FRAUD PREVENTION TIPS: Unexpected packages, QR codes and online offers can open the door to scams.

Consumers warned not to let curiosity or promises of easy money compromise their accounts

An unexpected envelope or package showing up at the front door may seem harmless, especially if there is nothing inside. However, consumer protection officials warn that unsolicited deliveries can be part of a “brushing” scam — and some now contain QR codes designed to steal personal information.

In a traditional brushing scam, an online seller mails an inexpensive item, an empty package or an envelope to a real person at a valid address. The seller then uses the delivery record to create the appearance of a legitimate sale and posts a false positive review in the recipient’s name.

The fraudulent reviews can increase a product’s rating and visibility, misleading other consumers into believing the merchandise has been purchased and recommended by verified customers.

The U.S. Postal Inspection Service said third-party sellers often obtain names and addresses from information available online or exposed through data breaches. Receiving an unsolicited package does not by itself mean the recipient’s bank account has been accessed, but it may indicate that some personal information is circulating among marketers or scammers.

A more dangerous variation combines brushing with “quishing,” or QR code phishing.

The package may contain a card asking the recipient to scan a QR code to identify the sender, register a gift, arrange a return or obtain additional information. The code can direct the phone to a fraudulent website designed to resemble a bank, retailer, delivery company or government agency.

The website may ask for account credentials, credit card numbers or other personal information. In some cases, a malicious link may attempt to install malware on the device.

The Federal Trade Commission advises consumers not to scan a QR code included in an unexpected package. Anyone who wants to contact the purported retailer should use the company’s official website or a verified telephone number rather than information included with the delivery.

Consumers are not required to pay for unsolicited merchandise. Under federal law, recipients may generally keep or discard merchandise they did not order. An unopened package bearing a return address may also be marked “Return to Sender.”

Recipients should report unsolicited packages to the retailer named on the label and ask the company to remove any reviews falsely posted in their name. Suspicious mail may also be reported to the U.S. Postal Inspection Service at uspis.gov or 1-877-876-2455.

Anyone who scanned an unfamiliar QR code and entered a username or password should immediately change that password anywhere it was used and enable two-factor authentication. Bank and credit card statements should be checked for unauthorized transactions.

Consumers concerned about identity theft can review their credit reports at AnnualCreditReport.com and consider placing a fraud alert or credit freeze with Equifax, Experian and TransUnion. Suspected identity theft may be reported at IdentityTheft.gov.

Social media scams produce billions in losses

Unexpected packages are only one way criminals attempt to gain trust or exploit curiosity.

The FTC reported that nearly 30% of consumers who reported losing money to fraud in 2025 said the scam began on social media. Reported social media scam losses reached $2.1 billion — approximately eight times the amount reported in 2020.

Facebook accounted for more reported losses than any other social media platform in 2025, according to the FTC. WhatsApp and Instagram ranked second and third.

Investment schemes generated the greatest losses among social media scams, totaling about $1.1 billion in 2025. Scammers often use professional-looking advertisements, fake investment platforms and fabricated testimonials to make the opportunity appear legitimate.

A victim may initially be allowed to withdraw a small amount of money, building confidence in the platform. The account then displays fictional profits, encouraging the victim to invest more. When the victim tries to withdraw the full balance, the money and the supposed adviser disappear.

Consumers should never allow someone they met through social media to direct their investments. Cryptocurrency transfers, wire transfers and gift-card payments are especially difficult to recover.

Job seekers are also frequent targets. A fake employer may offer remote work placing advertisements, reviewing products or completing simple online “tasks.” Applicants are then told to deposit their own money into a digital wallet or cryptocurrency account to unlock assignments or collect commissions.

Legitimate employers pay their workers. They do not require employees to wire money, purchase cryptocurrency or pay fees before receiving wages.

New Microsoft 365 phishing threat

The FBI has also warned Microsoft 365 users about an emerging phishing service known as Kali365.

In this scheme, a fraudulent email impersonates a trusted document-sharing or cloud service and provides a device code. The recipient is instructed to visit Microsoft’s legitimate verification page and enter the code.

Although the Microsoft page is real, the code belongs to the criminal’s device. Entering it can authorize that device to access the victim’s Microsoft 365 account. The attacker may then gain access to Outlook, Teams and OneDrive without obtaining the victim’s password or completing another multifactor authentication challenge.

Consumers should not enter a device authorization code received through an unsolicited message. Microsoft 365 users should review active sessions, devices and recent login activity and remove anything they do not recognize. Affected users should change their passwords, contact their organization’s information technology administrator and report the incident at IC3.gov.

Beware of fake virus warnings

Another common scheme begins with a pop-up claiming that a computer is infected, blocked or experiencing a serious security problem. The message may display an official-looking logo and telephone number while warning the user not to shut down the computer.

Consumers should not call the number, enter login information or give the supposed technician remote access.

The FBI advises users to close the browser or restart the computer. If the warning returns, the user should run updated security software or contact a reputable local computer professional using independently verified contact information.

Anyone who granted a stranger remote access should disconnect the device from the internet, contact financial institutions, change passwords from a different trusted device and have the computer checked for malicious software.

Scammers depend on urgency, fear, curiosity and promises of easy money. Taking a few minutes to independently verify an unexpected package, message, job offer or security warning can prevent a moment of uncertainty from becoming a costly loss.

This information was taken from the Rossen Reports YouTube channel. An excellent source for fraud prevention with over 600,000 followers.

Editorial Dept.

These stories are curated and posted by Valley News editorial staff members.