FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #54
FTC WARNS

Unexpected packages you never ordered can be part of a "brushing" scam, and any QR code tucked inside can lead to a phishing site.

MODERATE CONFIDENCEPublished 2026-08-25
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

The FTC warns that an unexpected package you did not order may be a brushing scam, in which a scammer uses your name to post a fake review of that product. The FTC says the package may appear to come from a known company such as Amazon, or from a person or business you have never heard of, and that recent reports to the agency describe cheap, random contents like baby wipes, toothpaste or seeds. According to the FTC, the sender sometimes leaves a note with a QR code claiming it will reveal who sent the package or process a return, and scanning it can lead to a phishing website built to capture credit card numbers, usernames or passwords. The FTC also frames the delivery as a possible sign that someone already has, or is trying to steal, your personal information. If a package arrives that you did not order, do not scan any QR code inside it — change the passwords on your online shopping accounts instead. The FTC states the law does not require you to return or pay for things you did not order, while advising caution about using the product because you do not know who sent it. Our harvested material does not say how many people have received these packages, how much money has been lost, or which sellers or platforms are involved. The source does not describe any particular age group, region or type of household as being targeted, so we do not narrow it to one. LIVEFRAUD ALERTS is an independent consumer fraud awareness publication and is not affiliated with the FTC, Amazon, or any company named here as an impersonation target. This alert was built only from the single official advisory listed below.
THE RULE
Scanning the QR code inside an unordered package can hand over card numbers and shopping account logins.

What we don’t know

The bench — who voted

3 INDEPENDENT AI MODELS REVIEWED THIS. ALL 3: MODERATE RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · MODERATE
The single evidence row covers only three elements: unordered packages, fake reviews posted in your name, and a QR code inside that leads to a phishing site. The finding adds a substantial layer of specifics the row does not contain — that packages may appear to come from Amazon or an unknown person/business, that recent reports describe baby wipes, toothpaste or seeds, that the note claims to reveal the sender or process a return, and that the phishing site targets credit card numbers, usernames or passwords. These may all be accurate to the underlying advisory, but the harvested row as presented does not carry them.
DISSENT, PRESERVEDThe headline CLAIM — unordered packages can be brushing, and an enclosed QR code can lead to phishing — is squarely carried by the one row and should not be softened. My objection is to the ornamentation around it, not the core.
DISSENT, PRESERVEDBuilding a public alert on a single sourced row and then populating it with unattributed detail is the failure mode worth naming here. The disclosure paragraph is honest, but honesty about sourcing does not license extrapolation beyond the source.
DISSENT, PRESERVEDOn danger: I grade moderate rather than high because the direct loss vector requires the reader to scan and then actively enter credentials or card data. Credential and card capture is a real harm, but the pattern is interruptible at two points and the defensive action (do not scan) is simple and costless. I would defend moderate against a push to high.
GROQopenai/gpt-oss-120b · MODERATE
The finding adds details (e.g., specific random contents like baby wipes, toothpaste or seeds, and the package appearing to come from known companies such as Amazon) that are not present in the cited FTC source, which only describes unordered packages and possible QR‑code phishing.
OPENROUTERopenrouter/free · MODERATE
Finding includes details not present in source: specific contents (baby wipes, toothpaste, seeds), a note with QR code claim, advice to change passwords, legal note about returning items, and recommendation about caution using the product. These go beyond the evidence row, which only states that unordered packages arrive for fake reviews and that a QR code may lead to a phishing site.

Reviewed by 3 independent models; all judged the finding to go beyond the evidence.

▼ Protocol & challenge record
Objection (high): Date currency / provenance anomaly. The single supporting row is dated 2026-08-20 and sits at a URL path /consumer-alerts/2026/08/. The entire alert rests on that one row, so if the publication date is wrong, fabricated by the harvester, or the page has since been revised, every sentence in the finding fails at once. Nothing in the packet shows the URL was resolved live or the date cross-checked against the FTC's alert index. A future- or near-future-dated advisory used as the sole load-bearing source should be re-fetched and the date confirmed before publication.
Not resolved — preserved on the record.
Objection (high): Material omission in the advice, plus a misframing. The FTC's remediation list has five parts: change shopping-account passwords; message the marketplace so it can investigate removing the seller; check credit weekly free at AnnualCreditReport.com; monitor for identity-theft signs; report to ReportFraud.ftc.gov. The draft keeps only the password step. Since the finding itself repeats the FTC's line that the package may mean someone already has your personal information, dropping the credit-check and identity-theft-monitoring steps removes the actions that respond to the very risk the alert raises. Separately, 'do not scan any QR code inside it — change the passwords on your online shopping accounts instead' uses 'instead,' which presents a password change as a substitute for scanning. The source presents it as independent remediation, not an alternative. The em-dash construction is the draft's own invention and is not in evidence.
Resolved: Fixable in-draft without new sourcing: replace the advice sentence with one that carries the FTC's full remediation set and drops the substitution framing, e.g. 'Do not scan a QR code that arrives inside a package you did not order. Change the passwords on your online shopping accounts, tell the marketplace if the package came through one, check your credit free each week at AnnualCreditReport.com, and report it at ReportFraud.ftc.gov.' All five elements are in the harvested row, so the sentence can carry the row_id rather than sit unsourced as 'advice'.
Objection (medium): No alternative explanation offered. An unordered package has several ordinary causes the reader will encounter far more often than brushing: misdelivery to the wrong address, an unannounced gift, a retailer shipping error, a duplicate replacement shipment, or reshipping/triangulation fraud, which is a different scheme with different remedies. The FTC hedges with 'could be'; the draft hedges once ('may be') and then narrates brushing mechanics for four consecutive sentences as the operative explanation. A reader who discards a legitimate gift or a misdelivered neighbour's parcel, or who resets passwords when the real event was a courier error, has been mis-served. One clause naming the benign possibilities costs nothing.
Not resolved — preserved on the record.
Objection (medium): Option-list integrity. 'ATTENTION: SCAMMERS' as a callout option and 'Send this to any scammer you know', 'Forward this to the scammers in your life', 'Send this to any monitor you know' as directive options are not plausible candidates for a consumer alert; the last is not even coherent English. Alongside 'DIRECTIVE NOT IN EVIDENCE: keeps' in targeting_dropped, where 'keeps' is a dangling fragment, this points to a templating or injection defect upstream. Even though the selected callout and the null share_directive are correct, shipping a packet whose candidate pool contains adversarial or garbled entries is a live risk if any downstream step re-selects from that pool.
Resolved: Strip the four non-viable entries from callout_options and directive_options before the packet moves on, and repair the truncated targeting_dropped string. Selected values are already correct, so this is a hygiene fix with no effect on published text.
Objection (medium): Source-to-claim stretch in the risk line. 'Scanning the QR code inside an unordered package can hand over card numbers and shopping account logins' converts the FTC's statement of the phishing site's design intent ('designed to steal information like your credit card numbers, usernames, or passwords') into an outcome, and narrows generic 'usernames or passwords' to 'shopping account logins,' which the source never says. The credentials a phishing page harvests depend on what page it imitates; the FTC does not specify. 'Card numbers and account passwords' would track the source.
Resolved: Reword the risk line to 'The QR code inside an unordered package can lead to a page built to capture card numbers and account passwords,' which stays inside the source's wording and drops the unsupported narrowing to shopping logins.
Objection (low): Overclaim in the claim line. 'any QR code tucked inside can lead to a phishing site' generalises from the FTC's conditional 'scanning could take you to a phishing website' about a note the sender 'might' leave. The FTC never asserts that all such codes are malicious. 'A QR code tucked inside can lead to a phishing site' carries the same warning without the universal quantifier.
Resolved: Delete 'any' from the claim line: 'Unexpected packages you never ordered can be part of a brushing scam, and a QR code tucked inside can lead to a phishing site.'
Objection (low): Entity-role confusion around Amazon. The source uses Amazon twice in opposite roles: as a company the package appears to come from, and as a marketplace the reader should contact to get the seller removed. The draft carries only the first role, then the disclaimer labels Amazon as a company 'named here as an impersonation target.' Amazon is also the reporting channel in the source, and the draft omits that entirely, leaving a reader with the impression the platform is only a spoofed brand rather than a place to complain.
Not resolved — preserved on the record.
Objection (low): Confidence reasoning is mislabelled. The first reason cites 'no independent corroboration' as a limit, but every claim sentence is attributed to the FTC and is about what the FTC says. For that proposition the FTC is definitive, not merely uncorroborated; the real uncertainty is whether the underlying phenomenon is as described and at what scale, which is what the third reason and the limitation sentences already cover. As written the confidence rationale conflates 'we have one source' with 'the source may be wrong about itself.'
Not resolved — preserved on the record.
Objection (low): Dropped qualifier. The source says recent reports 'usually' involve something cheap and random; the draft says reports 'describe cheap, random contents.' Small, but it removes the FTC's own signal that contents vary, which matters to a reader whose package contained something else and who may therefore rule out brushing.
Resolved: Restore the hedge: 'reports usually describe cheap, random contents such as baby wipes, toothpaste or seeds.'
Preserved dissent
ON THE RECORDThe advice sentence as drafted is the most consequential defect in this packet, and I do not accept it. The finding tells the reader the package may mean someone already holds their personal information, then gives them one action: change shopping passwords. The FTC's own advisory, in the same harvested row, tells them to check their credit weekly at AnnualCreditReport.com, watch for identity-theft signs, notify the marketplace, and report at ReportFraud.ftc.gov. Dropping four of five steps while keeping the alarming framing leaves the reader worried and under-equipped. If the Desk ships this as written, my position on the record is that the advice line is materially incomplete relative to the source it claims to summarise.
ON THE RECORDI also dissent on the word 'instead'. It tells the reader a password change is what you do rather than scanning the code. That is the draft's construction, not the FTC's, and it invites the inference that the two are alternatives addressing the same exposure. They are not.
ON THE RECORDOn date currency I want it recorded that I flagged a source dated 2026-08-20 as requiring live re-verification before publication, and that no evidence of such verification appears in this packet. The entire alert rests on that one row. If the date or the page turns out to be wrong, nothing else in the alert survives, and the check as drafted would not have caught it.
ON THE RECORDFinally, I regard the presence of 'ATTENTION: SCAMMERS', 'Send this to any scammer you know' and 'Send this to any monitor you know' in the candidate pools as a signal that something upstream is malfunctioning or has been tampered with. The correct selections were made this time. I do not think that should be treated as evidence the pool is safe.

The sources

Official sourceThat unexpected package you got could be a brushing scam2026-08-20
The FTC describes brushing scams in which unordered packages arrive so a seller can claim delivery and post fake reviews using your name, sometimes with a QR code inside that leads to a phishing site.
Authority: official. Retrieved 2026-08-25.
Limitation: Gives no counts, loss totals, dates of incidents, or named sellers, and does not identify any affected group beyond people who received a package they did not order.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/IaA-6mE

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 5 material sentence(s) map to FTC.
  • ✗ anthropic returned "overstated"; groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-25.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.