When the Parcel is Real, But the SMS is not: The Evolution of Courier Scam in Kenya
Allan Juma, Lead Cybersecurity Engineer at ESET
By Allan Juma, Lead Cybersecurity Engineer at ESET
Delivery notifications are the most routine messages received by Kenyans. Ordering, paying and receiving goods takes place almost entirely using a mobile device. What makes this market unique is not that Kenyans shop on their phones; this is a global reality, but that for the Kenyan shopper, the entire transaction lives in one place.
According to the Communications Authority of Kenya (CA)’s latest sector statistics, Kenya’s mobile money subscriptions increased to 53.4 million at a growth rate of 3.9%, with an additional two million mobile money accounts added in just three months from January to March 2026. This dependence and growth have created a unique ecosystem where everything from the order to the payment to the delivery update arrives in the same channel, and it is also creating a unique threat environment.
Fraud is rising alongside online deliveries, particularly in the last mile, because of the Kenyan mobile infrastructure, and both customers and the delivery riders are being targeted. For customers, the scam looks like a fake SMS about a delayed parcel, a spoofed link mimicking a real courier website, and the customer being asked to pay a small release fee. The moment they do, their payment details are stolen.
There have been several examples of these scams promoted on social media platforms. In July, the Postal Corporation of Kenya put several alerts on social media, warning customers of potential scams. These are getting increasingly sophisticated and use scare tactics to make customers click on fake links.
For the delivery rider, the fraudsters are placing a real order for pay on delivery and the riders arrive at a secluded location where the package is taken and the scammer disappears. In some cases the delivery riders are robbed or harmed as a result.
The agent layer is one of the key areas where this fraud is being felt and has come about as a result of this growth and demand. Mobile money is being placed at the heart of core financial infrastructure rather than as the add-on feature it has been in the past, which is putting the customer, company and delivery rider at risk. This infrastructure relies on the SMS as its centralised signalling rail, and any compromise within this channel can affect the entire lifecycle of the transaction. There isn’t a second, independent evidence trail – a digitally signed receipt in an app or an email – and this makes it challenging to detect fraud and makes user verification increasingly difficult and fragile. Everything lives within the mobile system and through the SMS.
Fraudsters are taking advantage of this linear system by copying the fulfilment flow with such accuracy that customers are finding it increasingly hard to detect the fakes. The messages announcing a held parcel or a missed delivery attempt and asking for a clearance or redelivery fee are designed to come across as incredibly authentic. The technique doesn’t require any real technical sophistication as it relies on the fact that a message about a delayed parcel is ordinary enough (and the fake branding believable enough) that most people respond before they assess it.
Companies need to change their payment collection processes. The point where the delivery scam converts is at the payment instruction, so if companies break this link, they are reducing the risk of customers clicking on fake links or SMS’s. Many have started to move their payment collection process off M-Pesa numbers and onto verified Paybill or Till numbers. Fraudulent sellers are flagged by their requests to pay using personal M-Pesa numbers instead of the official numbers, so this helps to break up reliance on a single channel while simultaneously reducing risk.
It’s important for companies to also consider training their delivery riders to spot suspicious addresses or sudden changes – the same goes for customers. Make sure people think about what they’re being asked to do or to double-check any order changes or messages. This will also give them the upper hand when it comes to managing unusual situations, especially if companies prioritise giving customers and riders a way of escalating a problem. Implementing one-time passwords for handovers along with real-time tracking can also support every person in the chain, improving visibility and providing ample opportunity to raise an alert.
While many of these additional measures do put the onus of proof on both the business and the consumer, they do help minimise the risks. It is the age-old struggle between functionality and security and speed versus safety – the whole appeal of mobile money is its instant gratification and resolution. This means that additional security has to balance speed and that it should only show up when a transaction looks wrong, like a new payee or an unusually large amount or several transfers at speed.
Ultimately, fraudsters are always going to find new ways of hacking into the courier process and disrupting trust and transactions. Companies need to find ways of diverting customers back onto secure pathways by remaining consistent and clear, using the same patterns and processes, and using language that is accessible and easy to understand. It costs nothing to be consistent and clear, but it adds meaningfully to security and customer protection.
