I Paid €1.95 to Collect My Chronopost Parcel — Bank Statement Mismatch After a Month

September 12, 2026

An SMS arrives, discreet, almost banal: “Your package is awaiting delivery, settle €1.95 for re-shipment fees.” The kind of message you open half-distracted between tasks, especially when you’re waiting for an order. Many French people click without thinking, pay this trivial amount, and forget the incident immediately. Except that a month later, while sifting through their bank statement, the surprise is quite different: a recurring debit, much higher, has slipped quietly into the charges. This small sum of €1.95 was therefore not what it seemed, and the story deserves attention, as it reveals a well-oiled mechanism behind an apparently harmless scam.

Key takeaways
  • The phishing SMS imitates Chronopost and demands €1.95 for re-shipment on a fake parcel
  • This payment does not unlock anything but validates a recurring direct debit mandate that triggers much higher debits a month later
  • You should avoid clicking these links, check your parcels directly on the official site, and regularly monitor your bank statements
Table of contents
  1. The SMS that looked like all the others
  2. Why €1.95 and not a penny more
  3. The real mechanism behind this symbolic payment
  4. What this scam reveals about our digital reflexes

The SMS That Looked Like All the Others

What stands out in this type of fraud is precisely its apparent banality. The message perfectly imitates the visual codes and vocabulary of legitimate couriers: a roughly sketched but recognizable logo, an institutional tone, and a tracking number that seems credible. As the school season begins, online shopping is on the rise again after summer, deliveries are multiplying, and consumers are used to receiving real tracking notifications. It’s precisely this habit that scammers exploit: the more a message resembles the ones we receive each week, the less time we take to question it. The included link redirects to a page that copies, pixel for pixel, the official Chronopost interface, with a payment field that seems innocuous.

The trap works all the better because the amount requested remains symbolic. No one worries about €€1.95, a trifling sum compared with the price of a coffee. This impression of a low-stakes issue disables our usual caution reflexes, the ones we activate when faced with a request for a larger amount of money.

Why €1.95 and Not a Penny More

This amount is no accident. The cybercriminals behind these campaigns have sharpened their strategy over the years, relying on successive tests to identify the optimal psychological threshold. Too small an amount, like a few cents, would seem suspicious because it would be trivial enough to justify any formal process. Conversely, too high an amount, say €10 or more, would immediately trigger the victim’s vigilance.

€1.95 sits precisely in that gray area where the brain classifies the expense as “negligible fees,” without triggering a particular alert. It is also a sum small enough for the bank, on its side, not to automatically block the transaction on fraud suspicion, unlike what could happen with a larger debit conducted by a stranger.

The Real Mechanism Behind This Symbolic Payment

Here lies the core of the problem, one that most victims uncover far too late: a carrier never requests delivery fees by SMS. Chronopost, like other players in the sector, does not operate this way. Any potential re-shipment or customs fees are always indicated directly on the official site, never via a link sent by message.

In reality, this €1.95 payment does not serve to unlock a package at all. It is used to validate a recurring direct debit mandate. By entering their banking details on the fake page, the victim does not pay for a one-off charge: they unknowingly authorize a repeated automatic debit, often for a higher amount, which triggers discreetly in the following weeks. The first payment, minimal, merely tests the card’s validity, a technical step that allows the scammers to verify that the number works before scheduling larger debits. This is exactly what victims discover a month later: a phantom subscription, never consciously subscribed to, that regularly drains their account for a service that does not exist.

What This Scam Reveals About Our Digital Reflexes

This case illustrates a broader reality: our relationship with small sums of money has shifted with the dematerialization of payments. Where we would hesitate to pull out cash for a dubious transaction, a simple click on a screen no longer triggers the same caution. The speed and fluidity of online payments, intended to simplify daily life, paradoxically become fertile ground for this form of fraud.

Some simple reflexes can nevertheless limit the risks: never click on a link received by SMS for a parcel, go directly to the official site of the courier to check the status of a delivery, and regularly monitor bank statements to spot unusual debits. It is also possible to lodge a rapid stop if such a debit is observed; the bank can then block future debits tied to this fraudulent mandate.

This €1.95 case ultimately recalls a simple truth often forgotten: the most effective scams are not always those that promise spectacular gains or demand large sums. Sometimes they are the ones that go unnoticed precisely because they seem too insignificant to deserve our attention. And if the best protection lay in being wary of what appears banal?

Sindre Halvorsen

I write about space exploration, frontier science and the technologies that are quietly shaping the future. From Norway, I follow the missions, discoveries and ideas that connect life on Earth with what lies beyond it. My goal is to make complex subjects clear, useful and worth paying attention to.