Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A parcel you never ordered has arrived. Its QR code will not solve the mystery

An unexpected parcel may be a mistake or an attempt to support a fake review. Do not scan the enclosed QR code to identify its sender.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
8 September 2026
READING TIME
7 min read
TOPIC
Human Security
A parcel you never ordered has arrived. Its QR code will not solve the mystery

A courier leaves a small parcel bearing your name and correct address. You ordered nothing, and the box contains a cheap, random item. A note promises an explanation if you scan its QR code: reveal the sender, confirm a gift or start a return.

The sender is relying on curiosity to do the work. That code may lead to a page asking for a shopping login, card details or a return fee. You do not need to scan it to respond sensibly.

Check your own accounts first

Open your shopping apps and marketplaces normally, without using anything printed in the parcel. Review orders, saved addresses, recent sign-ins and payments. Ask other people in the household too; a gift or purchase from a family account is the most ordinary explanation.

If the parcel appears to come from a particular platform, contact support through its app or an address you type yourself. Provide the tracking number and seller shown on the label. Do not use a phone number, email address or form printed on the suspicious note.

Change the shopping-account password if you find an unfamiliar order, address change or sign-in. Check whether anybody added a payment method or telephone number. If a card was actually charged, contact the bank through its official number.

Why would anyone send a cheap object?

One possible explanation is known as brushing. A dishonest seller sends a low-value product to create a delivery record, then publishes a review that appears to come from a genuine customer. The recipient is not the real customer in this story; their details are being used to make a listing look more credible.

The parcel does not automatically prove that somebody took over your account. An address could come from an earlier data breach, public record, old marketing list or seller error. Look for concrete evidence first: unknown transactions, orders and account changes.

Your phone will usually show the destination before opening it, but a shortened or lookalike address can still mislead. Do not install an app, enter a password or pay for a “mandatory return”. A genuine platform can investigate a tracking number without moving you to an anonymous page.

If you scanned the code but entered nothing and installed nothing, close the page and do not return. If you supplied a password, change it on the genuine service, end other sessions and enable an additional sign-in check. Contact the bank after entering card details; ask IT or a trusted repair service for help if you installed an unfamiliar app.

Do not pass the item on as a gift

Unknown origin means you cannot judge whether the product is safe. That matters especially for cosmetics, food, toys, electronics and anything used on the skin. Keep the packaging and label until the marketplace responds, then follow its instructions.

At work, do not open a parcel addressed to somebody else or scan its code on a shared device. Pass it to reception or the person responsible for incoming mail and record when it arrived.

What the source says and what Breachroad recommends

The US Federal Trade Commission’s August 2026 alert describes unexpected packages and brushing scams. It warns that an enclosed QR code may lead to a site seeking passwords or card details, and advises checking shopping accounts and reporting the seller to the platform.

Breachroad recommends never trying to solve the mystery with a tool supplied by the unknown sender. Reach the marketplace independently, check the facts and report the parcel where the order history can be inspected.

You can also read how phishing hides inside QR codes. We help organisations rehearse similar moments in our cybersecurity training.

SHARE / COPY