Shipping and logistics phishing: the prevalence of DHL, FedEx, and UPS impersonation

Every business that ships or receives goods trusts a handful of carrier brands completely. When a notification arrives from DHL, FedEx, or UPS, employees act on it quickly and without much scrutiny. Attackers have understood this for years.

According to Cloudflare’s brand phishing research, DHL ranks fourth among the most impersonated brands across all industries. Shipping and logistics collectively represent the fourth most-targeted industry for phishing impersonation globally. This ranking is a direct reflection of how these brands occupy a trusted, action-oriented place in day-to-day business communication.

Shipping phishing, broadly defined as phishing attacks that impersonate delivery and logistics companies to steal credentials, extract payment, or install malware, is one of the most effective attack categories in operation today. Understanding why it works, and how it reaches inboxes in the first place, is the starting point for defending against it.

Why logistics brands are prime impersonation targets

A phishing attack requires two things to succeed: a sender the target will trust, and a reason for the target to act. Carrier brands deliver both in abundance.

DHL, FedEx, and UPS communicate with business recipients constantly, across procurement teams, operations staff, finance departments, and individual employees who order supplies. Delivery notifications, tracking updates, customs clearance alerts, and missed delivery notices are normal and time-sensitive. Nobody questions an email from DHL when they’re expecting three shipments that week.

This is compounded by the nature of shipment-related actions. When a delivery fails or a customs hold is flagged, the recipient’s instinct is to resolve it fast. A delayed shipment has real business consequences. In such cases, all the attacker has to do is frame the lure convincingly and let the pressure do the rest.

There’s also a scaling advantage. Unlike attacks that require knowledge of a specific internal relationship, shipping impersonation requires no prior reconnaissance. The attacker doesn’t need to know who the target does business with, only that they receive deliveries. This means a single phishing campaign template can be deployed against millions of targets without modification.

The main lure types and how they work  

Shipping phishing isn’t a single tactic. It encompasses several distinct campaign types, each engineered around a specific scenario that prompts action.

Fake tracking notifications 

The most common variant. The email arrives with a realistic subject line (“Your DHL shipment is ready for pickup” or “UPS: Action required on your delivery”) and includes a tracking number, a branded layout copied faithfully from the real carrier, and a button or link to “track your package.” The link doesn’t lead to the carrier’s site, but to a lookalike phishing page designed to harvest credentials or deliver malware. Because the email mirrors the visual language of hundreds of legitimate notifications the recipient has seen before, the threshold for suspicion is low.

Delivery failure lures 

These emails claim that a delivery was attempted but failed, and that the recipient must confirm their address, reschedule, or pay a small redelivery fee to release the package. The urgency here is slightly higher. The implication is that the shipment will be returned to the sender if no action is taken. Research by Abnormal Security identified a FedEx campaign that escalated this pretext further, claiming a delivery had been attempted and that the recipient must verify their destination address via a provided link. The specificity of the claim, combined with polished branding, made it difficult for standard secure email gateways to flag as malicious because the emails contained no known-bad payloads or domains.

Customs fee pretexts 

This is a particularly effective variant targeting businesses with international supply chains. The email claims that a shipment is being held at customs pending payment of a clearance fee, typically a small amount designed to seem credible without triggering alarm. In most cases, victims are directed through a multi-step process: an information page presenting realistic shipment details, including a tracking number and weight, followed by a payment page collecting full card details. The small fee is a deliberate design choice. It lowers resistance and frames the interaction as routine administration rather than a financial risk.

Credential-harvesting via document shares 

A less visible but increasingly documented variant involves emails purporting to share shipping documents such as invoices, bills, or customs declarations, via links to services like Google Firebase or Quip. The document turns out to be a credential-harvesting page for work email accounts. Hosting the phishing page on a legitimate cloud service is a deliberate evasion tactic: the domain passes URL reputation checks because the hosting provider itself is trusted.

What makes these attacks psychologically effective  

Shipping phishing succeeds because it exploits several well-established psychological mechanisms simultaneously.

The first is expectation. Most people who receive a shipping notification are expecting one. Even if a specific message isn’t directly tied to anything they recall ordering, the cognitive leap to “maybe this is related to that supplier order from last week” is small and natural. That ambiguity works in the attacker’s favor.

The second is authority. DHL, FedEx, and UPS are household names with decades of brand equity. When their logo appears in an email, the trust transfer is immediate. Attackers invest in accurate brand replication because visual fidelity directly increases click rates.

The third is urgency. Delivery scenarios are inherently time-bound. A package held at customs will not wait indefinitely. A missed delivery will be returned. A shipment status needs to be confirmed before dispatch. The psychological pressure to act before something goes wrong is already embedded in the scenario.

The fourth is mobile context. Many employees review email on their phones during transit or between meetings. Mobile email clients typically display only the sender’s display name, not the full address. An email from “DHL Express Notifications” looks legitimate on a mobile screen even if the underlying address is entirely unrelated to DHL’s actual domains.

Detection signals for end users and IT teams 

Despite the sophistication of these campaigns, there are consistent signals that surface across most shipping phishing attempts.

What end users should check 

The most reliable check is the sender address itself. Legitimate carrier emails originate from authenticated domains such as @dhl.com, @fedex.com, @ups.com, and will pass DMARC validation. A sender address that uses a variation (dhl-notifications.com, fedex-support.net, ups-tracking.info) should be treated as suspect immediately. The same applies to links: hovering over a tracking button before clicking will reveal whether the destination URL matches the carrier’s actual domain.

Requests for payment via email are a near-universal red flag in this category. Neither DHL, FedEx, nor UPS solicits customs fees or redelivery charges through email links. FedEx has stated explicitly in its own guidance that legitimate communications will not pressure recipients to act urgently or request personal or financial information for in-transit shipments. Any email that does so isn’t from the carrier.

What IT and security teams should monitor 

The challenge for security teams is detection at the infrastructure level before users encounter these messages at all. Shipping phishing campaigns frequently change their payload domains, making blocklist-based detection unreliable. Many of these campaigns were notable precisely because they contained no malicious links or attachments to trigger traditional signature-based filters; the payload was a legitimate-looking web form on a domain registered specifically for the campaign.

The signals that matter at the infrastructure level are authentication failures, display name spoofing patterns, and lookalike domain registrations. Procurement and operations teams receiving a high volume of carrier communications are a focus for monitoring, because attackers researching an organization will target the inboxes most likely to find shipping-related messages unremarkable.

How email security solutions filter shipping phishing

The defining characteristic of well-crafted shipping phishing is that it’s designed to evade the defenses that catch attacks. There are no misspellings for a grammar-based filter to catch. There may be no malicious attachment. The link may point to a domain registered hours before deployment, with no established reputation. The visual design is indistinguishable from the real carrier’s template.

Filtering these attacks requires layered detection that operates across multiple signals rather than any single indicator.

SPF, DKIM, and DMARC enforcement is the foundation. When an attacker sends an email claiming to be from dhl.com, the email headers will typically show a misalignment between the claimed sender domain and the actual sending server. A properly configured email security layer will surface this misalignment and either quarantine the message or fail delivery entirely.

Beyond authentication, effective filtering for this category relies on contextual and behavioral analysis. That means detecting display name spoofing, identifying lookalike domains registered recently with high structural similarity to known carrier domains, and flagging the specific combination of certain red flags.

This is where cloud-native email security solutions, like Zoho eProtect, add meaningful value. Rather than relying solely on signature-based detection, platforms that apply real-time threat intelligence and multi-layer analysis can catch campaigns that would otherwise pass through gateway-level filtering.

Organizations that manage high shipment volumes should also consider whether their carrier communication workflows create predictable patterns that attackers could exploit. If procurement teams always receive DHL invoices on the same cadence, an attacker who knows that rhythm can time lures accordingly.

Wrapping up

Shipping phishing persists because the underlying logic is sound. It exploits a trusted brand, a scenario with built-in urgency, and communication habits that make scrutiny feel unnecessary. The organizations most exposed aren’t necessarily the least security-aware. They’re often the ones receiving the highest volumes of legitimate carrier communication, where one malicious email among dozens of real ones has the best chance of going unquestioned.

The defense isn’t primarily about training users to be more suspicious of every tracking email, though awareness helps. It’s about ensuring that authentication failures never reach the inbox, that lookalike domains are caught before delivery, and that the infrastructure separating a convincing phishing email from a legitimate carrier notification is doing its job. Those are filtering and configuration problems, and they’re solvable ones.

Leave a Reply

Your email address will not be published. Required fields are marked

By submitting this form, you agree to the processing of personal data according to our Privacy Policy.

You may also like