs should treat unsolicited courier payment links as suspicious by default. Verify through official courier channels, keep banking controls tight, use ScamShield, and respond quickly if card details have been exposed. The fastest way to defeat this scam is also the least glamorous: pause, check the source, and refuse to pay through a link you did not request.