An unexpected parcel that nobody ordered can feel like a harmless mix-up or even a small stroke of luck. Federal consumer regulators are cautioning that it can also be a signal that something is wrong with a household’s personal information.
The Federal Trade Commission has flagged these surprise deliveries as a possible sign of a “brushing” scam, a scheme built around fake reviews and, increasingly, phishing. The agency’s alert lays out what the packages usually contain and why receiving one is worth a second look.
How a brushing scam actually works
In a brushing scam, a seller uses a real person’s name and address to generate what looks like a genuine order and delivery. That delivery record then serves as “proof” the seller needs to post a fake review under that person’s identity, inflating a product’s ratings to make it appear more popular than it is.
The recipient never bought anything, but their name becomes a tool for boosting a seller’s sales. Because the package is delivered to a real address, the fake review can be presented as coming from a verified purchaser. That “verified” label carries weight on shopping platforms, where reviews tied to a confirmed delivery tend to rank higher and appear more trustworthy to other shoppers, which is exactly the credibility a dishonest seller is trying to manufacture.
What tends to be inside the box
According to the FTC, recent reports describe packages that hold something cheap and random, such as baby wipes, toothpaste, or seeds. The low-value contents fit the scheme, since the sender’s goal is a delivery record, not a valuable gift.
The parcel might appear to come from a well-known retailer, or from a person or business the recipient has never heard of. The mismatch between an unordered item and a familiar-looking label is one reason the deliveries can be confusing rather than immediately alarming. There is also usually no packing slip, no invoice, and no way to trace who actually placed the order, which leaves the person holding an item they cannot return through any normal channel.
The QR code twist that raises the stakes
The agency has added a newer warning about notes tucked inside these packages. Sometimes the sender includes a slip printed with a QR code, and scanning it can be the real danger.
The FTC has said those codes can route people to phishing websites built to steal information, including credit card numbers, usernames, and passwords. That turns a curiosity, a mystery box with an unexplained code, into a potential path to account theft for anyone who scans without thinking.
Why an unordered package can signal a data problem
Beyond the fake-review scheme, the FTC notes that receiving a package a household never ordered can be a sign that someone already has, or is trying to obtain, that household’s personal information. The delivery may be a byproduct of data that has leaked or been bought and sold.
That framing matters because the box itself may be the least of the problem. If a stranger has enough details to route a shipment to a specific name and address, the same details could be misused elsewhere. Names, addresses, and other basic identifiers circulate widely after data breaches, and a brushing delivery can be the first visible clue that a household’s information is being traded, even when no financial account has yet been touched.
Steps the FTC recommends after a surprise delivery
The agency’s guidance focuses on limiting downstream harm. Recipients are advised to change the passwords on their online shopping accounts, since those accounts are a common target when personal information is circulating.
The FTC also recommends reviewing credit card statements for charges that do not belong, and confirming that no one is being billed for the unordered item or pressured to return it. Consumers can read the agency’s brushing scam alert for the full breakdown of the warning signs and the actions to take.
Recipients should also resist the urge to scan any enclosed QR code or follow instructions printed on a note inside the box. Treating the code as untrusted removes the most direct route the scheme offers to a phishing page.
A pattern worth watching
Brushing has circulated for years, but the addition of QR-code phishing shows how an old scheme can be updated with newer tools. A tactic once aimed mainly at gaming online reviews now doubles as a delivery vehicle for credential theft. The physical package lends the whole approach an air of legitimacy that a plain email or text lacks, which is part of why a printed code inside a real box can lower a recipient’s guard.
The practical takeaway from the FTC is straightforward: an unexpected package is not a reason to panic, but it is a reason to check accounts, watch statements, and avoid scanning anything that arrives unbidden. Treating the delivery as a prompt to tighten security, rather than as free merchandise, is the safer response. There is no legal obligation to pay for or return goods that were never ordered, so a recipient can keep or discard the item, but the more valuable step is treating the arrival as a cue to review where personal information may have leaked. Reporting the incident to the platform the package appears to come from can also help retailers identify and remove the fake reviews the scheme is built to plant.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview