It’s a Tuesday, and there’s a box on the counter in the church office.
Nobody remembers ordering it. It’s addressed to the church, correctly, with the right street number and the right suite. Inside is a phone case in a color nobody would choose, or a set of silicone kitchen rings, or a keychain flashlight — something cheap, sealed in plastic, with no packing slip and no invoice.
There is one other thing in the box: a small printed card.
Thank you for your order! Scan the QR code below to see who sent this gift and claim your free item.
The volunteer who opens the mail on Tuesdays holds up her phone, taps the camera, and the code resolves into a link.
That is the whole attack. It took nine seconds, and nothing about it felt like an attack.
What a brushing scam actually is
Start with the original version, because it explains why the box exists at all.
A brushing scam is a fake-review scheme. A seller on a large marketplace wants better ratings, so they ship a cheap item to a real name at a real address — pulled from a data set they bought or scraped — and record it as a completed sale. Then they write a glowing review in that person’s name. Because a package genuinely shipped and genuinely arrived, the platform marks it a “verified purchase,” which is exactly the label shoppers trust most.
The US Postal Inspection Service describes the goal plainly: the packages are sent so as “to give the impression that the recipient is a verified buyer who has written positive online reviews.”
For years that was the end of it. Annoying, faintly creepy, mostly harmless to the recipient. You kept the phone case.
The new part: the card with the QR code
The scheme has been repurposed, and the second version is not harmless.
A QR code — short for Quick Response code — is that square pattern of black and white blocks. Your phone’s camera reads it and turns it into a web address, then usually offers to open it. It is a link with the letters hidden.
In the current variant, the package contains a card with a QR code and a reason to scan it. Scan to see who sent this. Scan to register your gift. Scan for a free item. Scan to leave a review. The code leads to a page that either asks for information — name, address, card number, or a username and password for an account you already have — or prompts you to install an app that gives an attacker access to the phone.
That is phishing: a message built to look like it comes from someone you’d trust, designed to get you to hand over information or install something. When the bait is a QR code rather than a link in an email, the security world calls it quishing. The Postal Inspection Service now names this pattern directly, warning that “cards with QR codes are being sent inside packages as a part of brushing scams.”
The FBI issued a public service announcement about it on 31 July 2025 — PSA I-073125-PSA, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes. The Bureau’s description: criminals “send unsolicited packages containing a QR code that prompts the recipient to provide personal and financial information or unwittingly download malicious software.” The Federal Trade Commission flagged the same thing in a consumer alert in January 2025, noting that scanning “could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords,” or “download malware onto your phone.”
Three government bodies describing the same box. That’s about as verified as a threat gets.
And a QR code is worse than a link in an email, for two reasons, neither of them technical.
It hides where it goes. In an email you can hover over a link and see the address it leads to. You can notice that “your bank” is actually a string of nonsense followed by .ru. A QR code shows you nothing. It’s a picture. By the time the address appears, it’s in a small gray bar at the top of a browser window that has already loaded the page.
It moves the attack onto a personal phone. Nobody scans a QR code with the church’s desktop computer. They scan it with the phone in their pocket — a device the organization doesn’t own, doesn’t manage, and can’t inspect. Whatever protections your email system has, they aren’t in the room for this. And a credential typed into a fake login page on a phone — a username and password — works just as well for an attacker as one typed on a laptop.
This is a different problem from the one where an attacker sticks a fraudulent sticker over the QR code printed in your Sunday bulletin. That’s a code your church published, replaced. This is a code that arrived at your church uninvited.
Why a church office is close to an ideal target
Here is the part that makes this specifically your problem.
Unexpected packages are normal at a church. At a house, a box you didn’t order is strange, and that strangeness is the one instinct protecting the average consumer. At a church, boxes arrive constantly — VBS curriculum, communion supplies, replacement bulbs, a case of coffee, something a small group leader ordered on the ministry card three weeks ago, a donated item somebody mailed in. Five different people can order things, and none of them tells the office. An unaccounted-for package doesn’t raise a flag because there is no baseline to raise it against.
The person opening the mail is rarely the person who got the training. Mail-opening lands on a volunteer, a part-time administrator, or whoever is at the desk that morning. They’re helpful by disposition — that’s why they’re there. Solving the mystery of a strange package by scanning the code that offers to solve it is the natural, generous, competent-seeming thing to do.
There’s no policy to violate. Nobody has ever written down what to do with an unexpected box, because until recently there was nothing to write.
Churches are easy to research. Your address, your staff names, and often their email addresses are on your website. That is all the data set a brushing operation needs.
It’s a symptom, not just an incident
Even if nobody scans anything, the package tells you something.
The USPIS point is worth taking seriously: “scammers obtain personal information through nefarious means.” The box arrived because your organization’s details are sitting in somebody’s list. Not necessarily from a breach of your systems — far more often from a vendor, a mailing list, a directory, or a public filing. But circulating, in the hands of people running fraud schemes.
If the package was addressed to the church generally, that’s your organizational data. If it was addressed to a named staff member at the church address, that person’s details are circulating too — and the same list is likely being used for email and phone attacks that will arrive later and won’t come in a box.
Treat it as a prompt, not an emergency. Two things are worth doing: confirm that multi-factor authentication is turned on for church email and any financial accounts, and mention to the named staff member that they may want to watch their own accounts for a while. That’s it. No panic required.
What to tell your older members
This lands hardest at home, and hardest on the people least likely to have anyone to ask.
The FBI’s 2025 Internet Crime Report logged 201,266 complaints from victims aged 60 and over, with losses totaling $7.748 billion — losses up 59% in a single year, and averaging $38,500 per report. Those are the figures for all internet crime, not brushing alone, but the direction tells you who is being worked hardest right now.
A church is one of the very few institutions that can warn that age group and actually be believed. Not a bank’s form letter, not a news segment. A line in the newsletter and a sentence from the front on a Sunday morning:
If a package arrives that you didn’t order, don’t scan any code inside it. You can keep the item — you’re not obligated to pay for it. But the card with the QR code is the scam, and scanning it can hand over your accounts. If it happens, tell the office and we’ll help you sort it out.
That last sentence matters more than the rest. People who have been caught by something like this tend to go quiet out of embarrassment, and the quiet is what turns a small problem into a big one.
If you can’t identify what’s inside
One physical-safety note the Postal Inspection Service raises, and it’s short.
If an unsolicited package contains organic material — seeds, plant matter, food — or a substance you cannot identify, don’t handle it, don’t open it further, and don’t throw it in the trash. Set it down and report it. The Postal Inspection Service takes these reports, and unsolicited seed shipments in particular have been the subject of federal and state agricultural warnings. This is rare. It costs nothing to know.
For an ordinary unwanted package, you’re within your rights to keep it or discard it. If it’s unopened, you can mark it “RETURN TO SENDER” and hand it back to the carrier. You are never obligated to pay for something you didn’t order.
What to do this week
Add one line to whatever passes for your mail routine. Say it out loud to whoever opens the mail, and write it on a sticky note on the mail table if that’s what it takes:
If a package arrives that nobody can account for, don’t scan anything inside it. Set it aside and ask.
Ten seconds to say. It closes the entire category, because it doesn’t require the volunteer to judge whether a particular card looks legitimate — only to notice that nobody ordered the box.
Put four sentences in the next newsletter warning members about unexpected packages and the codes inside them. Use the language above. Aim it at the people in your congregation who live alone and get few visitors, because they’re the ones for whom a surprise package is a small bright spot rather than a question.
Fifteen minutes, total, and no budget.
If someone did scan a code and enter a password, treat it like any other stolen credential: change that password immediately from a different device, sign out of all sessions, turn on multi-factor authentication, and watch the account. If money moved, report it to the FBI at ic3.gov the same day — speed is most of what determines whether funds can be frozen. If personal information was entered, identitytheft.gov walks through the recovery steps.
MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including the small physical habits like this one — and returns a baseline score with a ranked list of what to fix first.
No spam and no sales calls — just one email when it’s live.
Related reading
- the other unwanted paper arriving in the office mail
- the slower fraud your older members will not mention
- where a volunteer can send something that feels off
MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.
Sources: US Postal Inspection Service, Brushing Scam; FBI Internet Crime Complaint Center, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes, I-073125-PSA; Federal Trade Commission, Scam alert: QR code on an unexpected package; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

