Skip to main content

Morning Overview

A free package you never ordered can mean a brushing scam stole your data

An unexpected parcel arriving with no invoice and no sender feels like a small windfall, but investigators say it can be the opposite. The delivery is often the visible symptom of a “brushing” scam, in which an online seller ships cheap goods to a real person’s name and address to post fake verified-purchase reviews under that identity. The merchandise is free and usually worthless, yet its arrival signals that personal information is already circulating where it should not be.

How brushing inflates a seller’s ratings

Brushing exists because reviews sell products, and marketplaces give extra weight to reviews marked as coming from a confirmed buyer. To manufacture those, a dishonest seller needs completed orders tied to genuine names and addresses. The Federal Trade Commission’s consumer alerts describe how the scammer creates accounts, ships inexpensive items such as seeds, jewelry or small gadgets to those addresses, and then writes glowing “verified purchase” reviews as if the recipient had bought and loved the product. The packages are the cost of doing business, a cheap price for a flood of five-star ratings that push a listing higher in search results and dupe real shoppers.

What the delivery reveals about exposed data

The unsettling part is not the free trinket but what its arrival implies. For a brushing shipment to reach a doorstep, the scammer already has a working name-and-address pairing, and often an email or phone number, harvested from a data breach, a leaked customer list or information bought on the open market. The U.S. Postal Inspection Service, the federal law-enforcement arm that investigates mail-related fraud, treats an unordered package as a prompt to check for deeper trouble. Guidance from the Postal Inspection Service encourages recipients to watch for unauthorized accounts or charges, since the same stolen details used to fake a review could be used to open accounts or attempt purchases elsewhere.

The QR-code twist that turns a gift into phishing

A newer and more dangerous version swaps the mystery of the package for a trap. Some brushing parcels now arrive with no packing slip but a QR code, presented as the only way to identify the sender or claim the item. Scanning it leads to a phishing site that requests login or payment details, or that quietly installs malware. Fraud investigators warn against scanning any QR code on an unexpected delivery for exactly this reason: it converts a passive privacy red flag into an active attempt to steal credentials. The safe assumption is that a code with no legitimate explanation is bait.

What recipients can and cannot be forced to do

Federal law is clear that anyone who receives unordered merchandise is under no obligation to pay for it or to send it back. The item can be kept, and there is no legal duty to contact the sender or arrange a return. What recipients should not do is engage with the scammer, follow instructions printed on the package, or scan an unexplained code. Beyond that, the practical response is defensive. Consumer-protection officials advise reviewing bank and card statements for unfamiliar activity, changing passwords on the shopping and email accounts most likely to have been exposed, and enabling two-factor authentication so a stolen password alone is not enough to break in. The Federal Trade Commission’s scam resources also recommend requesting a free credit report to check for accounts opened without permission and considering a credit freeze if fraud is suspected.

Reporting and the bigger picture

Reporting a brushing package helps in two ways: it flags a seller’s fake-review operation to the marketplace, which can remove the fraudulent reviews and the accounts behind them, and it feeds data to investigators tracking how stolen personal information moves. Recipients can notify the online marketplace that appears on the label, report the incident to postal inspectors when the mail system was used, and file a complaint with the Federal Trade Commission. None of that recovers the exposed data, which is the real loss, but it disrupts the scheme and helps protect the shoppers who would otherwise trust the manufactured ratings. The lasting lesson is a shift in how a free package reads: not as luck, but as a quiet notice that someone, somewhere, is already holding enough personal information to put a stranger’s name on a doorstep.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview