NewSecurity Audit Kit — audit your business in 15 minutes.Launch $49· limited time offer
QR code scambrushing scammystery package scamquishingpackage scamUSPS

The Mystery Package QR Code Scam: Why You Shouldn't Scan It

Courtney
9 min read
Share
Free Interactive Guide

Free: How to Keep Yourself Safe From Scammers

9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.

The Mystery Package QR Code Scam: Why You Shouldn't Scan It

A box shows up on your porch. You didn't order anything. No return address, no invoice, just a cheap ring, a pack of stickers, or some random gadget — and a little card with a QR code on it that says "scan to find out who sent this" or "scan to track your delivery."

Frankenmuth police in Saginaw County, Michigan, put out a warning about exactly this on July 15, after residents started reporting the packages showing up on their doorsteps (WNEM). They're not the only ones. The FBI's Internet Crime Complaint Center flagged the same scheme in a public service announcement, and the Better Business Bureau has been logging reports through its Scam Tracker (IC3 PSA) (BBB). The whole thing runs on one instinct: curiosity. You didn't order it, so obviously you want to know who sent it. That's the trap.

How this scam actually works

This is a twist on something the U.S. Postal Inspection Service has tracked for years called a "brushing scam." Originally, brushing was mostly harmless: shady online sellers ship cheap junk to random addresses they scraped from a data leak, then use your name to post a fake five-star review and juice their store's ratings (USPIS). Annoying, but not dangerous — you just kept the free stuff.

The 2026 version adds a QR code to the mix, and that's where it stops being harmless. Here's the sequence, according to the FBI's IC3 advisory:

  1. A package arrives with no return address, no order confirmation, nothing that ties it to a store you've heard of. Inside is a low-value item — a ring, an accessory, a gadget — and a printed card or sticker with a QR code.
  2. The card frames the code as something you need: "scan to find out who sent this," "scan to track your package," "scan to register your gift" or start a return.
  3. Scanning it takes you to a fake website built to harvest whatever you type in — your name, address, card number, login credentials — or in some versions, it prompts you to download an "app" that's actually malware built to pull data straight off your phone.
  4. Because you initiated the scan yourself, out of curiosity rather than pressure, there's no red-flag moment where an urgent voice or a scary threat tips you off. That's the whole design.

The IC3 advisory ties this specifically to the "no sender information" detail — scammers leave the package deliberately unlabeled because a mystery is a stronger hook than a name you'd recognize and immediately distrust.

Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.

Scan it free →

Why this one is harder to spot than a delivery text

You've probably already trained yourself to be suspicious of a text that says "your package couldn't be delivered, click here." Most people have — package delivery scam texts are the most-reported text scam category in the country. But this scam skips the text message entirely and shows up as a physical object in your hand. There's no shortened link to squint at, no obviously fake sender number. Just a box, which feels a lot more real than a text ever could.

It also flips the emotional trigger. Delivery texts work through urgency — pay now or lose your package. The mystery box works through curiosity — who sent this, and why. Curiosity doesn't feel like pressure, so it doesn't set off the same internal alarm that a countdown timer or a threat does. You're not being rushed. You're being nosy, and scammers are betting that's a harder impulse to override.

The red flags hiding in plain sight

  • No return address or sender name. Every legitimate package ties back to a retailer, even if it's a gift. A box with nothing identifying who sent it is the first tell.
  • A QR code physically included in the box. Legitimate retailers put tracking and return information on the packing slip or in an email, not on a loose card inside the box demanding a scan.
  • Language that manufactures urgency or curiosity instead of just informing you. "Scan to find out who sent this" is bait, not information — a real gift note tells you who it's from.
  • A low-cost, generic item. Rings, phone accessories, small electronics, and stickers are common because they're cheap to mass-produce and ship to thousands of addresses at once.
  • You never ordered anything remotely like it. Check your recent orders across every account before assuming a family member sent it as a surprise.
  • The QR code claims to unlock something you'd normally get without scanning anything — tracking info, a gift message, a return label. Real versions of all three arrive by email or are printed directly on the shipping label.

If this already happened to you

Don't scan it if you haven't yet — that's the only step that actually matters before anything else. If you already did:

If you only scanned it and closed the page without typing anything: your risk is low. Close the tab, don't go back, and check your phone's recently granted app permissions for anything unfamiliar.

If you entered any personal or payment information on the site it opened: call your bank or card issuer now and flag the card as potentially compromised. Then follow our what to do after clicking a scam link guide for the full recovery checklist.

If you downloaded anything the page prompted you to install: back up your photos and factory-reset the phone. Don't just delete the app — a malicious install can leave things behind.

Either way, request a free credit report from Equifax, Experian, or TransUnion to check for anything unfamiliar, per the FBI's recommendation. If your name and address were harvested along with anything else, treat it as a data-exposure event, not just a bad scan — our what to do after a data breach guide covers the full lockdown steps.

Report it. File with the FBI's IC3 at ic3.gov and with the BBB Scam Tracker at bbb.org/scamtracker — both feed law enforcement patterns that lead to takedowns.

How to not become the next mystery-box victim

  • Don't scan QR codes from unsolicited mail, period. If you want to know what's in a package or where it came from, check your order history across retailers first. If nothing matches, the box is not for you to investigate — it's bait.
  • Keep the item if you want; you're not obligated to send it back or pay for it. The FTC's unordered-merchandise rule means it's legally yours. You just don't need to interact with anything else in the box.
  • If you're genuinely curious who sent it, look it up manually. Type the retailer's name into your browser instead of following any code or link included with the package.
  • Run any suspicious link through a scanner before you click it, whether it came from a QR code, a text, or an email. Cautellus's QR code scanner checks where a code actually leads before your phone does.
  • Talk to people in your house who order online a lot. The person most likely to scan out of curiosity is the person who orders enough packages that one more showing up doesn't seem strange.

This scam sits right next to the broader QR code scam (quishing) landscape that's been hitting parking meters and payment kiosks all year, and it borrows the same trick scammers use with fake delivery texts: make the ask feel routine enough that you skip the fifteen seconds of skepticism that would catch it. For the full rundown on how scam texts and smishing campaigns operate more broadly, see our text message scams hub — and if you get an actual delivery notice you want to verify, go straight to USPS's real scam guidance instead of anything printed on a card in a box.

Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.

Check it now →

FAQ

Is it illegal for me to keep a package I never ordered?

No. The FTC's mail-order rule says unordered merchandise is a gift — you're under no legal obligation to pay for it or send it back, even if a note inside demands payment or return. Keep it, and just don't scan anything that came with it.

How did scammers get my address if I never gave it to them?

Mailing addresses are widely available through data breaches, data brokers, and even public records. This scam doesn't require the sender to know anything specific about you — mass-shipping cheap items to scraped address lists is cheap enough that scammers don't need precision.

What actually happens if I scan the QR code?

Depending on the version, you land on a fake site designed to harvest whatever information you type in — often disguised as a "claim your prize" or "track your package" form — or you're prompted to download an app that pulls data directly from your phone. Neither outcome benefits you in any way.

Should I report it even if I didn't scan the code?

Yes. Reporting the package itself — even unscanned — to the FBI's IC3 (ic3.gov) or the BBB Scam Tracker helps investigators map where these mailings are originating and who's receiving them.

Is this the same as a normal brushing scam?

It's related but more dangerous. Traditional brushing scams just use your identity to post a fake review — annoying, but not something that steals your money. The QR code version adds an active phishing or malware component, which is why the FBI treats it as a distinct threat worth a dedicated advisory.

Can Cautellus check a QR code before I scan it?

Yes. Run the code through Cautellus's QR code scanner first — it checks the destination against a live database of confirmed scam and phishing domains before your phone ever loads the page.

The scammers mailing these boxes are betting that curiosity beats caution. Don't give them the fifteen seconds it takes to prove them right.


Sources: WNEM, "Mystery package scam target victims with fake QR codes, police say," July 15, 2026; FBI Internet Crime Complaint Center, "Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes," PSA250731; Better Business Bureau, "BBB Tip: Don't scan QR codes on unexpected packages"; U.S. Postal Inspection Service, "Brushing Scam"

Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.

Scan something free →
C

Courtney

Founder, Cautellus · 20+ years in financial services

Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.

Learn more

Keep reading

Support Our Mission

Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.

Found This Helpful?

Try Cautellus to analyze suspicious messages, links, and images and protect yourself from fraud.

Try the Scam Scanner