Scam Detective.
Scam guide

Is that mystery package with a QR code a scam?

The package is bait. Never scan a QR code on an unsolicited parcel — it leads to a phishing page or a malicious app, and postal inspectors have warned about exactly this.

Classic brushing was almost harmless: a seller ships cheap junk to your address so they can post a 'verified purchase' review in your name and inflate their ratings. Annoying, but the only real damage was fake reviews. The current wave adds a hook — a QR code on or inside the package, with a note inviting you to scan it to see who sent the gift, claim a reward, arrange a return, or 'verify delivery.' The U.S. Postal Inspection Service has issued alerts about these QR-code packages.

Scan it and you land on a phishing page that asks for your name, address, and card details ('a small verification charge'), or you're prompted to install an app that can read your messages and banking codes. The parcel exists purely to make the QR code feel trustworthy — a physical object at your door reads as more legitimate than any text or email. It isn't. Meanwhile the fact you're getting brushing parcels at all means your name and address are already circulating on a broker or breach list.

A typical note inside a brushing package
🎁 Congratulations! You've received a complimentary gift from our loyalty program. To see who sent it and claim your $100 reward card, simply scan the QR code below and confirm your delivery details within 48 hours. Unclaimed rewards expire!

How does the scam work?

  1. 01

    A parcel you never ordered shows up

    Seeds, a phone ring, cheap earbuds, a bracelet — the contents are near-worthless because they're not the point. Your address came from a data breach or a broker list, and the shipment either powers fake reviews, tests stolen card details, or delivers the QR bait itself.

  2. 02

    The QR code borrows the package's credibility

    A QR code is just a link you can't read before opening it. Printed on a physical parcel, it inherits an undeserved air of legitimacy — which is precisely why the scammers moved it off your screen and onto your doorstep.

  3. 03

    The landing page harvests, or the app burrows

    One branch asks for card details to 'verify your identity' or pay a tiny 'claim fee.' The other pushes an app install that requests permission to read notifications — including the one-time codes your bank texts you. Either way, the free gift becomes account access.

What are the red flags to check?

A package you didn't order, from a sender you can't identify

No legitimate retailer ships surprise gifts to strangers with no sender information. If there's no order in any of your accounts and no note from someone you actually know, it's brushing.

A QR code that promises to reveal the sender or a reward

Real senders identify themselves on the shipping label or a gift receipt. 'Scan to find out who sent this' exists for one reason: to get a link in front of you that you can't inspect first.

A 'claim fee' or card details for a free gift

A gift that requires your card number is not a gift. Even a $0.30 'verification charge' is a card-harvesting test transaction that validates your details for bigger fraud.

A countdown on the reward

"Unclaimed rewards expire in 48 hours" is the same manufactured urgency as every smishing text, relocated to a slip of paper. Real promotions don't ship first and threaten expiry after.

The QR link resolves to a fresh, non-brand domain

Preview the URL before opening it (most phone cameras show it). A days-old domain like reward-claims-center.top has nothing to do with any retailer — and domain age is exactly what a URL check exposes.

Unsure even after checking these? That’s exactly what the $2 Instant URL Check is for — paste the link and get a researched verdict with evidence, instead of guessing.

What should you do right now?

  1. Don't scan the code, and don't pay to 'claim' anything. You can keep or discard unsolicited merchandise — under FTC rules it's yours, and you owe nothing.
  2. Check your accounts: make sure the package wasn't a real order (yours or a family member's), and change your passwords if you see orders you didn't place.
  3. Report it: file at reportfraud.ftc.gov, notify the marketplace if a platform label is on the box, and report QR-code packages to the U.S. Postal Inspection Service at uspis.gov.
  4. Treat it as a data-exposure signal: your name and address are on a circulating list, so expect follow-up texts and calls — and watch card statements for small test charges.

What the check does: a one-time, researched risk report on the URL you paste. What it doesn’t do: continuous monitoring, takedowns, fund recovery, or legal advice — and we’ll never pretend otherwise.

Not ready to check a link yet?

Get this guide's red-flag checklist by email.

We'll send you the red flags and the 3-step plan from this page, so it's in your inbox the moment a suspicious text actually arrives.

One email, no spam, no subscription — that’s the whole deal.

Got a suspicious text? Get a verdict in 60 seconds — $2.

Check the link — $2