Article Read Time

On August 20, the Federal Trade Commission put out a short consumer alert about a package. Not a data breach, not a ransomware crew, not a foreign intelligence service. A package. Baby wipes, maybe, or toothpaste, or a small envelope of flower seeds. It shows up at your door with your name and address on the label, and you did not order it.
That alert is worth your attention, because the package is not the point. What comes with it is.
Many of these deliveries now include a small card with no sender listed. The card says something friendly. Scan this code to find out who sent your gift. Scan this code to arrange a return. The QR code, the square black-and-white pattern your phone camera can read, takes you somewhere you did not intend to go. The FTC states that a fake website often collects your card number, username, and password. The FBI’s Internet Crime Complaint Center warned about the same thing in a public service announcement last summer, and added a second risk: some of those codes push you to install an app, and the app quietly takes data off your phone.
Where this came from
People in the trade refer to the original version of this scheme by a name. It is called brushing, and it is review fraud, not theft.
Here is how the plain version works. A seller seeks better ratings on a large online marketplace. Reviews from confirmed buyers carry more weight than reviews from strangers. So the seller finds your name and address, which are cheap and widely available after years of data breaches, ships you something small and worthless, and then writes a glowing review under your name. As a result, the marketplace sees a real shipment to a real address and treats the review as verified. As a result, you get toothpaste you did not ask for. The seller gets a five-star rating that moves their product up the page.
Annoying, but not dangerous to you directly.
However, what the FBI and the FTC are describing now is the same delivery with a hook attached. The criminal is no longer selling anything. The package is bait, and the QR code is the trap. The absence of a sender is deliberate. Curiosity is the whole mechanism. You want to know who sent it, so you scan.
Why the QR code works
I have spent thirty years watching attackers pick the shortest path into a system, and this one is short.
A link in an email can be inspected. You can hover over it and see where it goes, and most people have been trained for a decade to do exactly that. A QR code, however, cannot be inspected. It is a picture. You have no way to read it with your eyes, so you point your camera at it and trust whatever comes up.
Add to that the setting. This did not arrive in your inbox with a spam filter in front of it. It arrived in a cardboard box carried to your porch by a delivery driver. Physical mail still carries a presumption of legitimacy that email lost years ago. That presumption is doing the criminal’s work for him.
What to do with the box
The advice here is short, and none of it requires hiring anyone.
Keep the item. Federal law says merchandise you did not order and did not agree to buy is yours. You do not have to return it, and you do not have to pay for it.
Do not scan the code. Not to identify the sender, not to arrange a return, not out of curiosity. There is nothing on the other side of it that you need.
Change the password on your shopping accounts. Your name and address are already in someone’s file. If you use the same password across sites, fix that first.
Watch your credit. You can pull your reports for free at AnnualCreditReport.com, and the FTC now recommends checking weekly. If you think you have been targeted, the three bureaus are Equifax, Experian, and TransUnion.
Report it. The marketplace it came from wants to know, because fake reviews damage them too. The FTC takes reports at ReportFraud.ftc.gov, and the FBI takes them at ic3.gov. If the person affected is over 60, the Justice Department runs an Elder Justice Hotline at 1-833-372-8311.
The part that applies at work
I would not write a whole column about toothpaste on a porch if that were the end of it. In fact, we recently got a free box of Kleenex this way.
The same trick is showing up in offices. A padded envelope arrives at city hall or at a small manufacturer’s front desk, addressed to a person by name, with a card inside and a code to scan. Sometimes it claims to be a vendor gift. Sometimes it claims to be a delivery problem that needs resolving. The person who scans it is standing in your building, often on a phone that also holds their work email.
Tell your staff the rule out loud, because most of them have never been told it. Unexpected package, unknown sender, do not scan. Bring it to whoever handles technology and let them look at it.
If your organization has never had that conversation, it is a fifteen-minute one, and we are glad to help you have it. Our number is 502-234-5554.
A criminal who mails you a gift is not being generous. He is buying your curiosity for the price of postage, and he expects to make it back.
