I received a message about a delivery I was actually expecting, from a courier I was actually using, at a time when the delivery was actually due.
I got as far as the payment page before something felt wrong. Nothing about it was technically clever, and it was the closest I have come to losing money to a scam.
Why it worked
Context, entirely.
The message arrived when I was expecting exactly that message. I was not evaluating whether a delivery notification made sense; I was processing an expected notification.
That is the whole mechanism. Modern phishing does not rely on convincing you of something implausible. It relies on arriving at a moment when the thing is already plausible.
The timing may have been coincidence, given how many such messages are sent. It may not have been, since delivery notifications and package tracking are widely visible.
What I noticed, eventually
Three things, none of which was the obvious one.
The amount was small and oddly specific, which is a deliberate technique. A small charge is below the threshold at which people stop to think.
The page asked for card details in full, including the security code, which a genuine surcharge process would generally handle through a payment provider rather than a form on the courier's own page.
And the sense of time pressure, stated as a deadline after which the item would be returned. Urgency is the most reliable single indicator, because legitimate processes rarely need an answer in the next two hours.
What I did not notice was the address, which I had not looked at, and which was wrong in a way that would have been obvious.
Why the old advice has stopped working
The guidance most people received years ago is now close to useless.
Look for spelling errors. Modern phishing is well written, and generative tools have removed the last of the clumsy translation that used to give it away.
Look for the padlock. Almost all phishing sites use encryption now, because certificates are free and automatic. The padlock indicates the connection is encrypted, not that the site is legitimate, and it never meant otherwise.
Check the sender name, which is trivially forged.
Hover over the link, which is difficult on a phone where most of these are read.
None of that is a reliable filter any more.
What actually works
Two habits, which I now apply without exception.
Never act from the message. If a message says there is a problem with an account, go to the service directly — typed address or saved bookmark — and check there. If there is a genuine problem, it will be visible.
This single rule defeats essentially all of it, because the entire attack depends on you following their route rather than yours.
And treat urgency as the signal. Anything demanding immediate action is either a scam or something that can survive being checked properly. There is no legitimate process that collapses if you take ten minutes.
The technical protections that help
Beyond behaviour.
Two-factor authentication, which limits the damage from a captured password. Hardware keys and passkeys are resistant to real-time relay attacks in a way that codes are not, which matters because the more sophisticated operations now relay codes in real time.
A password manager, which will not autofill on the wrong domain. That is an underrated protection — the manager not offering to fill is a strong signal, and I have since made a habit of noticing when it does not.
And card controls, since many banks allow limits and notifications that catch this quickly.
Reporting it
Worth doing and takes very little time.
Most countries have a national reporting service for fraudulent messages, and most large email providers and messaging platforms have a report function that feeds into blocking.
The genuine benefit is aggregate rather than individual — reports contribute to taking sites down faster, which reduces how many people encounter them.
The thing worth internalising
Being caught is not a failure of intelligence, and the framing that it is stops people reporting and warning others.
These operations are professional, they test their messages, and they send enormous volumes so that a small proportion arriving at the right moment is sufficient.
What protects you is not being clever. It is having a rule you follow regardless of how plausible the message is, because the plausible ones are exactly the ones the rule exists for.
What to do if you did click
Since the advice usually stops at prevention.
Change the password for the affected service immediately, from a device you trust, and anywhere else that password was used.
Enable two-factor authentication if it was not already.
If card details were entered, contact the bank rather than waiting to see whether anything happens.
Check for unfamiliar sessions, forwarding rules and recovery addresses on any compromised account, since establishing persistent access is a standard next step.
And report it, both to the service and to any national reporting scheme.
Speed matters considerably more than thoroughness in the first hour.