An unexpected package on the doorstep, addressed to the resident but never ordered, can feel like a small windfall. Consumer-protection officials say it is often the opposite: a red flag that a stranger already has enough personal information to use a name and address for their own gain. The practice has a name, and understanding how it works turns a puzzling delivery into a useful warning sign.
The scheme is built around fake reviews and inflated sales rather than an immediate demand for money. That indirect payoff is part of what makes it easy to dismiss, because the recipient is not asked to pay for anything and gets to keep whatever showed up. The deeper problem is what the delivery reveals about how far a person’s data has already traveled.
How the unordered-package scheme actually works
According to the Federal Trade Commission, scammers send people fake “luxury” items such as rings, beauty products, and even Bluetooth speakers, then use the recipient’s name to post fraudulent reviews that make the seller look more popular. The agency’s consumer alert on unordered packages explains that sellers of knock-off merchandise find a target’s address and other details online, ship goods that were never requested, and then write positive reviews in that person’s name to boost their ratings and sales. The term comes from the idea of “brushing up,” or artificially increasing, a seller’s apparent business.
Because the merchandise tends to be cheap and inexpensive to ship, the operators treat the loss on each parcel as the cost of manufacturing a “verified” review. The reviews, in turn, can nudge real shoppers toward products that may be low quality or misrepresented. What looks like a harmless free gift is essentially the byproduct of a review-fraud operation running through a real person’s identity.
Why a free gift signals a data-security problem
The reason officials treat these deliveries as a warning rather than a bonus is that they confirm someone has obtained personal information and is willing to use it. The U.S. Postal Inspection Service describes the sender as typically an international third-party seller who found the recipient’s address online, and its guidance on the brushing scam notes that the same information can be reused for other schemes and illicit activity later. In other words, the package is evidence that a name and address are circulating in places the resident never authorized.
Postal investigators also flag a newer twist that raises the stakes. Some brushing packages now arrive with a card containing a QR code, presented as a way to discover who sent the gift. Scanning it can lead to a counterfeit website designed to look like a bank, a government agency, or another trusted institution, with the goal of harvesting sensitive personal details, a tactic sometimes called quishing. Investigators warn against scanning unfamiliar codes that arrive this way, because the “mystery gift” framing is engineered to make the target curious enough to click.
What the law says about keeping the merchandise
One point both agencies emphasize is that recipients are not on the hook to pay. Under federal rules, unsolicited merchandise that arrives addressed to a person may be kept, and there is no legal obligation to pay for it or return it. Postal guidance spells out the options: an unopened parcel marked with a return address can be labeled “return to sender” and sent back at no charge, an opened item can simply be discarded if unwanted, and anything the recipient likes can be kept outright.
Organic contents are the exception that calls for extra caution. If a package contains seeds, plants, food, or an unknown substance, officials advise contacting the proper authorities rather than planting or discarding it, because unsolicited seeds in particular can pose agricultural risks. The general rule of thumb is that the physical item is the recipient’s to handle, but the circumstances around it deserve scrutiny.
Steps to take after an unexpected delivery
The recommended response focuses on locking down accounts rather than chasing the sender. The FTC advises changing passwords on online shopping accounts in case they were compromised, monitoring credit reports for signs of identity theft, and notifying the marketplace so it can investigate and remove fake reviews tied to the recipient’s name. Both agencies specifically warn against contacting the sender directly, since anyone who responds is likely to press for more sensitive information.
Reporting the incident helps regulators track the operations behind it. Consumers can file a report with the FTC at its fraud reporting site, and postal investigators encourage reporting suspicious deliveries as well, especially those involving QR codes or unknown substances. Treating a surprise package as a prompt to review account security, rather than as a lucky break, is the practical takeaway from officials who study the scheme.
This article was researched and drafted with the assistance of AI and reviewed before publication.
More from Morning Overview
- The sun launched material at 3.3 million miles an hour, and Earth is in its path
- The NSA is telling every phone owner to switch off Wi-Fi, Bluetooth and NFC in public.
- A skeleton under Petra’s Treasury was found gripping a chalice that looks like the Holy Grail
- Two Ford recalls now carry a rare “do not drive” warning, so owners should check their VIN.