This delivery text knows your name, your address and what you ordered: where's the leak?

Back to the blog
12 September 202611 min read

The message lands on a Tuesday at 11:12 a.m.:

"Hello Marie, your parcel no. FR-4471209 could not be delivered to 14 rue des Lilas (building B). Choose a new time slot: suivi-relais-colis.net/fr"

Your first name. Your street. Your building. A tracking number that looks exactly like the ones you genuinely receive. At this point, the question most people ask is no longer "is this a scam?" but "how do they know?".

That is precisely the shift the fraudsters were aiming for. For years, the delivery scam text was a net cast at random: "Your parcel is on hold", sent to millions of numbers, in the statistical hope that a few of them really were waiting for something. In 2026, it is no longer a net. It is a targeted shot, fed by very real personal data. And understanding where that data comes from completely changes how you defend yourself.

Man in a green jacket holding a smartphone and a bank card in a wood-panelled interior

The turning point: from generic message to documented message

The gap is worth measuring. A generic text converts poorly — estimates from anti-fraud players hover around a few tenths of a percent in click rates. A text that quotes your name and exact address sends that rate soaring, because it short-circuits the one defensive reflex most of us have been taught: "if the message doesn't know me, it's fake".

That mental shortcut was never a reliable criterion. It is even less so today. The Commission nationale de l'informatique et des libertés (CNIL) records several thousand personal data breach notifications in France every year, a significant share of which involve customer files containing name, postal address, email address and mobile number. Those four fields are all it takes to manufacture a credible delivery text.

In other words: personalisation proves nothing. It only proves that someone, somewhere, holds a database row about you. Which, statistically, is now true of virtually every adult in France.

Where does this data really come from? Five channels

1. Breaches at retailers and carriers

This is the most abundant source. An e-commerce site, a ticketing platform, a DIY chain, a meal delivery service: each one keeps customer files containing exactly what is needed. When an intrusion occurs, those files leave en masse.

What makes carriers and merchants particularly damaging is cruel: their data contains the delivery context. Not just your address, but also the existence of an order, its date, sometimes the name of the retailer. That is what lets the text mention "your Décathlon parcel" rather than a vague "your parcel".

2. Data aggregators and brokers

Between the breach and the text message lies an intermediary industry. Players buy, cross-reference and enrich databases: they match a file containing name + email with another containing email + phone number, and end up with a complete record. This matching work explains why data stolen in 2023 can produce a perfectly up-to-date text in 2026: your address, after all, probably hasn't changed.

3. What you publish yourself

A classified ad listing your neighbourhood, a Google review signed with your first and last name, a professional profile mentioning your city, a photo of your letterbox posted without a second thought. Taken separately, each item is harmless. Assembled, they form a profile.

4. Shipping labels thrown away intact

This is the most underestimated channel and, ironically, the easiest one to cut off. A shipping label carries your full name, your exact address, often your phone number and a barcode containing the tracking number. Tossed intact into a bin room or a recycling container, it is readable by anyone.

A small cross-cut document shredder sitting next to the bin settles the matter in three seconds per parcel. Failing that, a simple opaque blackout marker run over the label before throwing it away is more than enough for everyday purposes.

5. "Legal" marketing with loose boundaries

Not all files are stolen. Some circulate through consent obtained under dubious conditions: pre-ticked boxes, prize draws, "free quote" forms. The data is then passed on to partners, and then to partners of partners. By the fifth resale, nobody controls who is using it any more.

Bearded man in a grey shirt holding a smartphone and a bank card in a kitchen

What the text is really after (and why it's rarely €1.50)

The most widespread scenario asks for a trivial sum: €1.49, €2.30, "redelivery fees". That amount is not the objective. It serves three purposes:

  • Obtaining a full bank card number, with expiry date and security code.
  • Confirming the card is active, via a micro-transaction that goes through without raising suspicion.
  • Setting up what comes next, namely the phone call from a fake bank adviser who, a few days later, will ask you to "block a suspicious transaction".

In its work on payment fraud, the Banque de France has for several years highlighted the rise of so-called "manipulation" scams — those in which victims carry out the transaction themselves, convinced they are acting to protect themselves. The delivery text is often just the first brick in that structure.

A more recent variant asks for no payment at all: it offers to "reschedule the delivery" via an app you need to install. The app is malware that reads incoming text messages — and therefore banking verification codes. No card entered, no visible payment, and yet the account is drained.

The six signals that give away a fake, however well-informed

SignalWhat to look at
The link's domainThe real carrier uses its own domain. laposte.fr, not laposte-suivi-fr.co or lapostefr.info
The payment requestNo French carrier charges fees by text for a second delivery attempt
Countdown urgency"Within 24h", "final notice before return": time pressure is a marker
The reply channelReal tracking is checked in the app or on the website, never via the link you received
The spelling of the addressResold data is often slightly degraded: missing accents, odd abbreviations
The senderA French 06/07 mobile number for an automated notification: anomaly

This last point deserves an important caveat: the absence of an anomaly proves nothing either. Sender spoofing techniques make it possible to display a credible brand name. The only genuinely reliable test remains this one: never start from the message, always go back to the source. You open the carrier's app yourself, or you type the website address into the browser yourself.

Checking whether your data is already circulating

You won't be able to claw back what has leaked, but you can find out how exposed you are — and calibrate your vigilance accordingly.

Breach-checking services. Independent tools let you enter an email address and get the list of known leaks containing it. Some also accept phone numbers. If your address appears in five incidents, assume your name and postal address are circulating too.

Alerts from your bank. Turn on notifications for every transaction, including amounts under €5. Most institutions offer this free of charge in their app settings. It is the best detector of a micro-transaction test.

The right of access under the GDPR. You can write to any company to ask what data it holds about you, where it got it and who it has passed it to. A reply is due within one month. The CNIL provides letter templates on its website. This tedious exercise has a useful side effect: it lets you have your record deleted by companies whose existence you had forgotten.

Bloctel and opting out of cold calling. Signing up to the telephone marketing opt-out list won't stop the fraudsters — they ignore the law by definition — but it reduces the legal background noise and makes suspicious messages stand out.

Shrinking your exposure, in practical terms

There is no "erase my data from the internet" button. There is, however, a series of steps which, taken together, genuinely reduce the amount of information available about you.

Compartmentalise your identities. Use an email address dedicated to online shopping, separate from your main address. Several providers offer disposable aliases: if an alias starts receiving spam, you know exactly which merchant let your record leak.

Consider a second number. A prepaid SIM card dedicated to sign-ups, deliveries and classified ads isolates your main number. The day that secondary number is drowning in fraudulent texts, you replace it without losing your contacts or your accounts.

Limit the data you hand over. When ordering, the "address line 2" field doesn't need to contain "3rd floor, left-hand door, entry code 4512B". The phone number is sometimes optional: when it is, leave it blank.

Prefer pickup points where possible. Your home address then never travels through the logistics chain.

Destroy physical documents. Labels, delivery notes, statements, insurance letters. A cross-cut document shredder is not a gadget: it is the only piece of equipment that deals with the offline side of the problem.

Filter at phone level. Recent mobile operating systems can sort unknown senders into a separate tab and flag suspicious messages. On both Android and iOS, the option is in the Messages app settings. It doesn't block everything, but it breaks the element of surprise.

Man in a parka checking his smartphone while holding an orange bank card in the street

If you clicked: the first thirty minutes, step by step

Clicking is not fatal. Entering your details is far more serious. Here is the order of priorities.

  1. Stop using the site you opened. Close the tab. Don't "correct" an entry, don't try to "unsubscribe".
  2. If banking details were entered, immediately call the card-cancellation number shown on the back of your card or in your banking app — never a number received by message. Have the card blocked.
  3. If an app was installed, turn off mobile data and Wi-Fi, then uninstall it. If you suspect a persistent infection, a factory reset remains the safest solution.
  4. Change the passwords of any accounts whose credentials may have passed through, starting with your email. A password manager stops you reusing the same combination everywhere and speeds this step up considerably.
  5. Report the message to 33700, France's national service for reporting unwanted text messages, by forwarding the text and then the sender's number. It's free and it feeds the operators' blocking work.
  6. Report the incident on Cybermalveillance.gouv.fr and, if you have suffered financial loss, file a complaint. Online pre-complaints exist for scams with no identified perpetrator.
  7. Monitor your statements for several months. Stolen data is sometimes exploited weeks later.

Key takeaway: when it comes to text-message fraud, French law is on the victim's side. Article L.133-18 of the Monetary and Financial Code requires the bank to refund an unauthorised payment transaction, except in cases of gross negligence by the customer. The dispute turns precisely on that notion of negligence — hence the importance of keeping evidence: screenshots of the text, timestamps, correspondence with the bank.

What AI changes — and what it doesn't

Specialist newsrooms documented campaigns in 2026 using AI-generated visuals: a fake photo of the parcel "left on your doorstep", tailored to the type of housing. Spelling mistakes as a fraud indicator are a thing of the past, and images can no longer be trusted.

What doesn't change, however, is the structure of the scam. It always needs three things: that you click a link it supplies, that you enter something of value, and that you do it fast. Remove any one of the three and the attack fails, however sophisticated it may be.

That is why solid rules are not about the message's appearance — which will become flawless — but about the route taken. Go back to the source. Check in the app. Call back a number you looked up yourself. These reflexes work just as well against a text riddled with mistakes as against an impeccable message quoting your address down to the house number.

A consumer guide to home cybersecurity, sitting on a shelf and leafed through as a family, is often worth more than an alert skim-read in passing: it is shared habits, not individual knowledge, that protect a household.

Going further

  • Cybermalveillance.gouv.fr: quick-reference sheets on phishing and incident reporting.
  • CNIL: letter templates for exercising your rights of access, rectification and erasure.
  • 33700: free reporting of unwanted texts and calls, run with French operators.
  • Banque de France / Observatoire de la sécurité des moyens de paiement: annual fraud reports, useful for understanding trends.
  • Signal Conso (DGCCRF): for reporting a merchant or a questionable commercial practice.

The text that knows your name isn't a sign that you have been personally targeted. It is a sign that your details appear in one file among millions of others. The good news, if you can call it that, is that this banality applies to you exactly as it does to your neighbours — and that the protective measures remain within everyone's reach.

#smishing#arnaque#fraude#Vie privée#données personnelles#RGPD#Sécurité#2026#Conseil Sécurité

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS