Package‑delivery profiles are convenient, but they also create a new doorway into your personal life. Criminals target UPS, FedEx, and USPS accounts to quietly redirect packages, place unauthorized holds, harvest your home and work addresses, and time doorstep thefts. The good news: a few concrete changes to your settings and habits will close most of these gaps. This guide walks you through practical, beginner‑friendly steps to harden each account, spot tampering early, and reduce the fallout if something goes wrong.
Why criminals target delivery accounts
Attackers don’t always need to steal your credit card to profit. If they can access your shipping accounts, they can:
- Redirect valuable items to pickup lockers or alternate addresses before you notice.
- Place a mail hold and intercept statements, checks, or identity documents in one batch.
- Map your daily routine using delivery history to time break-ins or social‑engineering scams.
- Collect verified personal data (names, phone numbers, addresses) for identity fraud and account takeovers elsewhere.
Most delivery‑account fraud starts with weak passwords, reused credentials from unrelated breaches, or easy‑to‑bypass authentication. Your goal is to reduce access points and create high‑friction barriers that are still manageable for you.
Core hardening checklist (applies to UPS, FedEx, and USPS)
Before the carrier‑specific steps, complete these platform‑agnostic safeguards:
- Use a unique, long password (at least 14–20 characters) created and stored in a reputable password manager. Never reuse a password from any other account.
- Enable the strongest available two‑factor authentication (2FA). Prefer security keys (FIDO2) if supported, then an authenticator app (TOTP). Avoid SMS codes when possible.
- Lock down account recovery. Remove outdated emails and phone numbers. Add a recovery email/number you control and secure them with 2FA as well.
- Set real‑time notifications for sign‑ins, address changes, delivery‑instruction changes, and holds. If the platform allows only email or SMS, choose the one you check fastest.
- Minimize stored data. Delete old addresses, pickup locations, and payment methods you no longer use. Less data reduces what an attacker can exploit.
- Review active sessions and devices monthly. Sign out everywhere, then sign back in on trusted devices only.
- Create a “baseline” of preferences (signature required, no driver release, no alternate address authorizations). Reconfirm these settings after every app update.
- Beware phishing. Carriers rarely ask you to “verify your account” by clicking a text link. Access your account by typing the official site into your browser or using the official app.
Harden UPS My Choice
UPS My Choice lets you manage deliveries and authorize changes. Here’s how to secure it:
- Account sign‑in and 2FA
- Create a unique password in your manager; avoid memorable phrases you’ve used elsewhere.
- Turn on 2FA and choose an authenticator app or security key if available.
- Identity and address verification
- Complete UPS identity validation so UPS ties your profile to your real address. This makes it harder for a fraudster to add unauthorized addresses.
- Review your “Delivery Addresses” list and remove any you don’t recognize.
- Delivery preferences
- Set default Signature Required for high‑value shipments, when possible.
- Disable default “Leave at door” or “Driver release” options if they expose your items.
- Restrict alternate pickup locations or lockers unless truly needed.
- Change controls and alerts
- Enable alerts for delivery changes, access attempts, and new device sign‑ins.
- Set “Delivery instructions changes” to require re‑authentication.
- Payment and stored data
- Remove stored payment methods if you rarely use paid changes.
- Delete outdated addresses and former workplaces.
- Regular audits
- Monthly: check login history, app‑connected devices, and saved locations.
Harden FedEx Delivery Manager
FedEx Delivery Manager controls redirects, holds at locations, and signatures. Tighten it like this:
- Strengthen login
- Set a unique password and enable the strongest 2FA available.
- Review linked emails and phone numbers; remove any not under your control.
- Restrict delivery options
- Default to “Adult Signature Required” for sensitive shipments when offered.
- Disable or limit “Hold at Location” and “Redirect to FedEx Office” to reduce abuse.
- Alerts and change approvals
- Turn on notifications for delivery change requests, pickup authorizations, and profile edits.
- Require re‑authentication before confirming delivery‑instruction changes.
- Saved places and addresses
- Prune saved addresses and pickup spots to the bare minimum.
- Check for unknown nicknames (e.g., “Locker 3” or “Office Annex”) and remove them.
- Payment and preferences
- Remove cards you no longer need for delivery changes.
- Review “Delivery Instructions” text for anything that could aid theft (gate codes, door descriptions). Keep it generic.
- Account activity
- Monthly: review sign‑in history and devices; sign out everywhere and re‑authenticate.
Harden USPS Informed Delivery
USPS Informed Delivery previews mail and packages and allows holds and redirections. Because USPS controls your mailbox, this account deserves extra protection.
- Identity‑proofing
- Complete USPS identity verification. If online verification fails, finish in person at a post office with ID. This prevents strangers from creating a profile in your name.
- Login and 2FA
- Use a unique password and enable 2FA with an authenticator app when supported.
- Remove outdated recovery options that could be hijacked.
- Mail hold and forwarding controls
- Turn on alerts for any mail hold or change‑of‑address (COA) requests.
- Set a calendar reminder to review your USPS dashboard weekly for unexpected holds or forwards.
- Address and household management
- Verify the people listed at your address; remove unknown names.
- Lock down alternate addresses; ensure old residences are not linked.
- Minimal exposure
- Keep delivery instructions sparse. Never include gate or lock codes; use general guidance only.
- Physical mailbox hygiene
- Use a locking mailbox where permitted, or empty mail daily.
- Collect packages quickly and consider secure parcel boxes for frequent deliveries.
Stop redirects and unauthorized holds before they start
Most unauthorized changes are software‑driven (account takeovers) or staff‑assisted social engineering. These tactics make them harder to spot until a package vanishes. Layer these defenses:
- Require signatures by default for higher‑value items. Yes, it can be inconvenient, but it removes the easiest theft window.
- Use delivery windows and vacation holds sparingly. Shorten hold periods and confirm them directly inside your account—never by replying to texts.
- Disable broad authority like blanket “deliver to neighbor” or “any locker” permissions.
- Add a second contact (trusted household member) to receive parallel alerts so someone catches changes quickly.
- Set up cross‑channel alerts: push + email. If one channel is compromised or filtered, the other still signals.
Detect tampering early
Early detection limits losses. Build a quick daily/weekly routine:
- Daily: scan carrier notifications for “delivery change,” “redirect request,” “mail hold created,” or “new device sign‑in.”
- Shipment watchlist: for expensive orders, add tracking numbers to all corresponding carrier accounts and your calendar with reminders.
- Weekly: open each carrier app and review account activity, saved addresses, and delivery instructions.
- Monthly: sign out of all sessions, change your password manager’s generated password if there’s any suspicion, and verify recovery details.
If you suspect your account was compromised
Act immediately—speed matters for recovering packages and stopping further abuse:
- Lock down access
- From a trusted device, change your password to a strong, unique one.
- Enable or reset 2FA; revoke all active sessions/devices.
- Reverse changes
- Cancel redirects, holds, and pickup authorizations inside the account.
- Contact the carrier’s support to flag suspected fraud and request an account note requiring extra verification for future changes.
- Trace affected shipments
- Call the carrier with tracking numbers; request holds at your local facility with ID verification.
- Secure adjacent accounts
- Change passwords for your email and mobile‑carrier accounts, and enable 2FA—attackers often pivot through them.
- Document everything
- Save screenshots of changes, timestamps, and support case numbers in case of loss claims or police reports.
Reduce the value of what can be stolen
Even with strong settings, assume a determined attacker might learn some details. Limit your exposure:
- Don’t store sensitive delivery notes (alarm types, access codes, travel plans).
- Use package lockers or ship‑to‑store for high‑value items instead of home delivery when practical.
- Rotate delivery locations between home and work to avoid predictable patterns.
- Obscure packaging by selecting “gift” or “no marketing box” options from retailers when available.
Tie delivery security to identity protection
Package‑account abuse often overlaps with broader identity risks because the same credentials, phone numbers, and addresses appear in multiple systems. Monitoring your financial identity can help you spot related fraud signals—new accounts, address changes, or hard inquiries that you didn’t initiate—soon after a delivery‑account compromise or data breach. If you want proactive visibility, consider a credit and identity‑monitoring service that centralizes alerts and recovery resources, such as SmartCredit.
Household practices that make security stick
Security fails if only one person knows the rules. Make these habits household‑wide:
- Shared password manager for family accounts with individual logins and emergency access.
- One communication rule: never approve changes from a link in a text or email; always go through the official app or site.
- Doorstep discipline: pick up packages quickly; use a camera or smart doorbell for evidence if disputes arise.
- Travel protocol: if you must place a hold, set start and end dates tightly and confirm cancellation from the app when you return.
Quick reference: Red flags to act on now
- You receive a “Delivery change confirmed” notice you didn’t request.
- Your Informed Delivery shows expected mail that never arrives.
- You spot unknown addresses, lockers, or payment methods in any carrier profile.
- You get a sign‑in alert from an unfamiliar device, location, or time.
- Support says your account details fail verification despite you entering correct info.
Build a resilient response plan
Prepare a simple response playbook so you’re not scrambling under pressure:
- Contact list: bookmark carrier fraud/claims pages and save local facility phone numbers.
- Template notes: keep a short script describing suspected fraud to speed up calls.
- Evidence folder: store tracking numbers, receipts, and screenshots for 90 days after delivery.
- Quarterly drill: review settings, do a sign‑out‑everywhere sweep, and test that alerts still reach you.
Conclusion
Delivery accounts are high‑value targets because a single unauthorized change can reroute expensive items or expose your personal life. By combining strong authentication, strict change controls, minimal stored data, and fast alerts, you shut down the most common attack paths against UPS My Choice, FedEx Delivery Manager, and USPS Informed Delivery. Add routine checkups, household‑wide rules, and identity monitoring to catch spillover fraud quickly. A few minutes of setup today will pay off the next time a criminal tries to turn your convenience into their opportunity.
Good to Know
Fraudsters can change your delivery preferences without ever touching your porch by taking over your UPS, FedEx, or USPS profile. Tightening account security and setting alerts on day one prevents most redirects and unauthorized holds.