Free cookie consent management tool by TermsFeed Actualizare preferințe cookie-uri Skip to main content

ANCOM

In recent years, there have been reports of fraud attempts in which the identity of well-known postal service providers is misused to deceive users. Through SMS or emails, users are informed that they have a parcel awaiting delivery, that they need to update their delivery address, pay an additional fee, or select a collection point. In reality, the messages contain links to fake websites designed to collect confidential information or induce users to make payments.

In this context, the National Authority for Management and Regulation in Communications (ANCOM) recommends users to exercise caution and carefully check whether the messages received really come from postal service providers.

Examples of messages that should raise suspicion

Fraud attempts typically use wording designed to create a sense of urgency and encourage users to click on a link or provide personal information. In reality, this is a trap devised to direct users to a phishing website, i.e. a fake website that mimics the official page of a postal or courier service provider. Such fraud attempts are also frequently encountered during holiday periods.

Examples of such messages include:

  • “Your parcel could not be delivered. Please update your address by clicking the link below.”
  • “Payment of an additional fee is required to complete the delivery. Make the payment here.”
  • “Select the collection point for your parcel by clicking the following link.”
  • “Your parcel will be returned to the sender if you do not confirm delivery within the next 24 hours.”
  • “Update your delivery details to avoid cancellation of the shipment.”
  • ” You have a parcel addressed to your number. Choose a locker.”
How can users recognize a fraud attempt?

ANCOM advises users to be cautious if they receive an SMS or email that:

  • requests an urgent update of delivery details for a parcel;
  • requests payment of an unexpected fee to complete the delivery;
  • contains a link to a website whose domain differs from the provider’s official domain;
  • creates a sense of urgency by warning that the shipment will be returned or cancelled unless the user acts immediately.
  • asks the user to click on a link and sign in using their personal WhatsApp account.
  • requests personal or banking information.
What do postal service providers generally not request?

If an SMS or e-mail received on behalf of a postal service provider asks users for passwords, verification codes or full bank card details, ANCOM advises the recipients to treat it with suspicion! ANCOM emphasizes that  postal service providers do not normally request, by SMS or e-mail:

  • users’ account passwords;
  • verification codes received via SMS or messaging apps;
  • authentication codes for applications such as WhatsApp;
  • full bank card details (card number, expiry date and CVV/CVC);
  • other confidential information that can enable access to users’ accounts or funds.
How can users protect themselves?

ANCOM recommends some simple precautions that users can take to avoid the inconvenience caused by fraud attempts:

  • always check whether the message comes from an official source.
  • access the delivery information directly through the postal service provider’s official website or application, rather than using links received by SMS or e-mail;
  • do not enter personal or banking information on websites whose authenticity cannot be verified;
  • never share verification codes received by SMS or through messaging applications with anyone;
  • if they have doubts about the authenticity of a message, contact the postal service provider directly using the official contact details published by the provider.

If they receive a suspicious message, ANCOM advises users not to click on any links under any circumstances and not to provide the requested information. Users are encouraged to report the incident to the provider whose identity has been fraudulently impersonated and to the competent authorities. If a user has already entered banking details or authorized a transaction, they must immediately contact the card-issuing bank to have the card blocked and follow the bank’s instructions.

Such fraud attempts can be reported to the National Directorate of Cyber Security (DNSC) by calling 1911 or via pnrisc.dnsc.ro.

Another fraud method: unsolicited cash-on-delivery parcels

Another type of fraud that ANCOM advises users to be aware of involves unsolicited cash-on-delivery parcels. In such cases, recipients are persuaded to pay for parcels that they have not ordered.

To avoid such situations, users should always check the sender’s details and confirm whether they or a family member are actually expecting the parcel. If the shipment is unknown or appears suspicious, users are advised to refuse delivery and not pay the cash-on-delivery amount.

Users who are victims of fraud must inform the postal service provider and report the matter to the police so that the appropriate investigations can be carried out.