Case Library / Quishing (QR Code Phishing) / FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

FBI/USPIS/FTC "Brushing 2.0" Quishing Package Scam Advisories (2025)

The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that, when scanned, send recipients to phishing sites or malware instead of the promised gift-sender reveal or return instructions.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Across 2025, three U.S. federal agencies independently warned the public about an evolution of the long-standing "brushing" scam: unsolicited packages -- often containing low-value merchandise and no sender information -- now arrive with an enclosed QR code. The FTC's consumer alert (Jan. 23, 2025) was first to flag it, describing a note inside the package urging the recipient to scan a code to learn who sent the "gift" or how to return it. The FBI followed with formal PSA I-073125-PSA via its Internet Crime Complaint Center (IC3) on Jul. 31, 2025, formally labeling it a QR-code variant of the traditional brushing scam. USPIS built out dedicated "Quishing" and "Brushing Scam" educational pages during the year and folded the warning into its "Cut Out Crime This Holiday Season" 2025 consumer campaign, while USPS separately issued an internal employee/contractor advisory on Aug. 5, 2025. Scanning the QR code routes victims to a spoofed website impersonating a retailer, carrier, or institution that harvests personal/financial data or delivers malware. None of the three agencies published a dollar-loss figure, victim count, or complaint total specific to this scheme, and the FBI explicitly describes it as less widespread than other fraud types; the response across all three agencies was educational/advisory rather than tied to any known enforcement action or identified perpetrator.

How the Attack Worked

A consumer receives an unsolicited, low-value package (often household goods or small gadgets) at their door or in the mail, typically with no sender name listed, which is itself designed to provoke curiosity. Inside is a card or insert bearing a QR code, with instructions to scan it to "find out who sent this gift," to register/claim the item, or to arrange a return. Scanning the code routes the victim to a spoofed website impersonating a retailer, shipping carrier, bank, or government agency. That site then either harvests personal and financial information (credit card numbers, usernames/passwords, Social Security-adjacent PII) directly through a fake form, or silently pushes malware/spyware onto the phone via a disguised app-install or permissions prompt. USPIS frames this as the QR-code evolution of the long-running "brushing" scam, in which third-party e-commerce sellers ship unordered goods to real addresses so they can post fake verified-purchaser reviews in the recipient's name to inflate product ratings; the 2025 twist ("brushing 2.0") is that the package now also carries a phishing payload via QR code ("quishing" -- QR-code phishing), turning a reputation-fraud scheme into a direct identity-theft and malware-delivery vector.

The Lure & the Tell

The lure is a free "mystery gift" arriving unannounced, paired with an urgent-sounding QR code that promises to reveal who sent it or how to return/register it, exploiting curiosity, a sense of obligation ("I should find out and possibly return this"), and the general public's trained habit of scanning QR codes without scrutiny. The tell: legitimate senders (real retailers, USPS, banks) do not require scanning a QR code on a physical package to identify themselves or process a return; by law, unsolicited merchandise sent in the U.S. is the recipient's to keep for free, with no action required at all. Any package demanding a scan-to-claim, scan-to-identify-sender, or scan-to-return action, especially with no visible sender information, is the giveaway.

Outcome

No arrests, indictments, or named perpetrators have been publicly tied to this specific scheme; all three agencies' response was purely advisory and educational rather than enforcement-based. The FTC published its consumer alert on Jan. 23, 2025. The FBI's Internet Crime Complaint Center (IC3) issued formal PSA I-073125-PSA on Jul. 31, 2025, directing victims to report to ic3.gov (with a dedicated DOJ Elder Justice Hotline number for victims 60+). USPIS folded the "brushing and quishing" warning into its ongoing consumer-education content (dedicated "Quishing" and "Brushing Scam" pages, plus a "Cut Out Crime This Holiday Season" campaign promoted in Nov-Dec 2025), and USPS separately issued an internal employee/contractor advisory on Aug. 5, 2025, warning its own workforce about handling and receiving such packages. All three agencies frame the scheme as real but of limited scale relative to other fraud types, with reporting channels (IC3, ReportFraud.ftc.gov/IdentityTheft.gov, spam@uspis.gov) as the primary call to action.

Why It Matters

This case is a clean, well-documented example of a "hybrid" social-engineering vector that fuses a physical-world trigger (an unexpected package showing up at your door) with a digital payload (a QR code leading to phishing/malware), deliberately routing around the defenses people are trained to apply to email and text: there's no suspicious link to hover over, no sender email to scrutinize, just a physical object and a code. It also illustrates how a purely reputational fraud scheme (brushing, aimed at inflating product ratings) was retooled by adding a credential-harvesting/malware step, showing how established scam infrastructure gets upgraded with new technical hooks (QR codes) as they become culturally normalized. That three separate federal agencies (FBI, FTC, USPIS) each felt compelled to issue standalone public advisories on the same mechanic in a single year, despite acknowledging it isn't yet high-volume, signals it as an emerging vector worth front-loading into awareness training before it scales.

Defenses

All three agencies converge on the same core guidance: never scan a QR code from an unsolicited or unknown-origin package, email, or text; unsolicited merchandise is legally yours to keep under U.S. law so there is no need to "register," "return," or "identify the sender" via any code or link; if a code was scanned and credentials entered, change passwords immediately and enable two-factor authentication; pull a free credit report (AnnualCreditReport.com) and watch for unfamiliar accounts; consider a credit freeze or fraud alert; check phone permissions/apps granted after scanning and remove suspicious ones; report incidents to the FBI at IC3.gov, to the FTC at ReportFraud.ftc.gov / IdentityTheft.gov, and to USPIS via spam@uspis.gov or uspis.gov/report; if genuinely concerned about package contents, use USPS's "Return to Sender" (if a return address exists and unopened) or the Suspicious Mail process rather than any QR-based instructions.

Sources
  • Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes (PSA I-073125-PSA). FBI / Internet Crime Complaint Center (IC3) Primary. Official PSA, published Jul. 31, 2025; states the scheme is a QR-code variant of brushing scams and 'not as widespread as other fraud schemes'; no loss figures given. Fetched and confirmed live 2026-07-29.
  • Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes. FBI Primary. FBI.gov mirror of the same PSA content. Fetched and confirmed live 2026-07-29.
  • Scam alert: QR code on an unexpected package. Federal Trade Commission Primary. Published Jan. 23, 2025 by Alvaro Puig, FTC Consumer Education Specialist; describes the scam mechanics and remediation steps. Fetched and confirmed live 2026-07-29.
  • Quishing. United States Postal Inspection Service Primary. USPIS explainer defining quishing and its brushing-package variant, with reporting instructions (spam@uspis.gov). Fetched and confirmed live 2026-07-29.
  • Brushing Scam. United States Postal Inspection Service Primary. Published Mar. 24, 2025 (confirmed via independent search of page metadata); details the traditional brushing scam and its 2025 quishing-card evolution, plus protective steps. Fetched and confirmed live 2026-07-29.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Address and target sourcing: USPIS describes brushing operators, typically overseas third-party e-commerce sellers, as obtaining real recipient names and mailing addresses through commercially available data broker lists, prior order/shipping databases, or scraped public listings, with no need to contact the victim in advance.
Countering Stage 1: Consumers cannot realistically stop their name and address from circulating in commercial data-broker and e-commerce shipping databases; the practical control is downstream, treating any unsolicited package as suspect regardless of how the sender obtained the address.
2
Low-cost merchandise and QR-card production: The actor sources cheap, low-value goods (household items, small gadgets) and produces an insert card carrying a QR code, consistent with the FBI and USPIS description of the scheme as an upgrade to the existing brushing-scam supply chain rather than a new logistics operation.
Countering Stage 2: There is no consumer-side control over what a scammer sources or prints before shipping; the FBI and USPIS guidance instead targets what the recipient does once the card arrives, covered at Stage 5.
3
Spoofed landing page setup: Before packages ship, the actor stands up a phishing site designed to impersonate a retailer, shipping carrier, bank, or government agency, likely using look-alike domain registration and cloned branding, so the QR code has a convincing destination the moment it is scanned.
Countering Stage 3: Look-alike domains and cloned retailer branding are hard for an individual to detect pre-emptively; the effective control is not visiting the destination at all, which is why every agency's top tip is never scan the code rather than scrutinize the resulting site.
4
Unsolicited delivery: The package is shipped to the target's real address with no sender information listed, a deliberate omission that both enables the traditional fake-review brushing motive and heightens curiosity about the enclosed QR card.
Countering Stage 4: Recognize that an unsolicited package with no sender information is itself a warning sign, and remember that under U.S. law unsolicited merchandise is the recipient's to keep for free with no obligation to respond, register, or return it.
5
Curiosity-driven scan: The recipient, prompted by the card's instructions to scan the code to learn who sent the gift or how to return/register it, scans it with their phone camera, exploiting habituated QR-scanning behavior and a sense of obligation around an unexpected gift.
Countering Stage 5: Never scan a QR code from an unknown-origin package, email, or text, especially one urging immediate action; USPIS explicitly advises asking where a QR code came from before scanning.
6
Credential harvest or malware delivery: The spoofed site either collects personal and financial information directly through a fake form or pushes malware/spyware onto the device via a disguised app-install or permissions prompt, per the FBI PSA and FTC alert.
Countering Stage 6: If a code was already scanned and credentials entered, change the affected passwords immediately, enable two-factor authentication, and review phone app permissions granted after scanning to remove anything suspicious.
7
Objective completion: The actor monetizes the harvested data or device access through financial/payment card fraud, identity theft, or resale of PII, while the traditional brushing side-effect (a fake verified-purchaser review posted in the recipient's name) continues to inflate the seller's product ratings.
Countering Stage 7: Pull a free credit report from AnnualCreditReport.com, monitor bank and credit card statements for unfamiliar activity, consider a credit freeze or fraud alert, and report the incident to IC3.gov, ReportFraud.ftc.gov/IdentityTheft.gov, or spam@uspis.gov so agencies can track the scheme's scale.
Quick Facts
Victim
US postal customers / consumers nationwide (general public, no named individual victims)
Location
United States (nationwide)
Date
2025 (FTC consumer alert Jan 23, 2025; FBI IC3 PSA I-073125-PSA Jul 31, 2025; USPS employee advisory Aug 5, 2025; USPIS holiday advisory campaign Nov-Dec 2025)
Impact
No dollar-loss figure or victim/complaint count specific to this quishing-brushing package variant has been published by any of the three agencies. The FBI PSA explicitly characterizes the scheme as "not as widespread as other fraud schemes" and gives no loss estimate; the FTC's Jan. 23, 2025 alert and the USPIS quishing/brushing pages likewise cite no figures for this specific scam. (For context only, not specific to this scheme: the FTC separately reported $470 million in aggregate consumer losses to text-message scams in 2024, with fake package-delivery texts the most commonly reported type, a related but distinct SMS-based scam category.) Given the absence of hard loss/victim data, financial impact should be treated as unquantified/unknown rather than zero.
Status
Confirmed
Case Type
Research / Advisory
Sector
Consumer / General Public, Retail & E-commerce, Transportation & Logistics
Related

Related Cases

Orlando Downtown ParkMobile QR Parking Meter Sticker Scam (2025)

Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters, redirecting drivers who scanned…

Incident 2025Read →

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…

Incident 2024Read →

LevelBlue MTDR SOC "Quishing" Case Study - Fake Microsoft MFA-Setup QR Code Harvests Employee Credentials (2023)

LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…

Incident 2023Read →