What Should You Do If a Delivery Service Sends Driver or Courier Verification Messages You Did Not Request?

If a delivery service suddenly sends you driver or courier verification messages that you did not request, treat it as a security alert. These messages can signal an attempted account takeover, a misdirected login, or a phishing campaign designed to trick you into revealing one-time passcodes (OTPs). This guide explains how to tell the difference, what to do right now, and how to reduce your exposure to future attacks.

Common Reasons You’re Getting Unwanted Driver or Courier Verification Messages

  • Account takeovers in progress: A fraudster is trying to log in to your delivery account and trigger OTPs to your phone or email.
  • Phishing or smishing: You receive lookalike texts with links requesting your password, card info, or OTP. Some include realistic branding.
  • Mistyped number or recycled number: Another user (possibly a driver) entered your number by mistake, or you inherited a number linked to someone else’s account.
  • Bot-driven credential stuffing: Attackers use breached usernames/passwords to test logins across services. OTP prompts may follow.
  • SIM-swap reconnaissance: Attackers flood you with codes while trying to move your number to a new SIM they control.

Immediate Steps to Take

  1. Do not reply, click, or share any code. Never provide one-time passcodes, passwords, or recovery codes over text, email, or phone.
  2. Verify directly in the official app or website. Open the delivery service’s app or type its URL manually. Check for login alerts, sessions, or security notices in your account settings.
  3. Change your password right now. If an account exists with your number or email, reset the password using the official site. Use a strong, unique passphrase.
  4. Enable or re-enable multi-factor authentication (MFA). Prefer app-based authenticators over SMS where supported. Add backup codes and store them securely.
  5. Terminate unknown sessions. In account security settings, log out of all devices or revoke unrecognized sessions and tokens.
  6. Report the issue to the delivery service. Use their security or support channel to report unrequested verification messages and potential unauthorized activity.
  7. Silence or filter suspicious texts. On your phone, filter unknown senders and report spam. Do not block the official short code until you confirm it’s not needed for legitimate security alerts.

How to Confirm If a Message Is Legitimate

  • Sender details: Real services often use consistent short codes or in-app notifications. Scammers may use regular phone numbers or unfamiliar email domains.
  • Message content: Legit messages contain codes only and rarely include links. Scams push urgency, include links to odd domains, or ask for personal or card details.
  • Cross-check in the app: If the message is real, you’ll typically see a corresponding prompt or security log entry in your account.
  • No code sharing policy: Authentic companies do not ask you to read or forward a code to an agent or over the phone.

What If You Don’t Have an Account With That Delivery Service?

It could be a mistake or an attack that uses your phone number. Take these steps:

  • Do not engage with the message. Ignore and delete it.
  • Contact the company’s support via their official site. Ask them to remove your number if it’s mistakenly attached to an account and to flag attempts.
  • Watch for escalation. If verification requests continue, consider enabling call and text filters or temporarily blocking that sender while you confirm it’s not needed for any legitimate account you own.

If You Clicked a Link or Shared a Code

  1. Secure the account immediately. Change your password and enable MFA in the app or site. Log out of all sessions.
  2. Check connected accounts and payments. Review recent orders, addresses, saved cards, and payout settings (for driver/courier profiles). Remove unfamiliar details.
  3. Monitor your email and phone accounts. If attackers accessed your delivery account, they may target your email next. Change your email password and enable MFA.
  4. Review your bank and card statements. Dispute unauthorized charges promptly and request new cards if needed.
  5. Run a malware and browser check. If you installed a “security” app from a link, uninstall it and run a trusted antivirus scan. Remove suspicious browser extensions.

Lock Down Your Delivery and Gig Accounts

Delivery apps often store addresses, phone numbers, payment details, and driver license info (for couriers). Harden security with these practices:

  • Unique passwords for each service: Use a password manager to avoid reuse across delivery, shopping, and email accounts.
  • App-based MFA: Prefer authenticator apps or hardware keys. Avoid SMS MFA if the service supports stronger options.
  • Update recovery info: Ensure your email and phone are current, and remove recovery methods you don’t recognize.
  • Review third-party connections: Revoke access you don’t need (e.g., expense apps, integrations).
  • Check addresses and payout info: Confirm your home address, pickup locations, and any bank or payout destinations.

Reduce Future Exposure and Targeting

Attackers often source your phone number, email, and addresses from data breaches and people-search sites. Reducing exposure can cut down on unwanted verification prompts and fraud attempts.

  • Remove your data from people-search sites: Opt out of major data brokers to reduce public exposure of your number and addresses.
  • Use separate emails and numbers: Consider unique email aliases or a dedicated number for gig accounts and deliveries.
  • Harden your mobile account: Add a carrier account PIN and a port-out lock to defend against SIM-swap attacks.
  • Keep OS and apps updated: Timely updates close security holes that phishing kits can exploit.
  • Be breach-aware: If a service suffers a breach, reset passwords there and anywhere you reused one, and watch for phishing tied to that brand.

Signs of an Account Takeover Attempt

  • Multiple back-to-back OTP texts or emails you didn’t initiate
  • Unrecognized login alerts or new device sign-ins
  • Password reset emails you didn’t request
  • Locked-out sessions or changed recovery settings
  • Unexpected orders, deliveries, or payout changes

How to Report and Document the Incident

  • Contact the delivery service’s security or fraud team: Provide timestamps, the sender/short code, and screenshots (excluding your code digits).
  • Report phishing texts and calls: Forward SMS phishing (smishing) to your carrier’s spam number (often 7726 in many regions). Use your device’s “Report Junk” feature if available.
  • File a local incident note: Keep a personal log of dates, messages, and steps taken. This helps if charges or identity issues arise later.

Special Considerations for Drivers and Couriers

Driver and courier profiles may include license numbers, insurance details, tax info, and payout accounts, making them high-value targets.

  • Protect payout rails: Enable MFA on your bank and payment apps. Turn on transaction alerts for deposits and withdrawals.
  • Validate all “support” contacts: Scammers impersonate driver support to “verify” your identity and steal OTPs. Initiate contact through the in-app help channel only.
  • Use document redaction where possible: If the platform allows, hide sensitive digits on uploaded documents and never send IDs over text.
  • Regular security reviews: Set a monthly reminder to review security settings, devices, and payout destinations.

Protecting Your Financial Identity

Unrequested verification messages can be an early sign that your broader digital identity is being targeted. In addition to securing delivery apps, monitor for indicators of financial misuse such as new accounts, hard inquiries, or unusual transactions. Credit and identity monitoring tools can help you spot and respond to these issues more quickly.

If you want an optional, consolidated way to track credit changes, inquiries, and identity-related alerts after a suspicious event, consider evaluating SmartCredit’s privacy, credit, and identity monitoring as a next step.

Practical Do/Don’t Checklist

  • Do: Verify in the official app or website, change passwords, enable MFA, and review sessions.
  • Do: Set carrier PINs and port-out locks, and use a password manager.
  • Do: Remove your info from data brokers and keep software up to date.
  • Don’t: Share codes with anyone or click links in unexpected texts.
  • Don’t: Assume a brand logo means a message is safe.
  • Don’t: Reuse passwords across delivery, email, and banking.

When to Seek Additional Help

  • Persistent verification prompts: If they continue for more than a few days after securing accounts, escalate with the company’s security team.
  • Unauthorized charges or orders: Contact your bank or card issuer immediately and request new credentials if needed.
  • Possible identity theft: If personal details are misused beyond the delivery account, consider placing fraud alerts or security freezes with credit bureaus as appropriate in your region.

Conclusion

Unrequested driver or courier verification messages are a strong indicator that someone is probing your accounts or your contact information is being misused. Act quickly: ignore the message content, verify through official channels, change passwords, enable stronger MFA, and review devices and sessions. Then reduce future risk by removing exposed personal data, strengthening your phone account security, and monitoring for financial and identity changes. A few fast steps today can stop an account takeover and protect more sensitive parts of your digital life.

Good to Know

Legitimate companies almost never ask you to read back a verification code or share a one-time passcode with a caller or texter. If someone asks for it, they’re trying to take over your account.