Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


To understand “what is a brushing scam?”, focus on the seller's goal: sending unsolicited merchandise and using its delivery to support fake reviews or apparent sales. An unexpected parcel may fit that pattern, but it can also be a gift, a wrong delivery or an order made through your account. Start by checking the label and your own order history; do not scan a code inside the package to identify the sender.[1][2]
Use the digital privacy guide for the wider account checks. Receiving a parcel does not by itself prove that a shopping account was accessed.
Key Takeaways
- Brushing uses a real delivery to create misleading purchase or review credibility.
- Separate unsolicited merchandise from a parcel addressed to someone else and from an unauthorized order.
- A package QR code scam can lead to phishing. Open the retailer or carrier independently.
- U.S. unsolicited-merchandise guidance does not establish the rule for every country or for a neighbor's misdelivered property.
A seller can spend money on a cheap shipment to make fabricated activity appear more convincing. The intended benefit is increased credibility for a listing, rather than a legitimate sale to the person who receives the goods. Postal inspectors describe fake reviews written in the recipient's name and efforts to inflate product ratings.[2]
The visible parcel is only one part of the event. You may not be able to find the associated review or identify the seller from the packaging. Do not invent a conclusion from an unfamiliar return address: fulfillment services and legitimate gifts can also produce labels you do not recognize.
The FTC warns that some packages include a QR code promising to reveal the sender or process a return. It can take you to a page that collects account or payment information. The parcel does not make that page trustworthy; treat the request to sign in as a separate decision.[1]
This guide uses an original check of three records: delivery label, retailer account and payment history. Comparing those records is more useful than assuming every unusual item is brushing. It also makes the eventual report more precise: you can explain what arrived, what your account shows and whether any charge exists.
| What you find | What it may mean | Next check |
|---|---|---|
| Someone else's name or address | A delivery error | Contact the carrier independently |
| Your details, a known gift or a matching order | A legitimate shipment | Confirm with the buyer or retailer through known channels |
| Your details, no order and no charge | Possible unsolicited merchandise or brushing | Record the parcel and contact the retailer |
| An order or charge you did not authorize | Possible account or payment misuse | Report the transaction and secure affected access |
| A code demanding login or a fee | A separate phishing or payment lure | Do not follow it; inspect the account directly |
Ask other household members about purchases or gifts before filing a fraud report. Check subscriptions, split shipments and orders placed under another account you legitimately use. These checks are not an instruction to ignore suspicious activity; they reduce the chance of confusing an ordinary order with identity theft.
If the label is not yours, do not apply “free merchandise” advice to it. Work through the carrier's mistaken-delivery process. Do not hand it to someone who appears at your door claiming authority without independently checking the situation.
A text about a delivery you never received is a different starting point. Our package delivery scam guide focuses on fake messages and payment links, while this article begins with a physical item that actually arrived.
Record what you know without filling gaps. “A parcel addressed to me arrived; I found no matching order or charge” is useful. “My identity was stolen” is a stronger conclusion that needs evidence beyond the delivery.
A name and address can come from several sources, including public information or a data exposure. The package alone does not reveal which source was used. It also does not establish that someone knows your password or accessed your retailer account. Look for additional evidence before deciding which access needs recovery.
An unauthorized order in your own history deserves a different response from an unrequested item with no order. Preserve the record, report it to the retailer and contact the relevant payment provider about any charge. Check whether shipping details or account recovery information changed. Do not rely on the package sender to resolve the account issue.
If you entered credentials after scanning a code, change those exposed credentials through a trusted device and the real service. If you entered card information or paid, contact the card issuer or payment service promptly. Describe the facts, including what you submitted and whether you authorized a transfer. A Venmo scam report needs transaction-specific details, not only a parcel photo.
If you only opened the scanner and did not proceed to a site, that is not the same exposure as submitting a password or installing software. Closing a page after viewing it does not by itself prove either infection or complete safety. Follow up according to what you actually did and any verified device or account symptoms.
In the United States, FTC guidance says you do not have to pay for or return merchandise you did not order. This statement concerns unsolicited merchandise; it is not permission to keep a package addressed to somebody else. Outside the U.S., check the relevant consumer authority and carrier rules rather than importing this rule.[1]
Postal inspectors advise contacting the appropriate authorities about unexpected seeds, plants, food, unknown liquids or substances. Do not plant, eat, test or distribute unknown contents. If the parcel appears suspicious or hazardous, follow official suspicious-mail advice rather than continuing an ordinary return process.[2]
A return address does not make every handling option safe or necessary. Ask the carrier about its procedure if you need to resolve a mistaken delivery. Do not pay an unfamiliar sender to arrange a return, provide identity documents to “release” it or expose the package's personal details online.
This is general consumer information, not legal advice. The U.S. rule described above is jurisdiction-specific; ownership, handling and reporting duties depend on local law and the actual delivery circumstances.
Keep private records of the delivery and platform correspondence. Ask for a case reference when you report it and monitor for additional unexpected orders or charges. The FTC also recommends checking credit reports for identity-theft signs; use the official route available in your jurisdiction, not a link provided in the package.[1]
If someone contacts you through a messaging account to explain the parcel, verify them independently before sharing information. WhatsApp scam checks cover impersonation and access-code requests. A real parcel does not authenticate a caller any more than a familiar profile photo does.
Do not install a purported scanning or cleaning app offered by the sender. If a page presents a frightening device warning, use the separate Apple security alert scam response. That page's appearance is not a diagnostic report about your device.
For later shopping, network protection while shopping online addresses a separate transport task. It cannot stop a seller from mailing unsolicited goods, remove a fake review or reverse a payment. Account controls, transaction reporting and safe parcel handling remain necessary.
No. Gifts, split orders and mistaken deliveries can also be unexpected. Check the label, known orders and payment history before deciding which situation you need to report.
A brushing seller may use delivery to support fabricated reviews or apparent sales. That can make a listing seem more credible without a genuine purchase by the recipient.[2]
No. A parcel can be sent using a name and address alone. Inspect order history, charges and account changes for evidence of unauthorized access before drawing that conclusion.
No. A package QR code scam can lead to phishing. Open the retailer or carrier independently and use the delivery information you already have to ask about the parcel.[1]
FTC guidance says you do not have to pay for merchandise you did not order. Do not apply that guidance to a parcel addressed to someone else or automatically to another jurisdiction.[1]
Avoid using unknown contents. Postal inspectors advise contacting appropriate authorities for unsolicited seeds, plants, food and unknown substances, then following their handling instructions.[2]
Contact the affected payment provider promptly, preserve what you submitted and secure any exposed login credentials separately. Report the actual exposure rather than assuming the parcel alone caused the loss.
Sources checked 5 October 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





