← All terms

Brushing Scam

A brushing scam is the delivery of unordered packages so a seller can post fake verified reviews — increasingly paired with QR codes that lead to phishing sites.

A brushing scam is a fraud in which an online seller ships unordered, low-value packages to real names and addresses, then uses those "verified" deliveries to post fake positive reviews under the recipients' identities. The name comes from the Chinese e-commerce slang term for inflating sales figures. For years brushing was treated as a nuisance crime — the victim's main loss was knowing their name and address were circulating in a data broker's file — but it has evolved into a genuine security threat.

How it works

The seller buys leaked or scraped personal data — names, addresses, sometimes phone numbers — and creates buyer accounts that "purchase" its own products, shipping cheap items such as seeds, jewelry, or gadgets to the addresses on file. The platform now records a genuine, tracked delivery, which unlocks the ability to post a review that carries a "verified purchase" label. The recipient never asked for the package and usually cannot trace who sent it.

The dangerous variant adds a QR code. In July 2025 the FBI's Internet Crime Complaint Center warned about unsolicited packages containing QR codes that recipients are nudged to scan — to "find out who sent the gift" or claim a reward. The code leads to a phishing page that harvests credentials or payment details, or prompts a malicious app download: a physical-mail delivery channel for quishing. Because the package arrived at the victim's real address with their real name, the lure carries far more implied legitimacy than a random text message or smishing attempt.

How to defend against it

For individuals: never scan a QR code from an unsolicited package, check your shopping accounts for unrecognized orders or reviews posted in your name, and report unordered merchandise to the platform and, in the US, to the FBI's IC3. A brushing package is also a signal that your personal data is in circulation, so rotate weak passwords and watch for follow-on phishing. For organizations, brushing belongs in security awareness programs because employees increasingly receive such packages at office addresses harvested from B2B data leaks — the same "unexpected physical object with a scannable code" reflex that applies to QR lures in email, covered in our guide to QR code phishing, applies at the mailroom too.

Related terms

QuishingQuishing (QR code phishing) is a social engineering attack that uses malicious QR codes to direct victims to credential-harvesting sites or malware downloads.SmishingSmishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo