What Is Missed-Delivery SMS Fraud?
"We attempted delivery but you were not home. To reschedule, click here." Plenty of people have received an SMS like this. In its monthly reports for December 2023 and January 2024, the Council of Anti-Phishing Japan noted that among phishing attempts delivered by SMS (smishing), messages posing as delivery missed-notifications and leading to counterfeit sites accounted for many of the reports it received. Phishing reports reaching the council came to 90,792 in December 2023 alone, 6,444 more than the month before. Deliveries have also become routine as online shopping has grown, which is precisely what makes "a package must be on its way" such an easy assumption to exploit.
The sophistication of this scam lies in how it blends into everyday behavior. The more frequently someone shops online, the more readily they think "I might have ordered something" and tap the link in the SMS. Like phone scams impersonating delivery services, this tactic borrows the trust people place in logistics.
Victim Cases
Case 1: Credit Card Information Entered on a Fake Site
Mr. A, an office worker in his 30s, received an SMS from a 090 number: "Yamato Transport attempted delivery but you were not home. Please request redelivery at the link below." Since he was waiting for an online order, he tapped the link without suspicion. The site displayed was nearly identical to Yamato Transport's official website, showing a redelivery scheduling form.
The form requested name, address, and phone number, plus a credit card number field labeled "for identity verification." Mr. A briefly wondered whether card information was needed for redelivery, but convinced himself it might be a COD package and entered the details. The next day, his card company notified him of a 150,000 yen charge from an overseas site.
The key takeaway from this case is that the victim sensed something was off yet created his own rational explanation to continue. Scammers anticipate this psychology and include plausible-sounding reasons like "identity verification" or "security authentication" to neutralize doubt.
Case 2: Malicious App Installation (Android)
Ms. B, a homemaker in her 50s, received an SMS claiming to be from Sagawa Express about a missed delivery. Tapping the link displayed a screen saying "Please install the latest Sagawa Express app." She followed the instructions, but the app was malicious software disguised as Sagawa Express.
The malicious app seized SMS send/receive permissions from Ms. B's phone and mass-sent similar scam SMS messages using her number. Additionally, contacts, photos, and email contents stored on her phone were transmitted to an external server. Approximately 3,000 scam SMS messages were sent from her number, resulting in about 50,000 yen in communication charges.
Since Android 8.0, the device-wide "unknown sources" switch no longer exists. Permission to install apps is instead granted app by app, to a browser or a file manager for instance. Opening an app file from a link in an SMS triggers exactly that permission prompt, so declining it, and keeping Google Play Protect scanning turned on, is where the real defense lies.
Case 3: Apple ID Hijacking (iPhone)
Mr. C, a university student in his 20s, tapped a link in a missed-delivery SMS and was shown an Apple ID login screen. Believing the explanation that "login is required for package tracking," he entered his Apple ID and password. He was then prompted for a two-factor authentication code and entered the 6-digit code received via SMS.
The scammer hijacked Mr. C's Apple ID, accessed photos and notes stored in iCloud, and purchased approximately 80,000 yen worth of App Store gift cards using the linked credit card. Mr. C noticed the breach when he received an email from Apple saying "A new device has signed in."
For iPhone users, the primary goal is Apple ID theft rather than malicious app installation. No legitimate service needs your Apple ID in order to track a package. If you are asked for it anywhere other than Apple's own site, do not type it in; close the screen. See also two-factor authentication and phone number risks.
Characteristics of SMS Scam Tactics
Missed-delivery SMS scams share several common patterns.
- Sender numbers: They frequently arrive from mobile phone numbers (070, 080, 090), because they are sent from ordinary users' handsets infected with a malicious app
- URL characteristics: Fake domains resembling legitimate ones are used, such as "yamato-delivery.com" or "sagawa-express.net" - URLs that look authentic at first glance
- Time of arrival: When a message lands at an hour where a delivery attempt would be plausible, that alone supplies the explanation. A natural-looking time is not evidence that the message is genuine
- Message variations: Multiple patterns have been confirmed, including "we were unable to deliver due to absence," "please check your delivery status," and "there is an error in your address"
Measures to Prevent Damage
- Do not tap links in SMS messages: Check delivery notifications through official apps or by directly accessing official websites. Never tap any link in an SMS
- Track packages through official apps: Install the official apps from Yamato Transport, Sagawa Express, and Japan Post, and always track packages through them
- Do not grant install permission on Android: If you are asked "Allow installation of unknown apps?", decline. Go to "Settings" then "Security and privacy" then "Google Play Protect" and keep scanning enabled (menu names vary by device and version)
- Enable SMS filtering: On iPhone, go to "Settings" then "Messages" then "Filter Unknown Senders" to sort SMS from unregistered numbers into a separate tab
- Report suspicious SMS: The Council of Anti-Phishing Japan publishes a reporting address (info@antiphishing.jp). Because an SMS cannot be forwarded to email directly, the council asks you to attach a screenshot instead. Your carrier's spam SMS reporting service is another route
What to Do If You Are a Victim
If You Entered Credit Card Information
Immediately contact your card company to request a freeze and reissue. Unauthorized charges may be refunded through the card company's compensation program. Prompt reporting after discovering the fraud is typically a condition for compensation eligibility, so act quickly.
If You Installed a Malicious App
First enable airplane mode to cut off communication, then uninstall the malicious app. Next, change all passwords stored on your smartphone. For unauthorized communication charges, contact your carrier to explain the situation and negotiate a reduction or cancellation.
If You Entered Your Apple ID or Passwords
Immediately change your Apple ID password and review your two-factor authentication settings. Check the billing statements for credit cards linked to your Apple ID, and if unauthorized charges are found, contact both your card company and Apple Support.
In all cases, consult the police (#9110) and a consumer affairs center (188) following the phone scam reporting guide. Filing a report helps prevent similar scams from spreading.