Australia Post ‘Your Package has Experienced an Exception’ Malware Email

Email purporting to be from Australia Post claims that your package has experienced an exception and has been returned to the AusPost office.

Brief Analysis:
The email is not from Australia Post and the package it refers to does not exist. The email is designed to trick you into installing malware by clicking a link or opening an attached file.


Subject: [Name derived from email address] Your package has experienced an exception

Your package has experienced an exception and has been returned to the AusPost office. To collect the parcel please print out the shipment confirmation and visit AusPost facility.

Tracking #: AU54761866

Weight: 1.18 kg.

Reason: Not deliverable as addressed

Get shipping label


Penalties are imposed for storage of the parcel if you fail to collect it within 7 days.
The detailed information about storage is available at our website.

Please note: You might be required to show a valid governmental ID.

Australia Post Malware Email

Detailed Analysis:
According to this email, which purports to be from Australia Post, your package has experienced an exception and has been returned to the AusPost office. Supposedly, the ‘exception’ occurred because the package was ‘not deliverable as addressed’.  To get your package, claims the message, you need to click a button to print out a shipping label that you can take to an AusPost facility.  The email features the Australia Post logo.

However, the email is not from Australia Post, and the claim that a package could not be delivered to your address is a lie. Clicking the link opens a compromised website that harbours malware. Alternative versions of the email ask you to access the supposed shipping label by opening an attached file rather than by clicking a link. Again, the attachments contain malware.

Details, such as the supposed tracking number, the package weight, and the reason for the ‘exception’ may vary in different versions of the email. And, the content of the emails may be presented differently in alternative versions.

In fact, this is just the latest incarnation in a long line of similar malware emails that have falsely claimed to be from Australia Post.  All of the malware messages falsely claim that an Australia Post package has been returned or delayed and try to trick you into clicking a link or opening an attached file. Australia Post has set up a scam alerts page that provides warnings about these attacks and other types of Australia Post related fraud.

Note also that criminals have used the names of several other high-profile delivery or postal services around the world in similar malware campaigns.

If you receive one of these emails, do not click any links or open any attachments that it contains.

Last updated: May 4, 2016
First published: May 4, 2016
By Brett M. Christensen
About Hoax-Slayer

Australia Post ‘Parcel not Delivered’ Email Points to Malware
Australia Post Scam Alerts
Australia Post Undelivered Package Malware Emails
FedEx Incorrect Delivery Address Malware Email
Royal Mail Lost or Missing Package Malware Email