Recognizing Phony Address-Change Emails That Precede Package Redirection or Account Takeover

Criminals increasingly send “address change” emails that look like they’re from a delivery company, postal service, or retailer. The goal is simple: get you to click a link to “confirm” or “correct” your address so they can redirect a package, harvest your login, or take over your account. This guide explains how the scam works, the signs to watch for, and what to do immediately if you receive one of these messages.

Why Scammers Use Address-Change Emails

Address-change notices feel urgent. No one wants a package to go missing, so people click fast. That urgency helps criminals:

  • Intercept valuable packages: Redirect shipments or create new shipping labels to an address they control.
  • Capture logins: Steal retailer, carrier, or email account credentials using a fake login page.
  • Pivot to identity theft: Once in your account, they may access stored payment methods, personal data, and order history.
  • Push malware: Attachments or links may install spyware to capture more passwords.

How the Scam Typically Unfolds

  1. Hook: You receive an email that says “Your address was changed” or “Delivery on hold: confirm address.”
  2. Pressure: A deadline appears (e.g., 24 hours) or the threat of package return.
  3. Impersonation: The message uses familiar logos for carriers (USPS, UPS, FedEx, DHL) or retailers you’ve used.
  4. Phishing link: The button leads to a site that looks real but captures your credentials or payment details.
  5. Monetization: Criminals redirect packages, change your account email/phone, or attempt purchases and new orders.

Red Flags in Phony Address-Change Emails

  • Mismatched sender details: The display name may say a known brand, but the actual “From” address uses odd domains (e.g., random letters, extra words, foreign TLDs).
  • Generic greetings: “Dear Customer” instead of your full name or a masked name you use with that service.
  • Unrecognized order or tracking numbers: They may be missing, invalid, or not linked to any known purchase.
  • Links that don’t match the brand: Hover over buttons; phishing URLs often add dashes, extra subdomains, or misspellings.
  • Requests for sensitive data: Real carriers rarely ask for full SSNs, full card numbers, or security answers via email.
  • Spelling or formatting issues: Awkward grammar, off-brand colors, or low-quality logos.
  • Unexpected attachments: Shipping updates rarely arrive as .zip, .exe, or macro-enabled documents.
  • Unusual urgency or threats: “Act immediately or your account will be deleted.”

Legitimate vs. Scam: Quick Comparisons

  • How you’re addressed: Legitimate messages often use your name or masked account info; scams use generic salutations.
  • Where you’re sent: Legitimate notices direct you to log in through the official site/app; scams push you to click a link in the email.
  • What they ask for: Legitimate updates may ask you to verify a small detail inside your logged-in account; scams ask for full credentials, card data, or one-time codes directly from the email link.
  • Consistency with your activity: If you didn’t order anything or request changes, treat any message as suspicious.

Safe Ways to Verify Any Address-Change Message

  • Do not click links. Instead, open the official app or type the official domain into your browser.
  • Use your order history: Check your recent orders or shipments in your account to see if anything is pending or flagged.
  • Validate tracking numbers: Copy the tracking ID and paste it into the carrier’s official site (not via the email link).
  • Call known support numbers: Use the number listed on the retailer or carrier’s official website—not the one in the email.

What To Do If You Already Clicked

  • Close the tab immediately. If you downloaded a file, disconnect from the internet and scan your device with reputable security software.
  • Change your password on the real site: Go directly to the official website or app.
  • Enable two-factor authentication (2FA): Prefer app-based or hardware key methods; avoid SMS if possible.
  • Check recent activity: Review logins, address book, payment methods, and orders. Revoke unknown devices and sessions.
  • Contact the carrier/retailer: Ask them to freeze shipments, confirm your address, and block redirection.
  • Monitor financial accounts: Look for test charges, new orders, or added payment methods.
  • Watch your credit and identity signals: New accounts or address changes elsewhere can follow. Consider enrolling in a reputable credit and identity monitoring service to spot suspicious changes early. A resource to explore is SmartCredit for privacy, credit monitoring, and identity protection.
  • Report the phishing email: Forward to the impersonated brand’s abuse address and report to your email provider as phishing.

Specific Tips by Sender Type

Major Carriers (USPS, UPS, FedEx, DHL)

  • USPS: Official messages originate from usps.com. USPS change-of-address happens through USPS’s website or in person, not via links sent out of the blue.
  • UPS: UPS My Choice alerts appear in your dashboard. Check tracking at ups.com using the official tracking page.
  • FedEx: FedEx will not request full payment details via a link to “release” a package unexpectedly.
  • DHL: DHL often includes a shipment number you can verify on dhl.com; beware of lookalike domains.

Retailers and Marketplaces

  • Order history is king: If the email claims an address change for a recent purchase, verify inside your account’s order page.
  • Saved addresses and payment methods: Confirm no new addresses or cards were added; remove anything unfamiliar.
  • Beware of redirected returns: Scammers sometimes alter the return address or intercept returns; confirm RMA details inside your account.

Protective Settings That Block Package Redirection Attacks

  • Harden email security: Use spam filtering, disable automatic image loading, and consider separate inbox aliases for shopping.
  • Unique passwords and a manager: Password reuse lets one phish unlock many accounts. Use unique, long passwords stored in a reputable manager.
  • 2FA on all shopping and carrier accounts: App-based codes or security keys stop many takeover attempts even if a password leaks.
  • Lock down your address book: Periodically remove old addresses and confirm your default shipping location.
  • Monitor for new accounts and changes: Create alerts for login attempts, address changes, and new payment methods wherever possible.
  • Credit and identity monitoring: If attackers pivot to opening new accounts or changing your personal data elsewhere, you want fast alerts so you can act quickly.

How Criminals Bypass 2FA—And How You Can Resist

  • Reverse proxies and fake login pages: Attackers relay your credentials and one-time code in real time. Defend with hardware keys (FIDO2) where supported.
  • Push fatigue: Repeated prompts try to make you tap “Approve.” Reject unknown prompts and change your password immediately.
  • SIM swapping: If your phone number is hijacked, SMS codes go to criminals. Use app-based 2FA or security keys, and add a carrier PIN/port-freeze with your mobile provider.

If a Package Is Already Misdelivered or Redirected

  • Contact the carrier immediately: File a package intercept or hold request and open a fraud claim.
  • Notify the retailer or marketplace: Ask for address-lock and review of recent account activity.
  • Document everything: Save emails, screenshots, and tracking logs for disputes and police reports if required.
  • Freeze what matters: Remove stored payment methods and consider placing a temporary credit freeze if identity theft indicators emerge.

Sample Safe Response Workflow

  1. Pause: Don’t click the email link.
  2. Verify: Open the official app or type the brand’s domain manually.
  3. Check: Look at orders, tracking, and recent account changes.
  4. Secure: Change passwords, turn on 2FA, and review login history.
  5. Monitor: Watch bank statements, email filters, and your credit/identity alerts for a few weeks.

Prevention Checklist You Can Reuse

  • Never click “confirm address” from an email. Verify in the official app or site.
  • Hover to preview links; don’t trust display names or logos.
  • Use unique passwords and app-based 2FA on carrier and shopping accounts.
  • Set up account alerts for address, password, and payment changes.
  • Keep your device and browser updated; run reputable anti-malware.
  • Use separate email aliases for deliveries, shopping, and banking.
  • Regularly review saved addresses and payment methods; remove what you don’t use.
  • Monitor your credit and identity signals to catch spillover fraud quickly.

Conclusion

Phony address-change emails exploit urgency to steal logins and redirect packages. Treat every unexpected shipping or address alert as suspicious until you verify directly inside the official app or website. With a simple workflow—don’t click, independently verify, secure accounts, and monitor for fallout—you can stop package redirection and prevent a minor scare from turning into full account takeover or identity abuse. If you suspect broader exposure, consider credit and identity monitoring to get early warnings and act fast on any unusual activity.

Good to Know

Legitimate carriers and retailers rarely ask you to confirm an address change through a generic link; they typically direct you to log in to your account or provide a reference number you can verify independently.