How a Simple Tshirt Order Cost Me 57,800 in a Delivery Scam
My Story: How I Got Scammed
I had placed an order through the Shiprocket platform. Everything seemed routine - I received the order confirmation and waited for delivery. However, a few hours later, I received a phone call from a person claiming to be a representative of Blue Dart Courier Service.
With a confident and professional tone, the caller informed me that there was a “delivery address mismatch” with my parcel. He claimed that unless I corrected the address immediately, the delivery would be cancelled and the parcel returned.
To “fix” the supposed delivery issue, the caller informed me that he had just sent a link via SMS from the courier company’s “official address verification page.” He sounded polite, professional, and even mentioned my order number, which made the entire interaction seem genuine.
The message looked authentic. It had the Shiprocket logo, a tracking ID, and a shortened verification link, formatted just like real delivery notifications.
“Dear Customer, your parcel #SRK1234567 could not be delivered due to address mismatch.
Please verify your correct address to avoid return: [bit.ly/-link—]
— Blue Dert Courier Service”
Trusting it completely, I clicked the link. It opened a web page that appeared identical to a legitimate courier tracking site — it showed my parcel number, product name, and delivery status. Below that was a form asking me to confirm my name, mobile number, and address, followed by a field for “payment confirmation details” to verify identity.
Believing it was part of the address correction process, I entered my bank credentials, assuming it was a simple verification step. Moments later, I received an OTP (One-Time Password) on my phone. The caller, still on the line, politely said,
“Sir, please share the OTP to complete your address correction. It’s a system-generated code to validate your address details.”
Without suspecting anything, I shared the OTP.
Within seconds, the website displayed “Address successfully updated.” But before I could even close the page, I received a bank alert — ₹57,800 had been debited from my account.
Panic struck immediately. I tried calling the courier number again, but it was switched off. When I revisited the SMS, I realized that the link didn’t belong to the official courier domain — it was a phishing site cleverly designed to mimic a real one.
In reality, while I was filling in my details, the fraudster had already initiated a transaction in the background. The OTP I shared — thinking it was for address verification — was actually used to authorize the fund transfer from my account.
That single moment of misplaced trust — one click, one OTP — cost me ₹57,800.
When I tried to call the courier number back, it was switched off. That’s when I realized - I had fallen for a delivery scam cleverly disguised as a courier issue.
How This Fraud Happened
This is a Courier Delivery Scam — a form of cyber-fraud where scammers impersonate delivery service representatives and use fake “delivery issues” to trick victims into clicking malicious links.
Here’s how the fraud unfolded step-by-step:
- Legitimate Purchase with malicious company employee: The victim places a real order (in this case, via Shiprocket), providing scammers a credible entry point. If the e-commerce or courier company’s compliance around data privacy is weak, internal data (customer names, phone numbers, order IDs, delivery addresses) can be leaked — intentionally or accidentally — by a malicious or negligent employee. This leaked data makes it far easier for fraudsters to target specific customers with highly convincing, personalized messages and calls.
- Fake Courier Call: Fraudsters impersonate well-known courier companies and claim there’s an “address mismatch” or “payment issue”.
- Malicious Link: A link is sent via SMS or WhatsApp under the guise of correcting details or paying small charges.Clicking the link gives scammers access to sensitive data, banking credentials, or permissions for unauthorized transactions.
- Unauthorized Transactions and disappearing Act: Money is immediately siphoned from the victim’s account. Calls and messages go unanswered, leaving the victim with monetary loss and no recourse from the fake courier.
User Interface — How Convincing the Trap Looked
While this scam did not involve an app, it relied heavily on authentic-looking communication that mimicked professional courier operations.
Below are some common visual and behavioral cues that make such scams look genuine:
- Courier Branding: Use of reputed courier names like Blue Dart, Delhivery, or DTDC with slight name variations (e.g., “Blue Dert”).
- SMS Formatting: Messages that mimic official delivery updates with tracking IDs and clickable “update address” links.
- Polite Communication: Scammers sound calm, professional, and helpful — they don’t sound like typical fraudsters.
- Urgency Language: Phrases like “Your parcel will be returned if not updated in 30 minutes” create pressure to act quickly.
- Fake Confirmation Pages: Clicking the link may open web pages that look like courier tracking portals or address-update forms.
Why this is dangerous:
Such scams exploit your natural urgency to resolve small issues (like delivery problems) — lowering your guard. When urgency meets trust (a known platform name), the scam succeeds.
Warning Signs: When to Exercise Caution
🔴 Unexpected Delivery Calls: If a courier calls you directly to “fix” address or payment issues, treat it with suspicion.
🔴 Link in SMS/WhatsApp: Never click on links claiming to “update address” or “pay courier fees”.
🔴 Urgency Pressure: “Act now or parcel will return” — classic red flag.
🔴 Generic Courier Names: “Blue Dert”, “Speed Express”, “Quick Ship” — often sound real but aren’t.
🔴 No Official Notification: Genuine delivery updates come only from the official e-commerce app or email.
🔴 Unusual Bank Alerts: If you receive OTPs or debit alerts after clicking links, contact your bank immediately.
How to Prevent Such Fraud
- Never Click and act on Unknown Links: Courier companies do not send address-update or payment links via SMS or WhatsApp. Also, even if you open the link do not input or update any information.
- Verify Independently: Always check your order and delivery details directly on the official app or website (e.g., Shiprocket, Amazon, Flipkart).
- Avoid Sharing Personal Data: Do not share card details, OTPs, or banking information over calls.
- Order Only Through Reputed E-Commerce Platforms: Make purchases on well-known and trusted platforms rather than smaller or unfamiliar websites. This reduces the risk of exposure to fraudulent contacts or malicious third-party employees.
- Enable Transaction Alerts: Real-time SMS alerts can help detect unauthorized debits early.
- Report Immediately: If you fall victim, lodge a complaint at cybercrime.gov.in or call 1930 (Cyber Crime Helpline).
- Educate Family Members: Elderly and less tech-savvy people are often targeted for such scams.
Awareness Note
Courier-based phishing scams are growing fast in India. Fraudsters exploit trust in known logistics names and everyday online shopping behaviour. Even a small order can become an entry point to financial loss.
In this case, the loss was ₹57,800, but it could have been much worse.
Stay alert. Stay safe.
