Tracer’s pour-over coffee was halfway through its second bloom when the FindASpy headquarters doorbell rang.
He opened the lobby door and found a small cardboard box sitting on the mat. The label had his name, his address, and no explanation. Inside, according to the packing slip, was one packet of garden seeds, a pair of baby wipes, and an insert card inviting him to “discover who sent your surprise.”
Tracer stared at the QR code on the card.
Then he stared at the coffee filter, which had collapsed into the carafe.
“Two suspicious arrivals before 8:00 a.m.,” he said. “At least the coffee has confessed.”
The package was not a gift. The QR code was not a helpful customer-service shortcut. It was the kind of setup the Federal Trade Commission warned about on August 20, 2026: a brushing scam, sometimes paired with QR-code phishing.
If an unexpected package arrives with your name on it, are you curious enough to scan the code? That curiosity is exactly what the scammer is counting on.

What is a brushing scam?
A brushing scam begins with a package you did not order.
The item is usually cheap and random. The FTC lists examples such as baby wipes, toothpaste, and seeds. The package may appear to come from a familiar marketplace, or it may have a sender name you do not recognize.
The seller sends the package to your real address so the delivery appears legitimate. The delivery record gives the seller “validation” that the package reached a real person. The seller then uses your name to post a fake review and make the transaction appear to be a verified purchase.
That is where the term brushing comes from. The seller is trying to brush up its ratings, sales, and reputation.
The package also confirms something important to the scammer: your name and address are active. That information may have come from a data broker, a leaked customer database, a compromised shopping account, or another source. The package does not automatically prove that your bank account was accessed, but it does deserve attention.
The QR code is the second trap
The package becomes more dangerous when it includes a card with a QR code.
The note may say:
- “Scan to see who sent this.”
- “Scan to arrange a return.”
- “Scan to claim your surprise.”
- “Scan to leave feedback.”
The code leads to a phishing website. Phishing is a fake website or message designed to trick you into handing over private information.
The page may imitate a popular retailer, delivery company, or payment service. It asks for a username, password, credit card number, or other personal details. The page is built to steal what you enter.
That is why you should not scan the QR code, even if the package looks harmless. A cheap product does not make the insert card safe.
The FTC’s warning explains that QR codes in these packages are designed to steal credit card numbers, usernames, or passwords. Treat the card like an unverified link from a stranger.
Why the trick works on seniors and working families
The scam succeeds because the package creates a small mystery.
A senior may wonder whether a family member sent something. A retiree may recognize the marketplace name and assume the package was ordered by mistake. A working parent may open it between school drop-off and a morning meeting, see a familiar logo, and scan the code without having time to investigate.
The package also uses social pressure. Most people want to return merchandise properly. They want to identify the sender. They do not want to ignore a delivery that might belong to a neighbor or family member.
In Florida, the setup can be even more confusing. Households receive frequent deliveries, seasonal residents may have packages forwarded, and family members may share an address or online shopping account. A surprise box can look like a forgotten order, a replacement shipment, or a gift.
The scammer wants you to solve the mystery quickly.
The safer response is to slow the mystery down.
The moment of recognition
The recognition moment is simple:
You did not order the item, and the package contains a QR code asking you to take action.
That combination is enough to stop.
Do not scan the code to identify the sender. Do not enter your shopping password to process a return. Do not provide a credit card number to verify that you are the recipient.
If you already scanned the code and entered information, treat the account as exposed. Change the password immediately from the retailer’s official website or app. If you reused that password anywhere else, change it there too.
Start with your email account if it uses the same password. Email access often allows someone to reset other accounts.
Five practical protection steps
1. Do not scan, click, or call from the package
Leave the QR code alone.
Do not use the phone number, web address, or customer-service instructions printed on the insert. If the package appears to come from a marketplace, open the company’s official app or type its known website address into your browser yourself.
Never use the QR code to arrange a return or find out who sent the package.
2. Document the package without interacting with it
Take clear photographs of:
- The shipping label
- The sender information
- The contents
- The insert card
- The QR code, without scanning it
Keep the package and card together while you decide what to do. Do not use cosmetics, food, seeds, electronics, or other products you did not order. You do not know who sent them or how they were handled.
Keep the item away from children and pets. If the package is damaged, leaking, unusually powdery, or physically threatening, do not handle it further. Move away and contact the appropriate emergency or postal authorities.
For an ordinary brushing package, documenting it is usually enough. You do not need to investigate the sender yourself.

3. Secure every online shopping account
Change the passwords for all online shopping accounts, especially if the package appeared connected to a marketplace.
Use a different password for every account. A password manager can create and remember unique passwords so you do not have to reuse one.
Turn on multifactor authentication, which adds a second identity check after your password. The second check may be an authenticator-app approval, security key, or one-time code.
Also review:
- Recent orders
- Saved payment cards
- Shipping addresses
- Account recovery email addresses
- Logged-in devices
- Unrecognized profile changes
If you entered a card number on the fake site, contact your card issuer using the number on the back of the card. Ask whether the card should be replaced.
4. Check your credit and financial accounts
Review bank and credit-card statements for unfamiliar activity.
Check your credit reports weekly for free at AnnualCreditReport.com, the official site authorized by federal law. Look for accounts, credit inquiries, addresses, or other information you do not recognize.
The FTC also recommends monitoring for identity theft. If you find suspicious activity, report it promptly and consider a fraud alert or credit freeze.
Do not use a search advertisement or an unexpected message to access your credit report. Type the address yourself or use the verified link above.
5. Report the seller and the scam
Use the official marketplace app or website to report the unsolicited package. Ask the platform to investigate the seller and remove any fake review posted in your name.
Then report the brushing scam to the FTC at ReportFraud.ftc.gov.
Include the sender name, marketplace, delivery date, package contents, presence of a QR code, and whether you scanned it or entered information. Your report may help connect your experience with reports from other households.
What about the product and the law?
Federal law says you do not have to return or pay for unordered merchandise. You are not required to send the item back because a seller asks you to.
However, that does not mean you should use the product. The FTC advises caution because you do not know who sent it or how it was handled.
After documenting the package and reporting it, follow your local disposal rules. If the item appears hazardous or suspicious, do not put it in the trash until you receive appropriate guidance.
Tracer’s field hack: The Unpredictable Human Challenge
Scammers build a predictable path:
- You receive a package.
- You feel curious.
- You scan the code.
- You enter information.
- You respond to the next message.
Break the path with one unpredictable human decision: do nothing from the package.
Open the official marketplace app yourself. Contact the company through a verified support page. Check your account directly. Ask a trusted family member to review the situation with you.
The goal is not to panic. The goal is to prevent the sender from controlling your next move.
The warning to remember
An unexpected package is not proof that your identity has been stolen. It is a warning that your name and address were used in a transaction you did not authorize.
Do not scan the QR code. Do not enter a password. Do not provide a card number. Independently verify the package through an official app, website, or phone number before taking action.
Awareness is the first layer of protection. Knowledge gives you the next step. A calm, independent response keeps a cheap surprise from becoming an expensive breach.
Community Conversation
Have you or someone in your family received an unexpected package addressed to you? What was inside, and did it include a card, QR code, or return instruction?
Tell us which state you are from. Do surprise deliveries make you more likely to open a package, or more likely to verify it first? Have you changed the way you handle QR codes after seeing scams like this?
Tracer reads all posts.
If you found a suspicious gadget, package-related device, or hidden technology, share it with the community by clicking here.
🟩 Meet Sterling Reed – "TRACER"
How important was this article?
Your vote helps determine FindASpy Insider’s Readers’ Top Picks. One rating is allowed per reader for each article.
Today’s Coffee Conversation
Tracer shares cybersecurity stories, scam alerts, privacy tips, and investigative insights. Pull up a chair, share your experience, and help shape tomorrow’s discussion.