← All researched cases
Current multi-source warningThis is not a user complaint. It synthesises the linked public record and was last reviewed 25 August 2026.
Active delivery-linked warningGSR-R-016

Unsolicited-package QR scams

The FBI warned in July 2025 that unexpected parcels can include QR codes intended to move recipients into credential theft or malicious downloads.

QR phishing · Identity theftUnited States · International variants
Editorial artwork of a QR code on an unsolicited parcel opening a malicious portal
Original editorial illustration — not evidence or a photograph of the case.

Summary

What the record shows

A recipient receives an item they did not order, sometimes with no clear sender, and a QR code inviting them to identify the sender, arrange a return or learn more. Scanning can open a phishing site or trigger a malicious download.

This overlaps with “brushing,” where low-value parcels are sent to generate false reviews, but the QR-code variant adds a direct digital compromise risk.

Key findings

What is established and what is not

  • Do not scan codes in unsolicited parcels; use a known retailer or carrier account to investigate.
  • A physical object can make a digital link feel more trustworthy without authenticating it.
  • If a code was scanned, review permissions, change exposed credentials and contact the relevant financial provider.

Response and denials

The other side of the record

The reviewed material describes a distributed pattern using changing accounts, numbers and sites. No single identifiable operator or attributable operator denial was located.

Some approaches misuse the identity of retailers, carriers or purported senders. Those impersonated organisations are not treated as participants; verify any contact through an independently located official channel.

Global Scam Report evaluation

Summary assessment

Documented, active delivery-linked phishing technique — high confidence. Not every unsolicited parcel contains a malicious code, and technical inspection is needed to establish what a particular code does.

Scope qualificationDo not publish a live malicious QR code. Preserve it privately and use a non-clickable description or redacted image for reporting.

Reference record

Sources reviewed

  1. GovernmentFederal Bureau of Investigation · 31 July 2025Unsolicited packages containing QR codes used to initiate fraudOpen source ↗
  2. GovernmentUS Postal Inspection Service · 24 March 2025Brushing scamOpen source ↗
  3. GovernmentUS Federal Trade Commission · 6 December 2023Scammers hide harmful links in QR codesOpen source ↗
  4. GovernmentUS Postal Inspection Service · 19 May 2025Smishing: package-tracking text scamsOpen source ↗
  5. GovernmentFederal Bureau of Investigation · 20262025 Internet Crime ReportOpen source ↗
  6. GovernmentUS Federal Trade Commission · February 2025Consumer Sentinel Network Data Book 2024Open source ↗
  7. GovernmentUS Federal Trade Commission · May 2025How to avoid a scam — fraud handbookOpen source ↗