The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned, send recipients to phishing sites or malware instead of the promised gift-sender reveal or return instructions.
Reviewed by the Social Engineering Examples team.
Across 2025, three U.S. federal agencies independently warned the public about an evolution of the long-standing "brushing" scam: unsolicited packages -- often containing low-value merchandise and no sender information -- now arrive with an enclosed QR code. The FTC's consumer alert (Jan. 23, 2025) was first to flag it, describing a note inside the package urging the recipient to scan a code to learn who sent the "gift" or how to return it. The FBI followed with formal PSA I-073125-PSA via its Internet Crime Complaint Center (IC3) on Jul. 31, 2025, formally labeling it a QR-code variant of the traditional brushing scam. USPIS built out dedicated "Quishing" and "Brushing Scam" educational pages during the year and folded the warning into its "Cut Out Crime This Holiday Season" 2025 consumer campaign, while USPS separately issued an internal employee/contractor advisory on Aug. 5, 2025. Scanning the QR code routes victims to a spoofed website impersonating a retailer, carrier, or institution that harvests personal/financial data or delivers malware. None of the three agencies published a dollar-loss figure, victim count, or complaint total specific to this scheme, and the FBI explicitly describes it as less widespread than other fraud types; the response across all three agencies was educational/advisory rather than tied to any known enforcement action or identified perpetrator.
A consumer receives an unsolicited, low-value package (often household goods or small gadgets) at their door or in the mail, typically with no sender name listed, which is itself designed to provoke curiosity. Inside is a card or insert bearing a QR code, with instructions to scan it to "find out who sent this gift," to register/claim the item, or to arrange a return. Scanning the code routes the victim to a spoofed website impersonating a retailer, shipping carrier, bank, or government agency. That site then either harvests personal and financial information (credit card numbers, usernames/passwords, Social Security-adjacent PII) directly through a fake form, or silently pushes malware/spyware onto the phone via a disguised app-install or permissions prompt. USPIS frames this as the QR-code evolution of the long-running "brushing" scam, in which third-party e-commerce sellers ship unordered goods to real addresses so they can post fake verified-purchaser reviews in the recipient's name to inflate product ratings; the 2025 twist ("brushing 2.0") is that the package now also carries a phishing payload via QR code ("quishing" -- QR-code phishing), turning a reputation-fraud scheme into a direct identity-theft and malware-delivery vector.
The lure is a free "mystery gift" arriving unannounced, paired with an urgent-sounding QR code that promises to reveal who sent it or how to return/register it, exploiting curiosity, a sense of obligation ("I should find out and possibly return this"), and the general public's trained habit of scanning QR codes without scrutiny. The tell: legitimate senders (real retailers, USPS, banks) do not require scanning a QR code on a physical package to identify themselves or process a return; by law, unsolicited merchandise sent in the U.S. is the recipient's to keep for free, with no action required at all. Any package demanding a scan-to-claim, scan-to-identify-sender, or scan-to-return action, especially with no visible sender information, is the giveaway.
No arrests, indictments, or named perpetrators have been publicly tied to this specific scheme; all three agencies' response was purely advisory and educational rather than enforcement-based. The FTC published its consumer alert on Jan. 23, 2025. The FBI's Internet Crime Complaint Center (IC3) issued formal PSA I-073125-PSA on Jul. 31, 2025, directing victims to report to ic3.gov (with a dedicated DOJ Elder Justice Hotline number for victims 60+). USPIS folded the "brushing and quishing" warning into its ongoing consumer-education content (dedicated "Quishing" and "Brushing Scam" pages, plus a "Cut Out Crime This Holiday Season" campaign promoted in Nov-Dec 2025), and USPS separately issued an internal employee/contractor advisory on Aug. 5, 2025, warning its own workforce about handling and receiving such packages. All three agencies frame the scheme as real but of limited scale relative to other fraud types, with reporting channels (IC3, ReportFraud.ftc.gov/IdentityTheft.gov, spam@uspis.gov) as the primary call to action.
This case is a clean, well-documented example of a "hybrid" social-engineering vector that fuses a physical-world trigger (an unexpected package showing up at your door) with a digital payload (a QR code leading to phishing/malware), deliberately routing around the defenses people are trained to apply to email and text: there's no suspicious link to hover over, no sender email to scrutinize, just a physical object and a code. It also illustrates how a purely reputational fraud scheme (brushing, aimed at inflating product ratings) was retooled by adding a credential-harvesting/malware step, showing how established scam infrastructure gets upgraded with new technical hooks (QR codes) as they become culturally normalized. That three separate federal agencies (FBI, FTC, USPIS) each felt compelled to issue standalone public advisories on the same mechanic in a single year, despite acknowledging it isn't yet high-volume, signals it as an emerging vector worth front-loading into awareness training before it scales.
All three agencies converge on the same core guidance: never scan a QR code from an unsolicited or unknown-origin package, email, or text; unsolicited merchandise is legally yours to keep under U.S. law so there is no need to "register," "return," or "identify the sender" via any code or link; if a code was scanned and credentials entered, change passwords immediately and enable two-factor authentication; pull a free credit report (AnnualCreditReport.com) and watch for unfamiliar accounts; consider a credit freeze or fraud alert; check phone permissions/apps granted after scanning and remove suspicious ones; report incidents to the FBI at IC3.gov, to the FTC at ReportFraud.ftc.gov / IdentityTheft.gov, and to USPIS via spam@uspis.gov or uspis.gov/report; if genuinely concerned about package contents, use USPS's "Return to Sender" (if a return address exists and unopened) or the Suspicious Mail process rather than any QR-based instructions.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…