Skip to content

Alert · Phishing & Impersonation

parcel-customs-settle.example.com scam alert: Parcel Customs Settlement (courier impersonation)

Business named in this report

Critical$38,600 reported lost
Company name
Parcel Customs Settlement (courier impersonation)
Opened Jul 19, 2026Updated 1 mo agoPhishing & Impersonation

A courier impersonation kit delivered by SMS, claiming a parcel was held pending a small customs fee. The payment page harvested full card details and then a one-time passcode in real time, which was used to enrol the card in a mobile wallet. Reported card losses reached $38,600 across 22 people, most of it spent within an hour of the code being entered.

Critical: Payment evidence on file, nothing delivered, and nothing refunded. Assume anyone reaching you with these details belongs to the same operation.

Do not wire funds to parcel-customs-settle.example.com. If anyone using the details on this page asks for payment before you are holding documents you can independently check, stop the transaction — the same numbers and addresses reappear behind new company names.

Sample recordAn illustrative alert used while the live intake feed is being connected. The domain belongs to the reserved example.com documentation namespace and does not name a real business.

Indicators

Objective, checkable findings behind this severity level

  • Customs fee requested is deliberately trivial, between $1 and $3, to lower scrutiny
  • Domain registered eleven days before the first reported loss
  • Page requests a one-time passcode after the card details, which no courier ever needs
  • Lookalike domain uses the courier's brand as a subdomain prefix, not as the registered domain
  • Card is enrolled in a mobile wallet within minutes and spent at high-value retail
  • Kit rotates domains every few days while keeping identical page markup

Sequence

What happened, in order

  1. Jul 8, 2026

    Domain registered

  2. Jul 14, 2026

    SMS campaign begins

    Bulk send across multiple carriers using rotating sender IDs.

  3. Jul 16, 2026

    First reported loss

    $2.10 'fee' followed by $4,200 in wallet transactions within 40 minutes.

  4. Jul 19, 2026

    First alert filed

  5. Aug 2, 2026

    Registrar notified

    Abuse report filed with the registrar and the hosting reseller.

  6. Aug 15, 2026

    Host suspended

    Hosting account suspended; near-identical domains remain in rotation.

Reported accounts

First-hand descriptions from people who paid. Names are shortened at the reporter's request.

Marcus

New South Wales, AU

$4,200

Was expecting a delivery, so the message did not seem unusual. Paid a $2.10 customs fee, then entered a code that arrived by SMS. Within forty minutes there were three contactless transactions at electronics retailers in another state. The bank confirmed the card had been added to a mobile wallet on an unrecognised device.

Payment route
Card details and passcode
Date paid
Jul 16, 2026

H.N.

Auckland, NZ

$2,650

Noticed the domain looked wrong only after entering the details. Called the bank within fifteen minutes, which limited the loss to two transactions.

Payment route
Card details and passcode
Date paid
Jul 21, 2026

Evidence log

What was checked and what it showed

  • Domain age at first loss

    whois

    8 days. Registered 2026-07-08, first reported loss 2026-07-16.

  • Pixel-identical clone

    content

    Markup and assets match the courier's real tracking and payment pages.

  • Passcode harvesting

    communication

    The page requests a one-time passcode after card entry and relays it to an operator in real time.

  • Kit rotation

    hosting

    Fourteen sibling domains served identical markup from the same hosting range.

Identifiers on record

Contact points, wallets, and payment details as reported

Domain

  • parcel-customs-settle.example.com

Operator name

  • Parcel Customs Settlement (courier impersonation)

Aliases used

  • Global Parcel Settlement
  • Courier Fee Portal

Approach platforms

  • Bulk SMS
  • Messaging app forwards

Handles & accounts

None on record

Wallet addresses

None on record

Phone numbers

  • Sender IDs rotated across 40+ alphanumeric SMS headers

Email addresses

None on record

Addresses claimed

None on record

Payment routes requested

  • Card details harvested directly
  • Wallet enrolment using a stolen one-time passcode

Bank beneficiaries (masked)

None on record

Assets copied from

  • A national courier's tracking and payment pages, pixel for pixel

Related domains

  • parcel-fee-settle.example.com
  • courier-hold-release.example.com

Bank and card numbers are published in masked form only. Full details are retained for law enforcement requests and are not disclosed publicly.

Frequently asked: parcel-customs-settle.example.com

The questions people search before they pay, answered from this record

Is parcel-customs-settle.example.com a scam or legitimate?

parcel-customs-settle.example.com, operating as Parcel Customs Settlement (courier impersonation), carries a severity of "critical" in the Scam Alerted feed — payment evidence on file, nothing delivered, and nothing refunded. Assume anyone reaching you with these details belongs to the same operation. A courier impersonation kit delivered by SMS, claiming a parcel was held pending a small customs fee. The payment page harvested full card details and then a one-time passcode in real time, which was used to enrol the card in a mobile wallet. Reported card losses reached $38,600 across 22 people, most of it spent within an hour of the code being entered. This alert was first published Jul 19, 2026 and last updated Aug 15, 2026.

How much has been reported lost to Parcel Customs Settlement (courier impersonation)?

$38,600 across 22 reporting parties who supplied payment evidence. Read that as a floor, not a total: this figure counts only losses backed by documents we have seen, so it can move in one direction as further reports arrive.

When was parcel-customs-settle.example.com registered?

The domain was registered Jul 8, 2026 through Registrar with automated bulk provisioning, making it about 2 months old. Genuine phishing and impersonation operators do not run a business of this size on a domain that new, so registration age alone is a significant warning sign.

What address and contact details does Parcel Customs Settlement (courier impersonation) use?

Buyers were dealt with by phone on Sender IDs rotated across 40+ alphanumeric SMS headers. The website is parcel-customs-settle.example.com. Related domains on record: parcel-fee-settle.example.com, courier-hold-release.example.com. These are published so that anyone searching a number, an address, or a domain before paying finds this record first. An address or phone number shown on a website is not proof that a business trades from it — verify it against the state business register and independent imagery before you send funds.

How did Parcel Customs Settlement (courier impersonation) ask people to pay?

Reported payment routes: Card details harvested directly, Wallet enrolment using a stolen one-time passcode. All of these rails move funds without buyer protection or reversal rights.

What other identifiers has this operation used?

Brand names and aliases: Global Parcel Settlement, Courier Fee Portal. Phone numbers: Sender IDs rotated across 40+ alphanumeric SMS headers. Searching these identifiers is usually what links a brand-new site to an operation already on record.

Can I get my money back after paying parcel-customs-settle.example.com?

The window is set by the rail you paid on, and it starts closing the moment the payment settles rather than the moment you realise. A wire is the narrowest: while the funds are still sitting in the receiving account, your bank can ask the beneficiary bank to send them back, which is why the first call is your own bank's fraud line and not the seller. Card and PayPal goods-and-services payments carry a formal dispute route that stays open for weeks. Cryptocurrency has none at all. Once your bank has opened a recall, file with your national fraud body so investigators can approach the receiving institution independently of you. Anyone who contacts you afterwards offering to recover the money for a fee up front is running a second attempt on the same victim.

If you already paid

Act on the payment route first, the paperwork second

  1. Call your bank or card issuer now and ask for a recall, indemnity claim, or chargeback. Odds fall sharply after the first 24 to 72 hours.
  2. Send nothing further. Withdrawal taxes, liquidity fees, compliance deposits, and unlock payments are all the same scheme continuing.
  3. Secure your accounts — change passwords, revoke active sessions, re-enrol two-factor, and revoke any wallet token approvals you granted.
  4. Preserve everything, then file with your national fraud body and refuse every recovery agent who contacts you afterwards.
Full recovery guide

Elsewhere in the feed

Other active alerts

Browse the full feed
Critical

Superior Equipment & Rental

superiorequipandrent.com

A buyer reports losing $26,000 to Superior Equipment & Rental of Sheldon, Iowa, on a 2017 Kubota SVL95-2s compact track loader advertised at superiorequipandrent.com/listing/2017-kubota-svl95-2s. What makes the account checkable is the paperwork rather than the sale. A used machine crossing state lines normally generates an invoice naming a legal entity, a bill of sale carrying the machine PIN, a lien search, a bill of lading against a carrier with an MC number, and a cargo insurance certificate. By the reporter's account, not one of those documents was ever issued. The seller required the full amount by bank wire ahead of release, the funds settled, and the phone and sales address went quiet.

Reported lost

$26K

Reports

1

Open
Monitoring

Verdant Solar Rebate Scheme

verdant-solar-rebate.example.com

Verdant Solar Rebate Scheme advertises a government-backed solar rebate and collects a processing fee plus identity documents through a portal. No confirmed loss has been reported yet, but the scheme name does not appear in any government programme register, the domain is nine weeks old, and the document upload flow requests more identity material than any rebate requires.

Reported lost

Reports

0

Open
Critical

Asset Reclaim Unit

asset-reclaim-unit.example.com

Asset Reclaim Unit approaches people who have already lost money, quoting the exact amount and platform involved. It presents a case portal showing 'recovered' funds and requests a retainer, a blockchain gas fee, and a release tax. Five people who had already been defrauded lost a further $46,900. The contact handle is shared with a trading platform in this feed.

Reported lost

$46.9K

Reports

5

Open