Taiwan’s Cybersecurity Evaluation and Coordination Center told logistics firms and retail banks Thursday that fake “unpaid shipping fee” SMS messages jumped more than 40 percent in the first two weeks of September, a pattern investigators link to Mid-Autumn Festival gift parcels and mooncake boxes that crowd apartment lobbies before the long weekend.
What recipients are seeing
Messages typically cite a well-known courier brand, claim a 29- or 39-new-taiwan-dollar customs or storage charge, and push a shortened URL that mimics Taiwan mobile-banking login pages. Victims who enter card numbers see small “verification” charges that are actually test withdrawals; fraud rings then drain accounts through quick-payment apps before the 165 anti-fraud hotline can freeze transfers.
Unlike older voice-phishing calls in Mandarin, the current wave targets younger renters who track everything on chat apps and rarely answer unknown numbers. Criminal Investigation Bureau analysts said more than 1,100 reports in the past ten days mention the same handful of domain registrars hosted outside Taiwan, with TLS certificates issued hours before campaigns launch.
Why Mid-Autumn timing matters
Carriers publish peak delivery forecasts each September as employers ship gift sets to parents and in-laws. Scammers scrape public tracking numbers from social posts, then text “your package is held” notes that feel plausible because recipients are already expecting boxes. Convenience-store pickup notifications use official short codes; the fakes copy layout but swap one character in the sender ID.
CECC briefings shared with InfoHandle show three major e-commerce platforms agreed to banner warnings on checkout pages, while Chunghwa Post will push authenticated in-app alerts only—no fee links in SMS bodies after 20 September. Warehouse contractors must also revoke shared tablet logins used to scan outbound labels, a common leak path for recipient phone numbers.
Bank and telco response
The Financial Supervisory Commission asked lenders to throttle first-time bindings between newly opened accounts and crypto exchanges when the login originated from a parcel-scam domain within the prior hour. Taiwan Mobile and Far EasTone said they are filtering newly registered URL shorteners at the network edge, a step privacy advocates accepted because the blocklist is limited to fraud tickets filed with 165.
Smaller rural credit cooperatives complained they lack API access to the shared fraud feed; CECC promised a read-only mirror hosted on MODA’s G-cloud by October. Until then, branch staff are manually flagging customers who mention “package fee” at the counter.
What firms must patch
Logistics operators must rotate customer-notification templates so scammers cannot clone last year’s wording, and publish checksums of legitimate SMS headers. CECC is not mandating penalties yet, but the Personal Data Protection Commission warned that leaking recipient phone numbers from warehouse handhelds could trigger fines if audits find shared contractor logins.
Investigators seized two Taichung apartments this week where SIM boxes blasted 12,000 messages an hour; equipment was paid for with stolen virtual-account balances cashed out at night-market game stalls—a reminder that parcel scams sit on top of older mule-account infrastructure.
Consumer steps
Official guidance: open courier apps directly, never links in texts; pay storage fees only inside authenticated apps or at store kiosks printing paper receipts. The 165 hotline added an English-language queue after foreign residents reported losses on student visas. Losses are difficult to recover once funds hit overseas betting sites, prosecutors said in a Thursday press conference.
Cross-border hosting
CECC asked domain registrars in Singapore and Hong Kong to suspend repeat offenders; two complied within 48 hours, others requested court orders Taiwan cannot obtain before the holiday. That lag keeps a rotating pool of look-alike hosts alive for 72-hour bursts—long enough to clear out six-figure NT dollar hauls from family accounts shared for tuition payments.
What comes after the holiday
A Legislative Yuan hearing on digital fraud is scheduled for late September; opposition lawmakers want mandatory sender authentication on all commercial SMS, not voluntary carrier programs. CECC officials said they will publish weekly domain blocklists and parcel-scam loss tallies through October, when Double Ten promotions start another delivery spike.








