The FTC says scammers send unexpected, low-cost packages and use the recipient’s name to generate fake validation, including via reviews. The packages may include QR codes or “return” instructions that can lead to phishing sites aimed at stealing financial or login information.

The FTC describes “brushing scams,” where fraudsters ship an unsolicited, typically low-cost package and then use the recipient’s name to create fake legitimacy signals—most commonly by generating fraudulent reviews or validation associated with the delivery. In many cases, the scam is designed to make the seller appear credible even though the order was not actually placed by the consumer. The FTC warns that unexpected packages are a red flag even when the goods seem minor or the sender appears plausible. A key risk comes from what may be included inside the box. The FTC cautions consumers not to scan QR codes or follow return instructions printed on materials that arrive with the package. Those QR codes and prompts can direct victims to lookalike pages that harvest sensitive information, including banking details or account credentials. By clicking or entering data, victims can enable account takeover or payment fraud. The FTC’s guidance focuses on avoiding engagement with QR codes and return prompts from unsolicited deliveries.