UPS discloses data breach after exposed customer info used in SMS phishing

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
(Image credit: weerapatkiatdumrong / Getty Images)

Global shipping giant UPS has confirmed it has experienced a data breach that may have exposed some customer data.

According to Emsisoft threat analyst Brett Callow, who announced the discovery via Twitter, customers have been receiving a letter from UPS which says, “UPS is aware that some package recipients have received fraudulent text messages demanding payment before a package can be delivered.”

Despite promises to be investigating via an internal review, and the subsequent revelation of how the scammer got hold of customer information, UPS has been scrutinized for the way it handled the event.

UPS phishing scam results in data breach

The letter from UPS Canada starts by generally describing phishing and smishing attacks, leaving it until halfway through before disclosing that some customers have actually been affected. It's unclear whether other regions that UPS operates in are also affected.

Callow said in the thread: “This is not what a data breach notification should look like. They should immediately make clear what they are or else people will do what I almost did and put them in the recycling unread.”

UPS has confirmed that the attacker abused its package look-up tool to obtain information about the delivery, which it says “potentially [included] a recipient’s phone number.” The phishing scam uses victims’ phone numbers to demand payment for a package ahead of delivery.

It is believed that details, including the recipient’s name, shipment address, and “potentially phone number and order number” were obtained between February 1, 2022 and April 24, 2023, over a period spanning more than a year.

Bleeping Computer reports of numerous malicious messages, likely linked to this attack, that have been seen by the publication. It appears that the threat actor has posed as Apple and Lego, both of which are known for heavily using UPS’s services for fast delivery.

A UPS spokesperson told TechRadar Pro:

"We are constantly vigilant when it comes to phishing and other attempts from bad actors. UPS is aware of reports relating to an SMS phishing (“Smishing”) scheme focused on certain shippers and some of their customers in Canada. UPS has been working with partners in the delivery chain to understand how that fraud was being perpetrated, as well as with law enforcement and third-party experts to identify the cause of this scheme and to put a stop to it. Law enforcement has indicated that there has been an increase in smishing impacting a number of shippers and many different industries.

Out of an abundance of caution, UPS is sending privacy incident notification letters to individuals in Canada whose information may have been impacted. We encourage our customers and general consumers to learn about the ways they can stay protected against attempts like this by visiting the UPS Fight Fraud website."

For now, concerned users should consider using identity theft protection tools to keep on top of their personal data.

Via Bleeping Computer

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
Avast cybersecurity
Zapier tells customers their data may have been accessed
GrubHub app on a mobile phone
GrubHub reveals massive data breach - customers, drivers, businesses all affected, here's what we know
A computer being guarded by cybersecurity.
Wacom warns users their data may have been stolen in breach
Latest in Pro
ai quantization
Shadow AI: the hidden risk of operational chaos
Digital clouds against a blue background.
Navigating the growing complexities of the cloud
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
Latest in News
Apple Watch Ultra 2 timer
The Apple Watch is getting a sleep alarm upgrade it probably should have had 10 years ago
Nikon Z5
The Nikon Z5 II could land soon – here's what to expect from Nikon's rumored entry-level full-frame camera
Google Pixel Watch 3
Google Pixel Watches hit with delayed notifications, crashing, and performance issues following Wear OS 5.1 update
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs