DEV Community

Cover image for The FBI Just Warned About a Scam Hiding in a Box You Never Ordered
Short Lived
Short Lived

Posted on

The FBI Just Warned About a Scam Hiding in a Box You Never Ordered

What the FBI is warning about

The FBI issued an official public service announcement describing a scam built on a tactic normally used for something far more harmless “brushing”. Traditionally, brushing involved online sellers mailing unsolicited products to strangers just to use their address for a fake glowing review — annoying, but not dangerous. The FBI’s warning describes a darker variation unsolicited packages arriving with no product inside at all, just a printed QR code, designed specifically to get scanned.

Once scanned, the code can direct the phone to a fraudulent site asking for personal or financial details, or silently install malicious software that steals data directly from the device. The scam works because it exploits something QR codes are specifically designed to hide unlike a suspicious web link, which a careful person might scan for red flags, a QR code shows nothing about where it leads until after you’ve already scanned it.

Why QR codes are an unusually good disguise for this

Most scam-awareness advice trains people to look for something specific — a misspelled link, an unfamiliar sender, an urgent tone. A QR code sidesteps all of that. It’s visually identical whether it leads somewhere legitimate or somewhere malicious, and the format itself has become so normal — restaurant menus, parking payments, event check-ins — that most people scan them reflexively, without the pause they’d apply to a random link in a text.

The practical takeaway

Don’t scan QR codes from unsolicited mail or unknown sources, and be cautious of any QR code that looks physically added on top of something else (a common tactic on parking meters and payment signs, where a scammer’s sticker sits over the real code). If you’ve already scanned one and entered information, change the password on that account immediately and monitor your bank and credit statements for unauthorized activity. If you receive one of these packages, the FBI requests reporting it through the Internet Crime Complaint Center (IC3.gov).

The FBI notes this specific scam isn’t yet widespread compared to other fraud types — but the broader lesson (verify the source before scanning, not after) applies just as well to the more common QR code scams already circulating on parking signs and fake payment stickers.


Reference

Federal Bureau of Investigation, “Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes.” https://www.fbi.gov/investigate/cyber/alerts/2025/unsolicited-packages-containing-qr-codes-used-to-initiate-fraud-schemes


Support Me on Ko-fi

Top comments (0)