The Package You Didn't Order: Brushing Scams and the QR Card Inside
Bottom line up front
A package you never ordered showed up with your name on it. The FTC put out an alert about this on August 20, 2026: it is probably a brushing scam, where a seller ships you something cheap so they can post a fake “verified purchase” review in your name. You can keep the item — that part is settled law. What matters is the rest of it. If there is a card with a QR code inside, do not scan it. And treat the delivery as evidence that your name, address and phone number are sitting in somebody's spreadsheet.
The first one is almost funny. A padded envelope on the step, no note, no invoice, and inside it a phone-mount, or a bag of seeds, or a sample-size tube of toothpaste. Nobody in the house ordered it. You check your Amazon account, nothing. You check your partner's, nothing. It sits on the counter for a week while everyone forgets to deal with it.
Then a second one arrives. That is usually the point at which people start searching, which is presumably how you got here.
What you are looking at is a brushing scam, and the version circulating in 2026 has an extra component that the old one did not: a small printed card, often with friendly wording — scan to see who sent your gift, scan to process a return, scan to register your warranty — and a QR code underneath. That card is the part that can actually cost you something.
What to do right now: seven steps
If a package you did not order is in front of you, work through this list. It takes about fifteen minutes and most of it is free.
- Do not scan any QR code that came in the box. Not to identify the sender, not to arrange a return, not out of curiosity. The FBI's public service announcement on this variant is specific: the code can lead to a page that harvests personal and financial details, or push you into installing something that reads data off your phone.
- Change the password on the shopping account the package appears to come from. If it looks like it came through Amazon, eBay, Walmart or another marketplace, change that password and turn on two-factor authentication while you are in there.
- Tell the marketplace. Amazon, eBay and the rest have fraud-reporting paths, and a brushing report gives them the thread to pull on the seller. Ask them to look for and remove reviews posted under your name.
- Pull your credit reports. All three bureaus, free, weekly, at AnnualCreditReport.com. You are looking for accounts and inquiries you do not recognise.
- Consider a credit freeze. Free at Equifax, Experian and TransUnion, reversible in minutes when you need to apply for something. If your details are already circulating, this is the single control that does the most work.
- Keep it, bin it, or send it back — your call. Under 39 U.S.C. § 3009, unordered merchandise is a gift and you owe the sender nothing. If it is unopened and has a return address, the Postal Service will send it back free if you mark it Return to Sender. Be sensible about consuming anything edible or applying anything cosmetic from an unknown source.
- Report it. ReportFraud.ftc.gov for the FTC, ic3.gov for the FBI, and the Postal Inspection Service if it came through the mail.
One thing not to do
Do not call a phone number printed on the packing slip, and do not use a support number you found by searching. Bill-pay and customer-service impersonators buy search ads for exactly that moment — the FTC flagged that pattern separately on August 17. Go to the retailer's site by typing the address yourself, or open their app.
What is a brushing scam?
Definition
A brushing scam is when an online seller ships a cheap item to someone who never ordered it, using a name and address obtained elsewhere. The delivery record makes the seller look like a verified buyer, so they can post a fake five-star review in that person’s name.
The Postal Inspection Service has a whole page on it, and the framing there is worth borrowing: the sender is usually an international third-party seller who found your address online. Not stole, necessarily. Found. Names and addresses are cheap and abundant, sold by data brokers, dumped in breaches, scraped from public records.
The economics are the reason this keeps happening. A phone-case costs the seller a couple of dollars, shipping is subsidised, and in return they get a review that carries the platform's own “verified purchase” badge. Reviews with that badge move products. Multiply by a few thousand and you have a rating that looks organic and a sales rank that puts you on page one. The money goes in a circle — the seller pays themselves — so the only real cost is the postage.
Sequence per FTC consumer alert (Aug 20, 2026), USPIS and FBI IC3 alert I‑073125‑PSA. Amber marks the seller's move; red marks where a scan can cost the recipient.
For years this was written up as a nuisance crime. Free stuff, fake reviews, nobody's bank account touched. That reading was always a bit thin, and the 2026 version makes it untenable.
The QR card is the new part
The addition is small and physical: a card, sometimes the size of a business card, sometimes a folded insert, with a QR code and a line of text giving you a reason to scan it. The FTC's August alert describes the framing as an offer to reveal who sent the package or to process a return. The Postal Inspection Service adds a third: scan to learn more about the company that sent you the gift.
All three work on the same lever, which is that you genuinely want the answer. You are holding a box with your name on it from a person you cannot identify. Being told that the code will explain it is a good pitch.
What sits behind the code is a phishing page. Usually it is styled as a retailer, a courier, or a bank — whatever fits the pretext — and it wants a card number, a login, or enough identity detail to open something in your name. On some campaigns the page pushes an app install instead. The FBI notes the packages often ship with no sender information at all, precisely so the code looks like the only way to find out.
Print is a good delivery channel for this, and it is worth being honest about why. Email filters have gotten decent at reading links. They cannot read a picture of a link, which is the whole appeal of QR phishing, or quishing. Microsoft's Q1 2026 email threat report measured QR-code phishing rising 146% across the quarter, from 7.6 million detections in January to 18.7 million in March — the highest monthly volume they had seen in at least a year. That figure is about email, not mail. But it tells you where attacker attention is going, and a printed card skips the filter entirely.
The other thing a printed card does is move you onto your phone. You scan with the camera, the browser opens, and you are now on a small screen where the full URL is truncated, the padlock means very little, and every password manager habit you have on a laptop is harder to lean on. Our guide to QR-code scams goes through the preview-before-you-open habit in more detail; the short version is that most phones will show you the destination before they load it, and almost nobody looks.
What the package actually tells you
Here is the part that people skip past, and it is the most useful thing in this article.
Somebody had your full name, your deliverable street address, and enough confidence in both to spend money shipping to them. That is not nothing. It is the same starter kit that gets used for a dozen other things — a change-of-address filing, a credit application, an account-recovery attempt where the agent asks you to confirm your address and the caller already knows it.
The package is not the attack. The package is the receipt showing that your details were bought and used successfully.
The Better Business Bureau has been making this argument since 2024, and their phrasing is blunt: the fact that someone could have items sent to you as if you had purchased them means they hold some of your personal information. Where they got it is usually unknowable. It could be a breach you were notified about two years ago, a data broker, a marketplace account of yours that has been accessed, or all three.
You cannot claw any of that back. What you can do is make it worth less: freeze credit, turn on two-factor authentication where money or email live, and stop treating “they knew my address” as proof that a caller is legitimate. That last one matters more than it sounds, because knowledge-based verification — last four of the Social, date of birth, mother's maiden name, current address — is exactly what a caller with your data can pass. If you have older parents, the short list of warning signs worth taping next to their phone is built around that idea.
Five tells that a delivery is a brushing package
Not every unexpected parcel is a scam. Sometimes a friend sent a gift and the sender field is blank because they clicked the wrong option. What follows is a pattern, not a single item.
- No sender information, or a return address that leads nowhere. Often the return address is a real retailer's fulfilment centre, which tells you nothing about who paid.
- The item is cheap, light and random. The FTC's recent reports mention baby wipes, toothpaste and seeds. USPIS has seen phone accessories, socks, and empty boxes. The common factor is low shipping weight.
- It is not on any of your order histories. Check every account in the household before concluding this, including the one your teenager uses.
- There is a card with a QR code and a reason to scan it. Legitimate sellers do not ask you to scan a code to learn who sent you something.
- More than one arrives. Repeat deliveries mean your address is now on a working list, which is also when the porch-theft variant becomes worth thinking about.
The variant where the package is not for you
There is a second use for someone else's address, and it is nastier. A criminal orders goods with stolen card details, ships them to a real residential address they do not live at, and then watches the tracking to intercept the delivery before the resident brings it in. The BBB and USPIS both document it. Your address functions as a drop box.
The tell is that the items are not cheap. A brushing package contains a $3 phone-mount; a drop-shipping package contains something worth stealing. If expensive goods you did not order start showing up, that is a different problem: contact the retailer, keep the tracking numbers, and tell the local police if it repeats, because at that point there is a pattern and a delivery route attached to it.
If you already scanned the code
Scanning a QR code on its own is not a catastrophe. A code is just a link. What matters is what happened next.
Response sequence assembled from FTC, FBI IC3 and USPIS guidance for unsolicited-package QR fraud.
If you scanned it and the page loaded but you typed nothing, close the tab and move on. Clear the browser history if it makes you feel better; there is no residual harm from a page view on a modern phone.
If you entered a password, change that password now, and change it anywhere else you reused it. Turn on two-factor authentication on the account while you are there.
If you entered card details, call your bank on the number printed on the back of your card — not one from the website, not one from the packing slip — and ask for the card to be replaced. Do this even if nothing has been charged yet. Cards get tested with small amounts weeks later.
If you gave up a Social Security number, that has its own sequence, and we wrote it out step by step in what to do when a scammer has your SSN.
If you were prompted to install an app or approve a profile and you did it, treat the phone as compromised: remove the app, review which apps hold accessibility or device-admin permissions, run whatever built-in security check your phone offers, and change the passwords for your email and banking from a different device. If the first hour after any of this feels chaotic, the first sixty minutes lays out the order to do things in.
The text that usually arrives next
Worth knowing what tends to follow. Once an address is on a list, it often gets worked from more than one direction, and the delivery pretext is the easiest one to reuse. A text claiming a package is held pending a small fee. A message about a failed delivery attempt with a link to reschedule. Both are old, both still work, and both get a lift from the fact that you actually do have unexplained parcels arriving.
The Postal Service will not text you asking for money to release a package, and it does not send tracking links you did not request. We covered the mechanics of that one in the USPS text scam guide, and the same shape shows up in the unpaid-toll texts that have been running since last year. If a delivery message ever seems plausible, open the courier's own app instead of the link. That habit costs ten seconds and defeats the entire category.
If you are sorting this out for a parent
Two adjustments if the packages are arriving at a parent's house rather than yours.
First, resist the urge to make it a lesson. The person did nothing wrong; a stranger mailed them a box. Framing it as a mistake they made turns the next unexplained package into something they hide from you, which is the opposite of what you want.
Second, replace the whole discussion with one sentence they can actually recall. Something like: if a package I didn't order has a code in it, I don't scan it, I call you. Short rules survive; checklists do not, particularly under any kind of pressure. Our guide to protecting elderly parents works through how to have that conversation without it feeling like supervision.
Worth knowing: the FBI's alert points people aged 60 and over who want help filing a complaint to the DOJ Elder Justice Hotline at 1-833-FRAUD-11 (1-833-372-8311). A real person walks them through the form.
The tell is always the same
QR card, delivery text, urgent call — every one of them wants you to act inside the channel it arrived in. ScamDrill sends your household realistic practice scams and coaches whoever clicks, so the pause becomes automatic before it costs something.
Start a free trialWhere to report it, and why bother
Reporting a brushing package feels pointless. Nobody lost money, there is nothing to recover, and the seller is probably offshore. Do it anyway, for two practical reasons.
The first is that marketplace reports are the only mechanism that gets fake reviews pulled and sellers suspended. The platform cannot detect a review posted under a real customer's name against a real delivery; that is the entire design. Your report is the signal.
The second is that complaint volume is what turns a scattered annoyance into a documented pattern. The FTC's alert on August 20 exists because reports came in describing the same boxes of wipes and seeds. The FBI's QR-code advisory exists for the same reason. These are not big numbers on their own, but they are what regulators and investigators build from.
- FTC — ReportFraud.ftc.gov
- FBI — ic3.gov, and include the code's destination if you captured it safely
- Postal Inspection Service — uspis.gov/report; USPS-branded phishing texts go to spam@uspis.gov or forward to 7726
- The marketplace — through its own fraud form, asking for reviews under your name to be removed
- Identity theft you have already found — IdentityTheft.gov generates a recovery plan and pre-filled dispute letters
What to take from this
The brushing scam itself is minor. A seller games a review system, you get free toothpaste, the world turns. If that were the whole story it would not merit an FTC alert or a page from the Postal Inspection Service.
It merits both because of the two things attached to it. The card with the QR code, which is a phishing attack delivered by mail specifically to route around the filters that catch it in email. And the fact of the delivery, which is a quiet confirmation that your details are in circulation and being used by someone who paid for them.
Neither is an emergency. Both are worth fifteen minutes today: don't scan, change the marketplace password, pull the credit reports, freeze if you have been putting it off. Then keep the toothpaste. You are legally entitled to it.