I Clicked a USPS Text Scam Link — What Should I Do Now?
Free firstChoose what happened
Start with the furthest step you took. If more than one applies, also follow the earlier steps that matter to you. A text claiming to be from another delivery company calls for the same first response.
What happened?
1. I only read the text
Do not reply or use its link. If you are expecting a package, check the retailer or USPS site you open yourself.
If it impersonates USPS, forward the message to spam@uspis.gov or to 7726 (SPAM), then delete or report it as junk.
No account change, scan, or purchase is needed just because the text arrived.
2. I opened the link
Close the page. Do not enter anything or approve a download or notification.
If a file downloaded, do not open it; remove it. Keep your phone or computer software updated. If you opened a download or suspect harmful software, run the device’s security scan.
Check a real delivery independently through the retailer or USPS site you open yourself.
If you only opened a page and entered nothing, you do not need to replace a card or buy monitoring just for the click. If you installed something, use step 6.
3. I entered my name, address, or phone number
Stop communicating with the sender. Expect follow-up texts or calls that may refer to the details you supplied; verify any delivery request independently.
If you also supplied a Social Security number, bank details, or other sensitive identity data, use IdentityTheft.gov for steps tailored to that information.
A name and delivery address alone do not automatically mean identity theft or justify a paid monitoring service. If you also entered a card or password, follow the matching section below.
4. I entered credit or debit card information
Call the card issuer immediately using the number on the card or in the issuer’s app. Say the card details were entered on a fake delivery site; ask about blocking or replacing the card and checking recent transactions.
Watch for charges. If one appears, report it to the issuer promptly and follow step 7.
If you also shared other sensitive identity information, use IdentityTheft.gov for tailored next steps.
Do not use a phone number from the scam text or site.
5. I entered a password
Open the real account from its app or a saved address and change the password immediately. If you cannot sign in, use that provider’s official recovery process.
Change that password anywhere else you reused it, beginning with your primary email and financial accounts. Review recent sign-ins and sign out other sessions if the provider offers that option.
Turn on the provider’s supported two-step verification after access is secure. If you shared a verification code too, contact the affected provider through its official support channel.
Stop entering passwords or payment details on that device. Disconnect it from the network while you assess the installation.
Remove the unfamiliar app or profile through your device’s settings. Update the operating system and run its available security scan. If removal is unclear or the device still behaves suspiciously, seek help from the device maker or a trusted technician.
From a device you trust, change any passwords entered after installation and contact the card issuer if payment details were exposed.
If the page instructed you to paste commands or allow remote access, see the fake CAPTCHA and remote access Guides.
7. I already see a charge or lost money
Contact the card issuer, bank, or payment service immediately through its official app or known number. Report the transaction and ask what recovery or dispute options apply to your payment method.
Save the text, website address, receipts, transaction details, and any communication. Do not pay anyone promising guaranteed recovery.
Report the fraud to ReportFraud.ftc.gov. For internet-enabled financial crime, you can also file with FBI IC3. If someone used your identity to open accounts or make charges, follow your personal recovery plan at IdentityTheft.gov.
If you also entered a password or installed something, complete those sections after contacting the payment provider.
Where to report the text
For a USPS impersonation text, USPIS accepts reports at spam@uspis.gov; forwarding to 7726 (SPAM) helps your carrier identify the sender. For fraud or financial loss, use the FTC reporting route above; IC3 is an additional route for internet crime. Do the protective steps for your situation first.