A €4.95 customs charge is the bait in a newly documented bpost phishing campaign. The fake delivery page then asks for something far more valuable: personal details, an IBAN and card information. Malwarebytes described the Dutch-language lure on September 18; the failed-delivery date inside the email is part of the story the scammers tell, not proof that a parcel exists. [1]
The useful distinction is not whether a delivery company can charge import costs. It can. It is whether the request matches the parcel record you open independently in the official app or tracking service.
A small charge opens a much larger form
The message borrows bpost’s identity and presents an unpaid fee as the obstacle between the recipient and a delivery. Its link passes through a URL shortener before reaching a lookalike website. One reported address starts with bpost but sits beneath my[.]id; another is bpost[.]center. Neither becomes an official bpost address because the brand appears in it.
The sequence changes the decision being made. At first, the recipient appears to be settling a minor delivery problem. By the banking form, they are supplying reusable financial identifiers. That shift deserves more attention than the size of the requested payment.
Example
Subject: Parcel on hold: customs fee requested
Display name: bpost
Sender: notice [at] delivery-example [dot] invalid
Message: Your parcel is on hold. A customs fee of €4.95 is requested.
Button: Review payment details
This illustrative example conveys the lure; the sender address is fictional. The reported email was in Dutch.

The page contradicts its own payment story
Malwarebytes’ screenshots show the form requesting an IBAN alongside card details and a payment amount. They also show language about receiving funds, although the email asks the recipient to pay. Security-sounding badges decorate the same page. A badge placed by the page’s author is not an independent assessment of the payment recipient.

That contradiction is useful evidence, but it is not a universal test. A polished copy could remove the awkward wording while keeping the data collection. Checking grammar alone would then miss the underlying problem: an unverified destination asking for banking information.
Real import charges have an independent check
bpost’s own payment guidance says genuine import-cost notifications can arrive by email, text or app notification. The cost breakdown is available in My bpost and Track & Trace, and payment can be made there. The company also says it will not request a bank transfer or ask for a bank account number for this process. [2] That makes the IBAN request especially relevant to this case.
Open the app yourself, or reach tracking from bpost’s official website, and use the shipment details you already have. Do not use the suspicious message as the route to verify itself. A copied logo or a small fee does not establish that the request belongs to your parcel.
If you supplied banking information, contact your bank through its known app or telephone number. bpost’s fraud guidance advises contacting the bank immediately and reporting suspicious messages to abuse [at] bpost [dot] be. [3] Describe exactly what you entered so the bank can determine the appropriate response.
The related T-Mobile points phishing campaign uses a different reason to begin a similar handover of information. A Gridinsoft domain reputation check can add context about a suspicious destination; a clean or unknown result cannot authenticate a payment request.
The €4.95 figure sets the apparent stakes. The form reveals the real ones. Verify the parcel independently before deciding whether any payment is due.
References
- Mieke Verburgh. “Fake parcel delivery messages steal your card and bank details.” Malwarebytes, September 18, 2026. Campaign analysis.
- bpost. “How can I pay the import costs?” Accessed September 18, 2026. Official payment guidance.
- bpost. “Phishing: conseils et aide en cas d’arnaque.” Accessed September 18, 2026. Official fraud guidance.

