Fraudulent FedEx shipping notification designed to deliver malware through a malicious Excel attachment.
Threat Summary
| Category | Details |
|---|---|
| Threat Type | Phishing Email, Malspam Campaign, Malware Delivery |
| Associated Email | No specific sender address disclosed |
| Detection Names | FedEx e-Order Notification Email Scam, FedEx e-Order Notification Malspam Campaign |
| Symptoms | Suspicious FedEx shipment notifications, unexpected Excel attachments, requests to open customs documents, potential malware infection after opening attachment |
| Damage & Distribution | Credential theft, spyware infection, trojan installation, ransomware deployment, financial loss, identity theft; distributed via malicious email attachments |
| Danger Level | High |
| Removal Tool | SpyHunter |
How FedEx e-Order Notification Email Scam Tricks Users
The FedEx e-Order Notification Email Scam impersonates FedEx and claims that a shipment is being held by customs in a temporary storage facility. The email creates urgency by stating that the package can only remain in storage for 20 days before additional fees or complications arise.
To make the message appear authentic, the scammers include fabricated shipping details such as:
- Arrival dates
- Tracking numbers
- Warehouse codes
- Registration numbers
- Customs references
Recipients are instructed to open an attached Excel spreadsheet supposedly containing customs clearance documents and storage fee information. In reality, the attachment is designed to deliver malware onto the victim’s system.
The malicious attachment identified in this campaign is:
fedex_awb_bl_tax_bill_document_receipt_payment_05_25_2026_00000000.xls
Once opened, the spreadsheet may display a legitimate-looking document while attempting to convince the victim to enable editing or interact with embedded content. These actions can trigger malware installation.
Full Text of the FedEx e-Order Notification Email Scam Message
Below is a shortened excerpt of the scam message:
Subject: Your Shipment Customs Clearance Documents
FedEx e-Order Notification
Our valued customer,
Your shipment is subject to customs and has been taken to the FedEx Temporary Storage Area under the Airport Customs Directorate.
The waiting period for shipments in temporary storage is 20 days from the date of arrival.
You can find out the storage fee for your shipment held at customs as attached.
The message then lists various shipment-related details intended to create credibility and persuade recipients to open the attached spreadsheet.
What Happens If You Fall for FedEx e-Order Notification Email Scam
Opening the attachment and enabling its active content can result in the installation of various types of malware. Security researchers have observed similar campaigns delivering:
- Banking trojans
- Password-stealing malware
- Spyware
- Keyloggers
- Backdoors
- Cryptocurrency miners
- Ransomware
- Other malware loaders
Potential consequences include:
- Stolen passwords and account credentials
- Unauthorized access to online accounts
- Financial fraud
- Identity theft
- Data theft
- File encryption attacks
- Long-term system compromise
If you opened the attachment:
- Disconnect the affected device from the internet.
- Run a full malware scan immediately.
- Change passwords for important accounts, especially email, banking, and business services.
- Enable multi-factor authentication where available.
- Monitor financial accounts for suspicious activity.
- Contact your bank if financial information may have been exposed.
Conclusion
The FedEx e-Order Notification Email Scam is a malware-distribution campaign that abuses the trusted FedEx brand to lure victims into opening a malicious Excel attachment. The email uses fake customs and shipping information to create urgency and increase the likelihood of infection. Anyone receiving this message should delete it immediately and avoid opening any attached files. If the attachment has already been opened, a thorough malware scan and credential reset should be performed as soon as possible.
