Skip to main content

Morning Overview

That free package on your porch may carry a QR code built to empty your account

An unexpected package can be more than a mystery delivery. The Federal Trade Commission says a note inside may carry a QR code that promises to identify the sender or process a return, but scanning it can send a recipient to a phishing site designed to collect credit-card numbers, usernames or passwords. That is the mechanism behind the warning that a free package on a porch may carry a QR code built to empty an account.

In the FTC’s consumer alert on brushing scams, the agency describes packages addressed to real people that contain cheap, random items such as baby wipes, toothpaste or seeds. The package may look as though it came from a familiar company, or from a business the recipient has never heard of. The item is not the whole play; it can provide a believable reason to scan a code or visit a link.

The package can be used to manufacture a delivery record

Traditional brushing scams use a customer’s name and address to make it look as though a seller completed a real sale. The scammer then posts a fake review under that person’s name, using the delivery as apparent validation. The FTC says that practice is meant to “brush up” a business’s sales and reviews, not to provide a useful gift.

The arrival of a package can also signal that someone has personal information or is seeking more of it. A name and address are enough to put a parcel at a doorstep; a QR code inside can be an attempt to move the interaction onto a fraudulent site. The FTC cautions that the code might claim to reveal who sent the item or offer a return process, both natural questions for someone who never placed an order.

That sequence matters because the code is not evidence that the delivery company or marketplace endorses the request. It is merely a printed instruction inserted by an unknown sender. A recipient who scans first and evaluates later may hand over information before discovering that the delivery itself was part of the setup.

A QR code can hide the destination until after it is scanned

QR codes are convenient because a phone turns a camera image into a web address. The same convenience makes them poor proof of where a link actually goes. The FTC says the code in an unexpected package can lead to a phishing site designed to steal payment-card details, usernames or passwords. Those are the credentials that can be used to enter shopping accounts, attempt account recovery or make unauthorized purchases.

The agency’s warning does not say every code in every package is malicious. It says an unordered package is a poor reason to trust a code, particularly when the note tries to create urgency around a return or an unknown sender. A legitimate marketplace can be contacted through its official app or website without using a code supplied by an unfamiliar package.

That difference keeps the response practical. The package may be a real physical object, but the information request attached to it remains unverified. A consumer does not need to solve the sender’s story before declining to scan.

The FTC advises checking accounts and contacting the platform directly

The FTC advises people who receive a package they did not order to change passwords on online shopping accounts in case those accounts were compromised. If the package appears connected to Amazon or another marketplace, the agency says to message the platform directly so it can investigate the seller and remove a fraudulent listing if appropriate.

The FTC’s brushing-scam alert is the federal alert at the center of the warning. Its companion guidance on recognizing phishing explains why a code can be used to collect credentials. AnnualCreditReport.com is the federally authorized site the FTC names for credit checks, while ReportFraud.ftc.gov accepts reports. The FTC’s unordered-merchandise guidance addresses the question of whether an unexpected item must be returned or paid for.

It also recommends checking credit weekly through AnnualCreditReport.com and watching a credit report for signs of identity theft. Those actions follow a different path from the QR code: they use known services rather than a link chosen by a stranger. The FTC notes that federal law generally does not require a person to return or pay for unordered merchandise, although it advises caution about using an item when the sender is unknown.

A report can help the agency identify patterns. The FTC directs consumers who spot a brushing scam to ReportFraud.ftc.gov. A marketplace report and an FTC report are not the same thing, but each puts the information in front of the organization that can examine its own part of the problem.

The useful question is not who sent it, but what the note asks for

An unfamiliar package invites curiosity. The scam relies on that reaction, then supplies a convenient QR code to answer it. The FTC’s alert supplies the safer framing: the code may be a route to a credential-stealing page, while the parcel may be a vehicle for fake reviews or a sign that personal information has been exposed.

For a recipient, the hard fact is straightforward. An unordered delivery with a QR code does not need to be scanned to be handled safely. Account passwords, official marketplace contact channels, credit monitoring and an FTC report are all available without giving the sender another chance to direct the next click.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview