Metlivi Blog

Respond to exposed pickup information according to what actually leaked

If parcel-locker information leaks, do not begin by clicking the warning message or changing unrelated accounts at random. First identify the exposed item: a tracking number, a pickup QR or PIN, a carrier password, payment details entered on a look-alike page, or control of the phone number that receives notifications. These have different consequences. Open the retailer or carrier account from a saved app or typed address, check the parcel’s current state, and contact the official operator if a live pickup credential was visible to someone untrusted. Then secure the account that can issue or display new credentials. The FTC specifically advises checking delivery information independently rather than using a message link; USPS says its locker QR code should be kept confidential.

August 27, 20269 min readHome, Safety, Pets & Sustainable LivingBy Metlivi Editorial Team
Section 1

Classify the exposure before choosing actions

Write down what was visible, to whom, for how long, and whether the parcel is still awaiting pickup. A tracking number can reveal movement and destination detail but is not automatically the same as an opening credential. A QR code or PIN may operate the door. A carrier login may expose several shipments, saved addresses, preferences, and future notices. Payment details typed into a false delivery page create a separate account with the card issuer. Loss of the phone line can also intercept password resets and one-time messages. Use the narrowest category that fits, but if a screenshot contains several fields, respond to every field actually visible.

Do not keep forwarding the screenshot to ask whether it is dangerous. Make one private incident note with the time, platform, recipient, message URL or account event, and current tracking state. Crop nothing needed for evidence, yet avoid reproducing the live code in support forums. If the disclosure was in a public post, remove it where possible and preserve the post reference or moderation confirmation. Deletion reduces further viewing but does not prove nobody copied it.

Section 2

Secure the physical parcel through an official route

Open the known carrier app, the merchant order page, or a typed official address. Compare tracking number, location, readiness, and deadline. If a live locker code was exposed while the parcel remains available, contact the operator and ask what it can actually do: invalidate or refresh the credential, require staffed verification, move custody, or document the incident. Do not assume all systems can rotate a code. If the parcel was already collected, ask for the recorded time and location and preserve the official status before drawing a conclusion about who collected it.

Avoid racing an unknown person to the locker if the route or time is unsuitable. A quick response can be remote: notify the operator, protect the account, and arrange a safe pickup or trusted authorized delegate under current rules. Do not send the same exposed code to more people. If support gives a new credential, keep the old and new values out of ordinary notes; record only that the replacement occurred and the case reference.

Section 3

Secure the account that controls notifications

If a password was exposed, change it by entering the official service directly. Choose a new unique password and change any other account where the old password was reused, as the FTC advises. Review recovery email and phone, signed-in devices, recent security events, forwarding rules in the email account, saved delivery addresses, preferences, and notification channels. Sign out unfamiliar sessions where the service supports it. Protect the email account first when it is the reset path for the carrier account.

Enable multifactor authentication where offered; CISA explains that another factor makes access harder even after a password is compromised. Prefer the strongest option available to you, and store recovery codes privately. Do not approve an unexpected prompt merely because it arrives during cleanup. If control of the phone number was lost, contact the mobile provider through a known number to regain the line before relying on SMS password resets, then revisit the passwords and active sessions tied to that number.

Section 4

Handle false delivery messages and payment entry separately

The FTC warns that delivery texts can lead to look-alike sites asking for personal or payment information. If you only received the message and did not interact, block or report it according to the device and carrier options, then verify the real shipment independently. If you entered a username and password, follow the account steps. If you downloaded software or granted remote access, disconnect the affected device from sensitive activity and use trusted device-security support. Do not use contact details supplied by the suspicious page.

If payment details were entered, contact the card issuer through the number on the card or its official app and describe exactly what was submitted. Follow its account-specific instructions, inspect recent activity, and keep the case reference. This article does not decide liability or reimbursement. Its purpose is to preserve facts and reach the institution that controls the payment instrument. Never pay a second small ‘verification’ charge from the same delivery message.

Section 5

Preserve evidence without creating another leak

Keep the original suspicious message, sender address or number, timestamp, destination URL, official tracking state, security alerts, support references, and a short timeline of changes you made. Store the record privately. Redact QR codes, full addresses, phone numbers, card numbers, and account identifiers before sharing a screenshot with a workplace, building manager, seller, or platform moderator. Each recipient needs only the minimum information required for its role.

Report the fraudulent message using the relevant messaging, email, carrier, merchant, or regulator channel available in your region. A report is not a substitute for securing the account or parcel. Likewise, deleting the message is not a substitute for reviewing an account where credentials were entered. Separate containment from reporting: first stop current access, then document, then notify the responsible organizations.

Section 6

Rebuild notification privacy for future deliveries

After the event, choose one official app or bookmarked account as the place where delivery truth is checked. Reduce lock-screen preview detail if it reveals codes or locations, protect the phone with a screen lock, and remove old pickup screenshots after the handoff. Avoid storing live codes in shared calendars, group chats, photo albums synchronized to communal devices, or unprotected note widgets. When another person is permitted to collect, send only the credential and logistics they need, through a private channel, near the agreed pickup time.

Review who can access household email, retailer accounts, smart-home displays, shared tablets, and mobile-number recovery. The objective is not to hide ordinary delivery information from everyone; it is to ensure that a credential capable of releasing a parcel is shown only to an authorized person for the shortest useful period. Keep a compact response card with official app, carrier support path, email-security page, mobile-provider contact, and card-issuer contact. Do not put passwords, codes, or card numbers on that card.

Related questions

Common questions

Is a tracking number the same as a pickup code?

No. A tracking number identifies the shipment, while a locker QR or PIN may authorize release. Still protect tracking details because they can reveal delivery context.

Should I change my email password too?

Do so if the email password was exposed, reused, or the email account is the compromised reset path. Review its sessions and recovery settings.

Can deleting a public screenshot solve the problem?

It reduces further exposure but cannot prove that no copy was made. Continue with the actions matched to every visible field.

Related reading

Keep exploring this topic