Cybercriminals are impersonating Australia Post in a sophisticated phishing campaign designed to steal personal information, credit card details and one-time passcodes (OTPs) under the guise of a parcel being held by Australian Border Force.
MailGuard has intercepted this campaign within its filter network, protecting customers from a convincing email that claims a shipment is awaiting customs clearance. The scam exploits the trust Australians place in Australia Post and the urgency associated with delayed deliveries to pressure recipients into taking immediate action.
How the Scam Works
The email uses the subject line:
"Your shipment is currently being held by Australian Border Forces as part of the customs clearance process"
The phishing email contains a single link that appears legitimate but redirects recipients through an intermediary tracking URL before taking them to a newly registered phishing website designed to closely resemble Australia Post's online services.

Example phishing content shown using Australia Post branding. Not affiliated with Australia Post.
Rather than attempting to infect a device with malware, the objective is to harvest as much personal and financial information as possible over several stages.
The first page presents what appears to be an Australia Post "Address verification" form.

Example phishing content shown using Australia Post branding. Not affiliated with Australia Post.
Recipients are told they must confirm their delivery details before a parcel can proceed through customs. The page requests:
• Full name
• Residential address
• Mobile phone number
• Email address
• Postcode
An order summary displayed alongside the form shows a Parcel Box Medium purchase and a total payable amount of $48.20, adding credibility to the scam.
The website closely mimics Australia Post branding and layout, making it convincing at first glance. However, the website address is not an Australia Post domain, an important warning sign that the site is fraudulent.

Example phishing content shown using Australia Post branding. Not affiliated with Australia Post.
After submitting personal information, victims are taken to a second page claiming customs duty and taxes must be paid before delivery can proceed.
The page requests:
• Credit card number
• Expiry date
• CVV
The scam attempts to legitimise the payment by displaying an itemised order summary and repeating Australia Post branding throughout the page.

Example phishing content shown using Australia Post branding. Not affiliated with Australia Post.
Following submission of payment details, victims are shown an "Authentication in progress" screen while the attackers attempt to validate the stolen payment information.

Example phishing content shown using Australia Post branding. Not affiliated with Australia Post.
The next stage requests a one-time passcode (OTP), typically the verification code sent by a bank during online card authentication.
Capturing this code enables criminals to complete fraudulent transactions using the victim's payment card.
An error occurs, suggesting incorrect details have been entered, with the scam simply prompting for re-entry of the code to confirm the number and by time, before ultimately redirecting users to the legitimate Australia Post website, helping disguise the fraud and reducing suspicion.

Example phishing content shown using Australia Post branding. Not affiliated with Australia Post.
Why this campaign is convincing
Unlike traditional phishing emails that ask recipients to log in immediately, this campaign unfolds over multiple stages, each designed to build trust while collecting increasingly sensitive information.
The combination of:
-
Australia Post branding
-
references to Australian Border Force
-
parcel delivery urgency
-
realistic order summaries
-
staged data collection
- eventual redirection to the legitimate Australia Post website creates a highly convincing experience that may deceive even cautious users.
Stay Safe, Know the Signs
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
- Aren’t addressed to you personally.
- Are unexpected and urge immediate action.
- Contain poor grammar or miss crucial identifying details.
- Direct you to a suspicious URL that isn’t associated with the genuine company.
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
One Email Is All That It Takes
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.




