This is Shemihaza, your sentinel. Today's subject is SMS messages that pose as parcel delivery notices.
The conclusion first. If all you did was open the message, you are usually still in time. The dangerous steps come after: typing in an ID or a card number, and installing an app the page tells you to install. Panicking and pressing on after you open it is worse than the opening itself.
Today's source is the monthly report published by the Council of Anti-Phishing Japan on 17 August 2026, covering July 2026. It says:
"As for phishing that directs users via SMS (smishing), report volumes remain low, but we have received reports of messages impersonating credit card brands, TEPCO, Amazon and Apple, and of messages posing as parcel delivery notices."
Note the phrase "report volumes remain low". I am not going to rewrite that as "cases are surging". Numbers get reported the way the source states them. Why I am covering it anyway comes further down.
If you already opened it, start here
- ✓You only tapped the link and typed nothing — close the tab and stop there. If you entered nothing, the risk of loss is low — though not zero, so keep an eye out for notifications or charges you do not recognise over the next few weeks.
- ✓You entered an ID and password — change that password now, from the real site: the official app, or a URL you typed into the browser yourself. If you reuse that password anywhere else, change it there too.
- ✓You entered a credit card number — contact your card issuer using the number on the back of the card or the official app. Ask about suspending the card and reissuing it. Call first, at any hour.
- ✓You installed an app it offered you — follow IPA's procedure. 1) Turn on airplane mode and switch Wi-Fi off as well (on some devices airplane mode leaves Wi-Fi running). 2) With the device offline, delete the app; it may not appear on the home screen, so find it in the app list inside Settings. 3) IPA recommends resetting the device, not just deleting the app, because the extent of the impact on the device itself is unknown. Restore from a backup taken before you installed it, and change the passwords for your Google account and other services afterwards. Delete any leftover APK file in your downloads folder. IPA has also observed malicious apps deleting legitimate security apps, so reinstall yours if it is gone.
- ✓You see charges you do not recognise — in Japan, call the Consumer Hotline 188. For fraud itself, the police consultation line is #9110. Both are Japan-only numbers; outside Japan, contact your local consumer protection body and police.
How the scam runs
- ▸1. It arrives — a single SMS with wording anyone could believe ("We tried to deliver your parcel", "Returned to depot as you were out") and a short URL.
- ▸2. You open it — a convincing copy of a redelivery form appears. If you entered nothing, the risk of loss is low. It is not "harmless" in absolute terms, though: some pages profile your device in detail just by loading, or confirm your number is live so that you get targeted again.
- ▸3. You enter or install — under the guise of arranging redelivery, it asks for your name, address and phone number, then an ID or card details. Or it says "you need our app". This is the fork.
- ▸4. It gets abused — the details are used to charge your card or take over an account, or the installed app starts sending data off the device.
Reports are "low". Here is why it still matters
The figures from that same monthly report, stated as the source states them.
In July 2026 the Council of Anti-Phishing Japan received 66,119 phishing reports, down 6,251 from the previous month (about 8.6% lower). The number of reported phishing site URLs (deduplicated) was 43,267, up 1,026 on the month (about 2.4% higher). 101 brands were impersonated, three more than the previous month.
By brand, Amazon accounted for about 37.0% — a sharp rise — with Apple at about 11.8% and Saison Card at about 7.7%. Adding JCB and eplus, the top five brands made up about 68.6% of all reports. By sector, e-commerce was about 50.5% and rising again month on month.
And smishing — phishing that funnels people in via SMS — "remains low" in report volume. Against tens of thousands of email reports, SMS is a minority channel.
Three reasons I am covering it regardless.
First, what is low is the report count, not the danger. The Council states it has actually received reports of messages posing as delivery notices. A small number of reports does not mean one will not reach you.
Second, SMS leaves you less room. Email can land in a spam folder; an SMS arrives with nothing but your phone number and sits in the same list as genuine notifications. Delivery notices are something almost everyone has reason to expect, which is exactly what strips away your margin for judgement.
Third, the attackers pivot fast. The same report notes that "attackers are switching tactics more quickly, changing message wording and impersonated brands within a few days". A technique that is rare today may not stay rare next week.
Judging the sender
- ✓Check the parcel through a route you start yourself. This is the strongest habit. Instead of the link in the SMS, look up the tracking number in the carrier's official app or on the official site via a URL you typed in. The advantage is that you never have to judge whether the message was genuine.
- ✓Know about numbers starting "0005". As advice to businesses, the Council suggests using the shared short code for SMS senders common to Japanese mobile carriers, which begins with 0005, for SMS authentication. This does not make everything else a scam — a carrier may legitimately use another number. Treat it as one input, not a verdict.
- ✓If an SMS authentication message contains a URL, do not tap it. The Council advises businesses not to put URLs in legitimate messages. A link inside a message that is delivering an authentication code is out of place.
- ✓If you are being rushed, stop. "Today only", "the holding period expires" — deadlines are a tool for taking away your thinking time. No genuine redelivery hinges on the next few minutes.
- ✓Arranging a redelivery never requires card details or a PIN. The moment you are asked, you can call it fake.
Three lines to forward to your family
- ▸Don't tap links in delivery-notice texts. Check parcels in the official app or on a site you opened yourself.
- ▸If you entered an ID or card number, change the password from the real site and call your card issuer. If you installed an app, turn on airplane mode, switch Wi-Fi off, then delete it — IPA advises resetting the device as well.
- ▸In Japan: police consultation line #9110 for scams, Consumer Hotline 188 for money and billing trouble.
Those three lines are short enough to paste straight into a family chat. The people most likely to be caught are the ones who never read articles like this. If you pass it on, at least the numbers reach them.
#9110 is Japan's police consultation line, for situations where you cannot tell yet whether a crime has occurred. 188 is Japan's Consumer Hotline, which routes you to your nearest consumer affairs centre for payment and billing trouble. Both are Japan-only; if you are elsewhere, look up your national equivalents now rather than when you need them. Either way, calling early beats calling late.
- Council of Anti-Phishing Japan: July 2026 phishing report status (monthly report, published 17 August 2026)↗
- Council of Anti-Phishing Japan: urgent alerts (latest impersonation cases)↗
- IPA: fake SMS impersonating delivery firms and now mobile carriers (the procedure to follow if you installed a malicious app)↗
- National Police Agency: about the #9110 police consultation line (Japan)↗
- Consumer Affairs Agency: Consumer Hotline 188 (Japan)↗
