Morning Overview

The FBI says do not scan the QR code hidden inside a mystery package

The FBI issued Alert Number I-073125-PSA warning Americans not to scan QR codes found inside unsolicited packages arriving at their doors. The alert, published through the bureau’s Internet Crime Complaint Center, describes a scheme in which criminals mail mystery parcels, often with no return address, that contain printed QR codes designed to steal personal data or install malicious software on the recipient’s phone. The warning lands at a time when separate FBI alerts have already documented mail-based QR scams targeting corporate executives with ransom demands ranging from $250,000 to $500,000.

Why mystery-package QR codes pose a growing threat

QR codes are cheap to generate and easy to print on a slip of paper tucked inside any box. Postal systems accept packages with minimal sender verification, which means a criminal can ship dozens of parcels without revealing an identity. That combination turns the mail into a low-friction attack channel that sidesteps the spam filters and domain-reputation checks that block most email and SMS phishing. The U.S. Postal Inspection Service has connected these mailings to brushing scams, where sellers ship unordered goods to generate fake purchase records, and has noted that the same packages now carry QR codes that route recipients to phishing sites.

The tactic works because people trust deliveries. A box on the porch feels tangible and legitimate in a way that a suspicious email does not. When a printed note inside the package asks the recipient to scan a code for “delivery details” or “product registration,” the physical context lowers suspicion. The FBI’s alert makes clear that scanning such a code can lead victims to hand over financial information or unknowingly download malware onto their devices.

FBI and FTC alerts trace a pattern of QR-code mail fraud

The July 2025 public-service announcement is not the first time federal agencies have flagged QR-code abuse through physical channels. The IC3 warned in January 2022 that tampered QR codes were already redirecting victims to malicious sites designed to steal login credentials and financial information, and that some codes delivered malware directly. That earlier alert focused on codes placed over legitimate ones in public spaces, such as parking meters and restaurant menus. The new warning extends the same threat model into the mail system, where recipients have even less reason to question a code that arrives alongside a physical product.

A separate FBI alert documented ransom letters mailed to corporate executives that included a QR code linked to a Bitcoin wallet. Those letters demanded between $250,000 and $500,000 and threatened to publish stolen data if the payment was not made. The progression from consumer-level brushing packages to six-figure extortion letters shows how the same delivery mechanism scales across different targets and price points.

The Federal Trade Commission has issued matching consumer guidance, confirming that QR codes in unexpected packages can route phones to fake websites or trigger harmful app downloads. The FTC also reminded recipients of a practical legal protection: under 39 U.S.C. Section 3009, anyone who receives unordered merchandise may treat it as a gift with no obligation to the sender. That statute means recipients do not need to return the package, pay for it, or engage with any instructions inside it.

What federal agencies have not yet disclosed

The FBI’s alert tells people what to avoid but leaves significant gaps in the public record. No aggregate complaint volume or total dollar losses tied specifically to the mystery-package QR scheme appear in the bureau’s announcement or on the IC3 portal. Without those numbers, it is difficult to gauge whether the threat is concentrated in certain regions or spread evenly across the country. The alert also contains no forensic detail about the domains these QR codes redirect to, the types of malware delivered, or the operating systems most affected.

The Postal Inspection Service’s guidance on brushing and quishing similarly offers prevention advice without disclosing how many packages have been intercepted, traced, or linked to specific criminal networks. No enforcement statistics or recent prosecution examples connected to QR-code mail fraud appear in any of the published federal materials. That absence makes it hard to assess whether law enforcement is actively dismantling these operations or simply issuing defensive guidance while investigations proceed behind the scenes.

The statutory framework around unordered merchandise also has limits. While 39 U.S.C. Section 3009 protects recipients from payment obligations, it was written decades before QR codes existed and does not address the data-theft dimension of these packages. Whether postal acceptance rules will be tightened to require more sender verification on small parcels is an open question that none of the current alerts address.

Anyone who receives an unexpected package containing a QR code should avoid scanning it. The FBI directs victims to file reports through the IC3 or contact a local field office. Recipients can keep the merchandise or mark the unopened package “Return to Sender” and hand it back to their mail carrier. The next development to watch is whether the FBI or IC3 releases complaint data that quantifies the scale of these attacks, which would signal whether the advisory reflects a contained problem or a rapidly expanding one.

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.