Brushing Scam
A brushing scam is the delivery of unordered packages so a seller can post fake verified reviews — increasingly paired with QR codes that lead to phishing sites.
A brushing scam is a fraud in which an online seller ships unordered, low-value packages to real names and addresses, then uses those "verified" deliveries to post fake positive reviews under the recipients' identities. The name comes from the Chinese e-commerce slang term for inflating sales figures. For years brushing was treated as a nuisance crime — the victim's main loss was knowing their name and address were circulating in a data broker's file — but it has evolved into a genuine security threat.
How it works
The seller buys leaked or scraped personal data — names, addresses, sometimes phone numbers — and creates buyer accounts that "purchase" its own products, shipping cheap items such as seeds, jewelry, or gadgets to the addresses on file. The platform now records a genuine, tracked delivery, which unlocks the ability to post a review that carries a "verified purchase" label. The recipient never asked for the package and usually cannot trace who sent it.
The dangerous variant adds a QR code. In July 2025 the FBI's Internet Crime Complaint Center warned about unsolicited packages containing QR codes that recipients are nudged to scan — to "find out who sent the gift" or claim a reward. The code leads to a phishing page that harvests credentials or payment details, or prompts a malicious app download: a physical-mail delivery channel for quishing. Because the package arrived at the victim's real address with their real name, the lure carries far more implied legitimacy than a random text message or smishing attempt.
How to defend against it
For individuals: never scan a QR code from an unsolicited package, check your shopping accounts for unrecognized orders or reviews posted in your name, and report unordered merchandise to the platform and, in the US, to the FBI's IC3. A brushing package is also a signal that your personal data is in circulation, so rotate weak passwords and watch for follow-on phishing. For organizations, brushing belongs in security awareness programs because employees increasingly receive such packages at office addresses harvested from B2B data leaks — the same "unexpected physical object with a scannable code" reflex that applies to QR lures in email, covered in our guide to QR code phishing, applies at the mailroom too.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo