Security researcher Troy Hunt recently received an SMS claiming FedEx required payment of duty and taxes on an incoming parcel. The message ticked nearly every box of a classic phishing attack: urgency language, capitalization errors, a suspiciously short shipment number matching the payment amount, and a link to “bpoint.com.au” rather than an official FedEx domain.

When Hunt polled his followers, 87% of over 4,000 respondents voted the message “dodgy AF.” The red flags were numerous. FedEx typically capitalizes the “E” in its name. The currency wasn’t specified. The contact number in the SMS differed from the one on FedEx’s official website. Most concerningly, Hunt discovered the payment link used simple URL parameter tampering—changing the tracking number, customer name, and amount required no technical sophistication, functioning more like every phishing site ever than a legitimate payment service.
BPOINT, the payment processor listed, is operated by Australia’s Commonwealth Bank, yet appeared vulnerable to basic manipulation. Hunt noted this represented “a completely parallel issue to phishy FedEx SMSs.”
Confronted with this ambiguity, Hunt followed standard security advice: verify directly through official channels. He accessed FedEx’s website but found no mention of duty or tax payments. He called the customer support number listed on FedEx’s website—different from the SMS number—and navigated a voice system that became unresponsive, eventually connecting with an operator who confirmed the shipment (a Prusa 3D printer valued at US$799) was indeed subject to inbound fees.
Three days after the initial SMS, an email arrived with matching payment details and—crucially—the Prusa invoice as an attachment. The invoice provided the missing authentication: it contained Hunt’s order number, price, and shipping details that could not have been known to a phisher.
“87% of you were wrong,” Hunt concluded, noting the message was legitimate.
The incident underscores a genuine problem. Hunt cited Australian Communications and Media Authority data showing 336 million scam SMSs were blocked in recent reporting, but acknowledged authorities cannot measure how many fraudulent messages slip through undetected. Australians alone lose over AU$3 billion annually to scams. When legitimate communications share the characteristics of phishing attacks—poor formatting, suspicious domains, urgency tactics—distinguishing real from fake becomes nearly impossible without access to original purchase records or direct verification through official websites.
Key facts
- An SMS claiming FedEx required duty payment on an incoming parcel exhibited classic phishing characteristics, with 87% of respondents rating it suspicious
- The payment link used simple URL parameter tampering, allowing the shipment number, customer name, and amount to be changed without technical sophistication
- BPOINT, operated by Commonwealth Bank, provided the payment processor but appeared vulnerable to basic manipulation
- FedEx customer support contact numbers differed between the SMS and the official website
- The message was ultimately legitimate, confirmed by an email three days later that included the original Prusa invoice as authentication
- Australian authorities reported blocking 336 million scam SMSs but cannot measure how many fraudulent messages escape detection
