Brushing Scam: How it Fuel Fake Reviews and Fraud

A brushing scam sends unsolicited packages to post fake reviews in a victim's name. How brushing scams work: the QR code variant and the right response.
Published on
Wednesday, October 7, 2026
Updated on
October 7, 2026

A package arrives that no one ordered. There is no note, no sender name, and often no return address, just a cheap item like seeds, costume jewelry, or a phone accessory. It looks like a harmless mix-up, yet an unordered package is frequently the calling card of a brushing scam.

A brushing scam is a fake-review fraud in which a seller ships unrequested goods to a real name and address, then posts a glowing verified-purchase review in that person's name. In 2025, the practice turned more dangerous, as the FBI warned that scammers had begun slipping QR codes into the packages to steal personal and financial data.

What is a Brushing Scam?

A brushing scam is a form of e-commerce fraud built to manufacture fake product reviews. A dishonest seller sends an unordered item to a real person, the platform records it as a genuine sale, and the seller then writes a positive review under that person's name, so it appears as a trusted verified purchase.

Ranking is the goal, not generosity. Verified-purchase reviews carry weight with shoppers and marketplace algorithms, so a flood of them pushes a product higher in search results and lends it false credibility. The items shipped are deliberately cheap, since the seller only needs a delivery to register, not a valuable gift.

How Does a Brushing Scam Work?

A brushing scam mainly runs in three stages.

how a brushing scam works

1. Harvesting Names and Addresses

The seller first needs real delivery details. Names and addresses come from data breaches, leaked or purchased contact lists, and public sources, which the US Postal Inspection Service notes are often gathered through illicit means for later misuse.

2. Shipping the Unordered Package

Using those details, the seller places an order to the victim's address, often paying for the cheap item out of pocket. The package ships and the marketplace marks it delivered, creating a record of a completed, verifiable sale.

3. Posting the Fake Review

With a delivery on file, the seller writes a five-star review in the recipient's name, flagged as a verified purchase. Repeated across many stolen identities, these reviews inflate a product's rating and bury genuine feedback.

Mystery Seeds: Brushing at a National Scale

Brushing scams drew national attention in the summer of 2020, when thousands of Americans across all 50 states received unsolicited packets of seeds postmarked from China. Many arrived in envelopes mislabeled as jewelry or toys, holding nothing but random seeds.

After investigating alongside Customs and Border Protection, the US Department of Agriculture concluded the shipments were most likely a brushing scam, cheap and lightweight items sent to generate fake reviews. Officials still urged recipients not to plant the seeds, citing the risk of invasive species, and the episode showed how ordinary a brushing package looks while quietly signaling that an address is exposed.

QR Code Brushing Scams

qr code brushing scam

Brushing scams took a sharper turn when criminals added QR codes to the packages. Because the box carries no sender information, a curious recipient scans the code hoping to learn who sent the item or how to return it.

That scan is the trap. The code leads to a phishing page that harvests logins and card details, or triggers a malware download that steals data from the phone. The FBI has linked these codes to theft of banking credentials and even cryptocurrency access, turning a nuisance package into a direct financial attack.

Why a Brushing Scam is Not Harmless

A free package sounds like a win, though a brushing scam carries real costs:

  • Exposed personal data. A brushing package signals that a name, address, and possibly more already circulate on criminal marketplaces.
  • Hijacked identity. Someone is using a real person's identity to post fraudulent reviews, which platforms tie back to that account.
  • Misled shoppers. Fake five-star reviews push low-quality or counterfeit products onto buyers who trust the ratings.
  • Escalation to theft. The QR-code variant converts the scam into outright theft of credentials and money.

Signs of a Brushing Scam

A brushing package tends to share a recognizable set of traits:

  • Deliveries of items no one in the household ordered.
  • Packages with no return address, or one listing only a retailer.
  • Shipments addressed to a resident by full name.
  • Goods that are cheap and random, such as seeds, jewelry, or small gadgets.
  • Parcels arriving repeatedly over days or weeks.

What to Do After Receiving an Unsolicited Package

Handling a brushing package safely takes a few deliberate steps:

brushing scam response checklist
  1. Avoid scanning any QR code on or inside the package, which often leads to phishing or malware.
  2. Keep, donate, or discard the item, which is legally the recipient's to keep, with no obligation to pay or return it.
  3. Notify the marketplace, such as Amazon, eBay, or Temu, so it investigates the seller and removes fake reviews.
  4. Change passwords on shopping and financial accounts, and turn on two-factor authentication.
  5. Monitor bank and card statements, and request a free credit report to spot fraudulent activity.
  6. Report the scam to the FTC, and to the FBI's IC3 and the Postal Inspection Service where relevant.

How to Prevent Brushing Scams

Limiting exposure lowers the odds of being used in a brushing scheme:

  • Guard personal data. Share names, addresses, and contact details sparingly, and review privacy settings on shopping accounts.
  • Check for breaches. Track whether personal information has surfaced in known data breaches, and update any exposed passwords.
  • Use strong, unique passwords. Protect marketplace and email accounts with a password manager and two-factor authentication.
  • Stay cautious with reviews. Avoid posting personal details in public reviews that scammers harvest.

Frequently Asked Questions

Does a brushing scam cost the recipient money?

No, the recipient is not charged for the items, since the seller pays to create the fake order. The real cost is exposed personal data and the risk of QR-code fraud.

Can a brushing scam lead to identity theft?

Yes, indirectly, because a brushing package signals that personal data is already exposed, and the QR-code variant enables direct financial fraud. Monitoring accounts and credit closely is wise.

Are brushing scams illegal?

Yes, brushing scams break consumer-protection law, and the FTC's 2024 rule specifically bans fake reviews with civil penalties. Misusing personal data adds further legal exposure.

Can brushing packages contain dangerous items?

Most brushing items are cheap and harmless, but unsolicited electronics and QR codes warrant caution, as either is a potential malware or fraud vector. Recipients are advised not to power on unknown devices or scan codes.

Why do brushing scams spike during the holidays?

Holiday shipping volumes surge, so fraudulent packages blend in and draw less suspicion. Higher marketplace activity gives sellers extra cover to plant fake reviews.

What happens to the fake reviews from a brushing scam?

Marketplaces remove fake reviews once detected and often penalize or ban the seller. The wrongly named reviewer's account is usually cleared, though the exposed personal data remains a concern.

Related Posts
Malware vs. Virus vs. Worm: How They Spread & Key Differences
Malware is malicious software; viruses replicate inside a host file, and worms spread as standalone programs. Their replication methods determine how infections continue.
12 SaaS Security Threats and How to Mitigate Them
SaaS security threats include stolen credentials, session hijacking, and data loss. Mitigation requires secure sign-ins, limited permissions, and controlled integrations.
Capital One Data Breach (2019): Attack Path, Root Causes, and Cloud Security Lessons
The Capital One breach shows how a misconfigured WAF, AWS credentials, IAM permissions, and S3 access formed an attack path, plus where cloud defenses can stop it today.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.