Skip to content

Security1 publisher2 min readPublished

Fake bpost customs email escalates a EUR4.95 duty into a request for card and bank details

A phishing email impersonating Belgium's bpost asks for EUR4.95 in unpaid customs duty. Malwarebytes says the pages behind the demand are built to harvest bank and card credentials, and the fee is the pretext.

The Watch · Security desk

Illustration accompanying Fake bpost customs email escalates a EUR4.95 duty into a request for card and bank details

What happened

  • Malwarebytes says a phishing email impersonating Belgium's bpost claims a parcel could not be delivered on September 9, 2026, because EUR4.95 in customs duties went unpaid.
  • The link in the email passes through the URL shortener qr.paps.jp before redirecting the recipient to a fake bpost site.
  • The same delivery pretext runs under other postal brands, including USPS in the United States, Correos in Spain, Poste Italiane in Italy and PostNL in the Netherlands.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure One form yields an IBAN alongside a card number and expiry date, so the operator holds credentials for both card fraud and direct debit attempts, and Malwarebytes says such data is also sold on.
  • capability Because the pretext is a failed delivery and the localisation is brand and language, an operator can move between markets without rebuilding the flow.
  • constraint Consumer guidance that leans on spotting bad grammar has a short reach when Malwarebytes says many pages ship with no obvious mistranslation. The remaining checks are the domain and the courier's own app.

The email names a fixed EUR4.95, and the payment page asks the victim to type the amount [1]. Malwarebytes reports that the first page collects name, phone number, email address and age [6]. The second wants an IBAN, a card number, an expiry date and that amount field [7]. The third asks for full card and bank details [8]. Malwarebytes says the site does not stop at collecting the supposed fee [9].

The path to the page runs through a shortener, qr.paps.jp [3]. Landing domains included bpost.center and bpost.be-pakje-ontvangen-nl-recevoir-colis-fr.my.id [4], a string that opens with bpost.be and ends on the registrable domain my.id [2]. The page copies bpost's branding and displays "Secure SSL connection," "256-bit SSL," "SEPA compliant" and "Secure payment," labels the operator added itself [5].

Two errors break the pretext in the Dutch version. One page refers to receiving funds, which does not match the email's demand for a customs payment [10]. A button read "Indian search" where "Betaal" belonged [11]. Malwarebytes wrote that "many phishing pages are built carefully enough that there will be no obvious typo or mistranslation" [12].

Counting bpost, the writeup names seven postal brands across six countries [3]: USPS in the United States, Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy and PostNL in the Netherlands [13]. In each the message claims a delivery problem and steers the recipient to a fake courier site to enter personal and financial information [13].

Malwarebytes does not say whether a charge this small clears bank-side fraud scoring, and it does not describe any completed transactions or how issuers treated them [19]. The escalation targets the IBAN, and Malwarebytes says a request for an IBAN as well as card details should be treated with suspicion, particularly when it supposedly relates to a small delivery fee [15].

Card details that are submitted may be used for fraudulent purchases or sold to other criminals, and Malwarebytes says the personal and banking data can also make later scams more convincing [14]. Its advice for anyone who typed the data in is to contact the bank or card provider immediately, freeze the card if the banking app allows it, monitor accounts for unfamiliar transactions, and change any password entered on the site [16].

What to watch

  • New landing domains once bpost.center is blocked, and whether the operator stays with .my.id subdomains.
  • The same three-page form sequence turning up under PostNL or Correos branding with the fee restated locally.
  • Any Belgian bank reporting SEPA direct debit attempts against IBANs collected through this kit.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories