The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned.
Social Engineering Examples·5 sources
Across 2025, three U.S. federal agencies independently warned the public about an evolution of the long-standing "brushing" scam: unsolicited packages -- often containing low-value merchandise and no sender information -- now arrive with an enclosed QR code. The FTC's consumer alert (Jan. 23, 2025) was first to flag it, describing a note inside the package urging the recipient to scan a code to learn who sent the "gift" or how to return it.
The FBI followed with formal PSA I-073125-PSA via its Internet Crime Complaint Center (IC3) on Jul. 31, 2025, formally labeling it a QR-code variant of the traditional brushing scam. USPIS built out dedicated "Quishing" and "Brushing Scam" educational pages during the year and folded the warning into its "Cut Out Crime This Holiday Season" 2025 consumer campaign, while USPS separately issued an internal employee/contractor advisory on Aug. 5, 2025. Scanning the QR code routes victims to a spoofed website impersonating a retailer, carrier, or institution that harvests personal/financial data or delivers malware.
None of the three agencies published a dollar-loss figure, victim count, or complaint total specific to this scheme, and the FBI explicitly describes it as less widespread than other fraud types; the response across all three agencies was educational/advisory rather than tied to any known enforcement action or identified perpetrator.
A consumer receives an unsolicited, low-value package (often household goods or small gadgets) at their door or in the mail, typically with no sender name listed, which is itself designed to provoke curiosity. Inside is a card or insert bearing a QR code, with instructions to scan it to "find out who sent this gift," to register/claim the item, or to arrange a return.
Scanning the code routes the victim to a spoofed website impersonating a retailer, shipping carrier, bank, or government agency. That site then either harvests personal and financial information (credit card numbers, usernames/passwords, Social Security-adjacent PII) directly through a fake form, or silently pushes malware/spyware onto the phone via a disguised app-install or permissions prompt.
USPIS frames this as the QR-code evolution of the long-running "brushing" scam, in which third-party e-commerce sellers ship unordered goods to real addresses so they can post fake verified-purchaser reviews in the recipient's name to inflate product ratings; the 2025 twist ("brushing 2.0") is that the package now also carries a phishing payload via QR code ("quishing" -- QR-code phishing), turning a reputation-fraud scheme into a direct identity-theft and malware-delivery vector.
The lure is a free "mystery gift" arriving unannounced, paired with an urgent-sounding QR code that promises to reveal who sent it or how to return/register it, exploiting curiosity, a sense of obligation ("I should find out and possibly return this"), and the general public's trained habit of scanning QR codes without scrutiny. The tell: legitimate senders (real retailers, USPS, banks) do not require scanning a QR code on a physical package to identify themselves or process a return; by law, unsolicited merchandise sent in the U.S. is the recipient's to keep for free, with no action required at all.
Any package demanding a scan-to-claim, scan-to-identify-sender, or scan-to-return action, especially with no visible sender information, is the giveaway.
No arrests, indictments, or named perpetrators have been publicly tied to this specific scheme; all three agencies' response was purely advisory and educational rather than enforcement-based. The FTC published its consumer alert on Jan. 23, 2025. The FBI's Internet Crime Complaint Center (IC3) issued formal PSA I-073125-PSA on Jul. 31, 2025, directing victims to report to ic3.gov (with a dedicated DOJ Elder Justice Hotline number for victims 60+).
USPIS folded the "brushing and quishing" warning into its ongoing consumer-education content (dedicated "Quishing" and "Brushing Scam" pages, plus a "Cut Out Crime This Holiday Season" campaign promoted in Nov-Dec 2025), and USPS separately issued an internal employee/contractor advisory on Aug. 5, 2025, warning its own workforce about handling and receiving such packages.
All three agencies frame the scheme as real but of limited scale relative to other fraud types, with reporting channels (IC3, ReportFraud.ftc.gov/IdentityTheft.gov, spam@uspis.gov) as the primary call to action.
This case is a clean, well-documented example of a "hybrid" social-engineering vector that fuses a physical-world trigger (an unexpected package showing up at your door) with a digital payload (a QR code leading to phishing/malware), deliberately routing around the defenses people are trained to apply to email and text: there's no suspicious link to hover over, no sender email to scrutinize, just a physical object and a code.
It also illustrates how a purely reputational fraud scheme (brushing, aimed at inflating product ratings) was retooled by adding a credential-harvesting/malware step, showing how established scam infrastructure gets upgraded with new technical hooks (QR codes) as they become culturally normalized. That three separate federal agencies (FBI, FTC, USPIS) each felt compelled to issue standalone public advisories on the same mechanic in a single year, despite acknowledging it isn't yet high-volume, signals it as an emerging vector worth front-loading into awareness training before it scales.
All three agencies converge on the same core guidance: never scan a QR code from an unsolicited or unknown-origin package, email, or text; unsolicited merchandise is legally yours to keep under U.S. law so there is no need to "register," "return," or "identify the sender" via any code or link; if a code was scanned and credentials entered, change passwords immediately and enable two-factor authentication; pull a free credit report (AnnualCreditReport.com) and watch for unfamiliar accounts; consider a credit freeze or fraud alert; check phone permissions/apps granted after scanning and remove suspicious ones; report incidents to the FBI at IC3.gov, to the FTC at ReportFraud.ftc.gov / IdentityTheft.gov, and to USPIS via spam@uspis.gov or uspis.gov/report; if genuinely concerned about package contents, use USPS's "Return to Sender" (if a return address exists and unopened) or the Suspicious Mail process rather than any QR-based instructions.
Social Engineering Examples. “FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)”. Accessed 19 September 2026. https://socialengineeringexamples.com/fbi-uspis-ftc-quishing-brushing-package-scam-2025
USPIS describes brushing operators, typically overseas third-party e-commerce sellers, as obtaining real recipient names and mailing addresses through commercially available data broker lists, prior order/shipping databases, or scraped public listings, with no need to contact the victim in advance.
Consumers cannot realistically stop their name and address from circulating in commercial data-broker and e-commerce shipping databases; the practical control is downstream, treating any unsolicited package as suspect regardless of how the sender obtained the address.
The actor sources cheap, low-value goods (household items, small gadgets) and produces an insert card carrying a QR code, consistent with the FBI and USPIS description of the scheme as an upgrade to the existing brushing-scam supply chain rather than a new logistics operation.
There is no consumer-side control over what a scammer sources or prints before shipping; the FBI and USPIS guidance instead targets what the recipient does once the card arrives, covered at Stage 5.
Before packages ship, the actor stands up a phishing site designed to impersonate a retailer, shipping carrier, bank, or government agency, likely using look-alike domain registration and cloned branding, so the QR code has a convincing destination the moment it is scanned.
Look-alike domains and cloned retailer branding are hard for an individual to detect pre-emptively; the effective control is not visiting the destination at all, which is why every agency's top tip is never scan the code rather than scrutinize the resulting site.
The package is shipped to the target's real address with no sender information listed, a deliberate omission that both enables the traditional fake-review brushing motive and heightens curiosity about the enclosed QR card.
Recognize that an unsolicited package with no sender information is itself a warning sign, and remember that under U.S. law unsolicited merchandise is the recipient's to keep for free with no obligation to respond, register, or return it.
The recipient, prompted by the card's instructions to scan the code to learn who sent the gift or how to return/register it, scans it with their phone camera, exploiting habituated QR-scanning behavior and a sense of obligation around an unexpected gift.
Never scan a QR code from an unknown-origin package, email, or text, especially one urging immediate action; USPIS explicitly advises asking where a QR code came from before scanning.
The spoofed site either collects personal and financial information directly through a fake form or pushes malware/spyware onto the device via a disguised app-install or permissions prompt, per the FBI PSA and FTC alert.
If a code was already scanned and credentials entered, change the affected passwords immediately, enable two-factor authentication, and review phone app permissions granted after scanning to remove anything suspicious.
The actor monetizes the harvested data or device access through financial/payment card fraud, identity theft, or resale of PII, while the traditional brushing side-effect (a fake verified-purchaser review posted in the recipient's name) continues to inflate the seller's product ratings.
Pull a free credit report from AnnualCreditReport.com, monitor bank and credit card statements for unfamiliar activity, consider a credit freeze or fraud alert, and report the incident to IC3.gov, ReportFraud.ftc.gov/IdentityTheft.gov, or spam@uspis.gov so agencies can track the scheme's scale.
Browse by what this case has in common with others in the library.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
To unmask a boardroom leaker, HP's leak investigators and their hired data brokers impersonated directors and journalists to trick phone…
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes…
Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3…