Brushing Scam Explained: Why Mystery Packages Put Your Identity at Risk

A parcel with your name on it arrives even though you ordered nothing. The item may be cheap, strange, or almost useless, which makes the delivery feel more confusing than dangerous.

A brushing scam can begin exactly this quietly. The package is real, but the transaction behind it may have been created to manufacture trust online and use your identity as part of someone else’s sales strategy.

Fake online order history showing an unsolicited item marked as delivered for $0.00

Overview

What a brushing scam is

Brushing is a scheme in which a seller sends merchandise that the named recipient never ordered. The seller then treats that shipment as evidence of a completed sale and may publish a glowing review under the recipient’s name or a related fake account.

The item is usually inexpensive because its value is not the point. The shipment creates tracking data and a delivered status, which can make a false review appear connected to a genuine purchase.

Why sellers send mystery packages

Online marketplaces often reward products with strong ratings, recent sales, and verified-purchase reviews. A dishonest seller may use brushing to manipulate those signals, lift an item in search results, and persuade real shoppers that the product is popular.

Your address becomes a tool in that manipulation. The seller spends a small amount on postage and a low-cost object, hoping the manufactured activity produces far more revenue from buyers who trust the inflated record.

What the delivery may reveal about your data

The parcel does not automatically mean that your bank account was charged or your shopping account was hacked. However, someone obtained enough information to direct merchandise to you, commonly a name and current mailing address.

That data may have come from public records, a marketing list, a breached database, or a compromised marketplace account. A QR code or follow-up message can turn the scheme into direct phishing by asking you to identify the sender or claim a reward.

  • A package arrives under your name although nobody in the household ordered it.
  • The parcel has no useful invoice, recognizable seller, or clear return information.
  • A matching order appears in an account you do not recognize.
  • A review is posted under your identity without your permission.
  • The shipment includes a QR code that promises details about the sender.
  • Someone later asks you to pay, review the item, or confirm account information.

How the Brushing Scam Works

Step 1: A seller collects usable recipient data

The scheme begins with a list of names and addresses. Some information can be assembled from public sources, customer lists, online profiles, previous transactions, or data exposed in a breach.

A complete identity profile is not always necessary. For a basic shipment, the seller may need only a recipient name, street address, city, and postal code.

If phone numbers or email addresses are also available, the campaign can become more invasive. Those details allow follow-up texts, delivery notices, QR-code lures, and fake support messages.

Step 2: A fabricated order is created

The seller or an associate places an order through an account they control. Payment may be made with the seller’s own funds, promotional credit, compromised payment information, or another method designed to create normal marketplace records.

The recipient did not agree to the purchase and may never see the order in a personal account. The important record for the scheme is the platform’s confirmation that an item was purchased and shipped.

In some cases, account compromise is involved. If an unknown order appears in your real shopping history, treat that as a stronger warning and secure the account immediately.

Step 3: A cheap item is shipped to your address

The sender chooses a low-cost, lightweight product to minimize expenses. Reports commonly involve small accessories, household trinkets, seeds, or other items that can be mailed cheaply.

Real tracking is valuable to the dishonest seller. A carrier scan and delivered status help make the artificial transaction look complete to a marketplace system.

The United States Postal Inspection Service explains that unsolicited merchandise can be part of a larger brushing scam. It advises recipients not to pay for merchandise they did not order.

Step 4: A fake verified review is published

After delivery, the seller posts a positive rating or written review. The platform may label it as a verified purchase because a transaction and shipment exist, even though the person named on the parcel did not write anything.

The review may praise quality, delivery speed, or customer service. A group of such reviews can create the appearance of demand and bury genuine warnings from actual buyers.

This is the central purpose of traditional brushing. The recipient is not selected for the contents of the parcel; the address is used to support a deceptive reputation signal.

Fake seller dashboard showing a fabricated five-star verified-purchase review

Step 5: The seller benefits from manipulated rankings

More orders and positive reviews can improve a listing’s visibility. Real customers may see the high rating, assume many others had a good experience, and buy a product they would otherwise avoid.

The damage therefore reaches beyond the person who received the parcel. Honest competitors are disadvantaged, marketplace search quality is distorted, and shoppers make decisions using fabricated evidence.

A delivered package can also prove to the sender that the address is active. That confirmation may make the record more valuable for future spam, fraud, or resale.

Step 6: A QR code or message adds a second trap

Some unsolicited packages contain a card asking you to scan a QR code to discover who sent the gift, register a warranty, or claim another item. The code can lead to a phishing page rather than useful shipment information.

The page may request shopping credentials, card details, a survey payment, or personal information. A harmless-looking mystery package then becomes the physical opening for an online account theft.

Do not scan an unexplained code to satisfy curiosity. If you want to investigate the tracking number, use the carrier’s official website by typing its address yourself.

Company, Address, and Fulfillment Checks

Look for the order in accounts you control

Review order histories on marketplaces and retailers you use. Search by the item, delivery date, tracking number, and recipient name. Also check archived orders and family accounts that may share the address.

If no matching order exists, the shipment may have been created through someone else’s account. If it appears in your account, change the password, end unfamiliar sessions, and review saved payment methods.

Inspect the label without contacting unknown senders

Record the tracking number, return address, carrier, and seller name before discarding packaging. Do not call a number, email an address, or visit a website printed on an unfamiliar insert.

A return address may belong to a fulfillment warehouse rather than the seller. That mismatch is not proof by itself, but it means the address cannot establish who created the order.

Verify the retailer through its official support channel

Go directly to the marketplace or retailer and report unsolicited merchandise. Provide the tracking number and ask whether a review or account was associated with your identity.

The Postal Inspection Service brushing guidance recommends notifying the retailer and asking it to remove fake reviews posted under your name.

Separate delivery proof from purchase proof

A carrier’s delivered status proves that a parcel reached an address. It does not prove that the recipient placed an order, authorized payment, or wrote a review.

Do not let a seller pressure you into paying because tracking shows delivery. Unordered merchandise should not become a debt merely because someone chose to mail it.

What an Unexpected Package Does and Does Not Mean

A brushing delivery is a warning about data exposure, but it is not automatic evidence of full identity theft. Check facts before assuming every account is compromised.

  • It does mean someone had a name and address that could receive a shipment.
  • It may mean a marketplace record or fake customer profile was created around that address.
  • It may mean a seller intends to publish a false verified-purchase review.
  • It does not prove that your card was charged or your bank login was stolen.
  • It does not require you to pay a bill sent after the merchandise arrives.
  • It should prompt a review of shopping accounts, statements, passwords, and credit reports.

Be more cautious if the shipment contains unknown food, seeds, plants, powders, liquids, batteries, or hazardous-looking material. Avoid using or opening suspicious contents and follow carrier or local authority instructions.

Search the product listing and recent reviews if the seller can be identified. A cluster of generic five-star comments posted close together, repeated phrases, or reviews unrelated to the item can support a report, although none of those clues proves brushing alone.

Check whether your name, initials, or profile appears beside a review you never wrote. Capture the page before reporting it because the seller or platform may remove the content after an investigation begins.

Keep a simple log if more parcels arrive. Repeated dates, sellers, tracking origins, and marketplace names can reveal a pattern that one isolated delivery would not show.

What to Do if You Have Fallen Victim to This Scam

  1. Document the delivery. Photograph the label and record the tracking number, sender, date, contents, and any insert. Avoid scanning QR codes or using contact details enclosed with the item.
  2. Check household orders first. Ask family members and review legitimate shopping accounts. This prevents a surprise gift or forgotten purchase from being reported as fraud.
  3. Report the package to the retailer. Use support reached through the official app or website. Ask the platform to investigate the transaction and remove any review falsely associated with you.
  4. Review account security. Change the shopping password if an unknown order appears in your history. Sign out other sessions, remove unfamiliar addresses, and enable multifactor authentication.
  5. Examine payment statements. Look for small test charges and unfamiliar merchant names. Contact the card issuer or bank promptly if any transaction was not authorized.
  6. Check your credit reports. Watch for accounts or inquiries you do not recognize. If broader identity misuse appears, follow a recovery plan at IdentityTheft.gov.
  7. Handle the merchandise safely. The Postal Inspection Service says recipients generally may keep or dispose of unordered items. Treat unknown organic or hazardous contents more cautiously and seek official guidance.
  8. Scan after digital interaction. If you opened a linked file, installed an app, or visited a suspicious QR destination, update the device and run a full Malwarebytes scan.
  9. Block malicious follow-up pages. AdGuard can reduce access to known phishing and tracking domains. It does not replace card cancellation, password changes, or account review after information was submitted.
  10. File fraud reports. Report mail-related fraud to the Postal Inspection Service and deceptive activity to ReportFraud.ftc.gov. Include the tracking and seller details you preserved.

Frequently Asked Questions

Do I have to pay for a package I never ordered?

Do not pay an invoice simply because merchandise reached your address. The Postal Inspection Service says you should not be swindled into paying for unsolicited merchandise.

If a collection demand follows, do not use the sender’s number. Contact the named retailer independently and keep records of the report.

Can I keep an item sent in a brushing scam?

Federal guidance says recipients may generally keep unordered merchandise. An unopened parcel with a valid return address may also be marked for return through the carrier.

Do not keep or use suspicious food, plants, chemicals, or unknown substances. Ask the appropriate authority how to handle those contents safely.

Was my shopping account definitely hacked?

Not necessarily. A brushing seller may create a separate order using address data obtained elsewhere. The package alone does not show how the information was collected.

An unknown transaction inside your real account is stronger evidence of unauthorized access. Secure that account and inspect linked payments immediately.

Why would someone spend money to send me something?

The item and postage can be treated as marketing costs. A delivered transaction may support a fake verified review, improve search placement, and persuade many genuine customers to buy.

The seller expects increased sales to outweigh the small cost of sending cheap merchandise to addresses on a list.

Should I scan the QR code to identify the sender?

No. A code inside an unexplained package can lead to a phishing form, subscription trap, or malicious download. Curiosity is the hook in that extension of the scheme.

Use tracking information only through the carrier’s official site and report the parcel through a retailer channel you reached independently.

How can I stop more brushing packages?

There is no single switch that guarantees the mail will stop. Reporting the seller, removing fake reviews, securing accounts, and reducing public address exposure can make your information less useful.

Continue monitoring statements and credit reports. Repeated packages, unknown orders, or new identity misuse deserve a fresh report with all related tracking numbers.

The Bottom Line

A brushing scam uses a real shipment to manufacture a fake sale and a misleading review. The mystery item is usually cheap because your address and the delivered tracking record are what the sender values.

Do not pay, scan unexplained codes, or contact unknown details inside the parcel. Verify orders through your own accounts, notify the retailer, and watch for signs that more than an address was exposed.

If the brushing scam expands into unauthorized purchases or identity misuse, act on those concrete signs quickly. Preserve the shipment details, secure affected accounts, and report the activity through official channels.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Funssey.com EXPOSED – Legit Store or Fake? Buyer Warning

Next

716-992-9211 Police Scam Call: How Spoofed Warrant Threats Steal Your Money