DHL say it is urgently investigating a potential 鈥渟mishing鈥 text message as scammers try to cash in on parcel deliveries ahead of Black Friday and Christmas.
A DHL Express New Zealand spokesperson today confirmed the company was investigating the possible smishing (SMS) messages.
鈥淭he potentially fake SMS claims to be from DHL and asks recipients to call a hyperlinked landline number to provide further information to get their shipment released from customs,鈥 the spokesperson told the Herald.
鈥淵our shipment is held for Customs Clearance,鈥 the text read, with one specimen shared on Reddit appearing to encourage people to then call a DHL number, and sent from an extremely long number beginning with the New Zealand calling code.
DHL said any customer receiving a message believed to be suspicious could verify it by contacting the company鈥檚 customer service team on 0800 800 020.
鈥淭he security of our customers and online platforms is a priority and we are constantly working to enhance the strength of these systems and processes,鈥 DHL added.
鈥淯nfortunately, this type of criminal activity is becoming more sophisticated and frequent, particularly during the peak Christmas period when freight volumes increase, so we take all potential threats seriously and are investigating this with urgency.鈥
Some sceptical customers shared these messages on Reddit to raise concerns about a possible parcel delivery scam. Photo / Reddit
The DHL spokesperson added: 鈥淲e encourage anyone who is concerned about the authenticity of a text message not to reply, and to verify it by calling our customer service team.鈥
The National Cybersecurity Centre (NCSC) said the possible DHL scam texts, unlike phishing messages, often had no link in them.
鈥淚t can sometimes be difficult to ascertain if a message is a phishing text,鈥 the NCSC added.
Phishing referred to messages seemingly from a credible source but were intended to dupe recipients into disclosing personal details such as passwords and credit card information.
鈥淗owever, we know text messages like this are a common phishing tactic,鈥 the cybersecurity centre added.
鈥淪cammers often send messages about parcels that couldn鈥檛 be delivered or are held up at Customs to trick recipients into clicking on phishing links or calling a number.鈥
The cybersecurity centre said an uptick in phishing texts sent to New Zealanders was detected last year in the weeks approaching Christmas and New Year.
鈥淭hese messages claim to be from NZ Post, DHL, or other postal agencies and ask you to click on a link. Since it鈥檚 a time of year when a lot of people are actually expecting parcels, these messages appear all the more credible.鈥
The NCSC advised people to be wary of any unexpected messages, especially if one was not expecting a parcel.
鈥淚f you get a text message that looks suspicious, do not click on the link or call the number provided. Instead, you can call the postal company on their publicly listed number and ask if the text is genuine.鈥
The cybersecurity centre said if the text was from a company the recipient was unfamiliar with, the recipient should research the company by reading reviews or checking how long their website had been around.
鈥淪cammers use links that resemble an official one, with words like 鈥渘z-post鈥 or 鈥渄hl-nz鈥 in the URL to make them look legitimate,鈥 the NCSC added.
鈥楽ense of urgency鈥 and scam-yourself attacks
鈥淭hey also create a sense of urgency so you have less time to think before you respond to them,鈥 the cybersecurity centre said.
鈥淭he best course of action is always to contact the company on their publicly listed website or phone number.鈥
Meanwhile, Nasdaq-listed most prominent Gen Digital Inc, formerly Symantec Corporation, said in a third-quarter threat report it had detected a 614% increase in 鈥渟cam-yourself attacks鈥 where users were guided to infect their own devices.
Gen said these attacks deployed social engineering to fool people into installing information stealers, droppers and other traditional malware.
Droppers, according to Europol, were malicious software designed to install other malware onto a target system.
Gen said scam-yourself attacks were the third most prominent threat to Kiwis in the third quarter, after general scams and malvertising, where online ads were infected.
鈥淚n New Zealand, email threats such as phishing attempts, fake invoices, extortion demands for cryptocurrency and lottery scams are increasingly common.鈥
It said dating or romance scams were still rampant too, as were technical support scams, where criminals posed as IT professionals to access devices or financial data.
鈥淭hese shifts in targeting strategies and tactics signal the importance of remaining on alert for new methods and flavours of online scams,鈥 Gen added.
John Weekes has covered crime and courts for publications including the Herald, Herald on Sunday, Dominion Post, and for 九一星空无限 Corp, Australia.
Take your Radio, Podcasts and Music with you
Get the iHeart App
Get more of the radio, music and podcasts you love with the FREE iHeartRadio app. Scan the QR code to download now.
Download from the app stores
Stream unlimited music, thousands of radio stations and podcasts all in one app. iHeartRadio is easy to use and all FREE