Home Articles Get your free assessmentComing soon

Tag: quishing

  • QR Codes in the Bulletin: The Giving Scam Nobody Sees Coming

    QR Codes in the Bulletin: The Giving Scam Nobody Sees Coming

    The giving QR code is on the back of the bulletin, on the screen during announcements, on the laminated card in each pew rack, and on the poster by the door — because it works. Point a phone at the square, the giving page opens, and the awkwardness of passing a plate past a visitor is gone.

    Now consider what that square actually is. A QR code — the name stands for quick response — is a web address printed as a pattern a camera can read. That’s all. And its defining feature is the problem: a human being cannot read it. You can proofread every word of the bulletin, but you cannot proofread the code. A square that sends the congregation to your giving platform and a square that sends them to a scammer’s copy of it look identical from across the room, and nearly identical from six inches.

    The FBI warned about exactly this in a public service announcement back in January 2022: criminals “tamper with both digital and physical QR codes,” swapping legitimate ones for their own to steal credentials and payments. The FTC followed in December 2023 with the consumer version, describing the physical trick already common on parking meters — a scam sticker printed and stuck over the real code.

    A parking meter and a pew card have a lot in common. Both sit unattended in a public place. Both are trusted by the person scanning. And both are asking for money.

    The two directions the swap happens

    On paper, with a sticker. Someone prints their own code on adhesive labels — a task that takes ten minutes and costs nothing — and applies them to the lobby poster, the pew cards, the yard sign for the capital campaign. The fake destination is a page that looks like your giving platform: same logo, lifted from your website; same colors; a form that takes card numbers. Sunday’s gifts flow to an account you’ve never heard of, and the failure is invisible until someone asks why online giving dipped.

    Upstream, in the file. The subtler version never touches your building. It compromises the source of the code: the shared Canva account a volunteer uses for slides, the email thread where the bulletin file gets passed around, the church email account of whoever assembles it. Change the code in the master file once, and the church then prints, projects and distributes the fraud itself, every week, with its own hands.

    And to complete the picture: this scam also arrives at the church from outside — unsolicited packages with “scan to see who sent you this gift” cards, which we covered in the brushing scam. Same square, opposite direction. Today’s post is about the codes you publish.

    Why nobody notices

    Nobody checks the destination. On a phone, the preview that appears when you scan shows a URL for a moment — but giving platforms have long, forgettable addresses full of subdomains ( `yourchurch.givingvendor.com`, `app.vendor.com/give/12345` ), so the congregation has no memory of what the right address looks like. The FTC’s advice — inspect the URL for misspellings before opening — assumes you know what correct is. Most givers don’t.

    That’s not a reason to abandon the codes. It’s the design constraint: the safeguards have to live with the people who publish the code, because the people who scan it can’t be expected to catch anything.

    What to do this week

    Put the giving address into human memory. Pick the shortest true form of your giving URL and print it next to every code, every time: “Scan, or visit yourchurch.org/give.” That one habit does three jobs: givers who prefer typing never scan at all; anyone who scans can compare what opened against what’s printed; and a swapped sticker now has to fake two things that must agree. A code with no readable address beside it is asking the congregation to trust ink they can’t read.

    Make one person the owner of the square. Not a committee — a name. That person generates the code (directly from the giving platform, not from free third-party QR generator sites, which can route through tracking domains you don’t control), keeps the master graphic in one place, and is the only source others copy from. Every “just grab the code from last month’s file” is a link in a chain nobody is watching.

    Add the codes to a monthly walk-through. First Sunday of the month, someone scans every published code in the building — pew cards, posters, yard signs, the slide deck — on their own phone and confirms each lands on the real page. It takes five minutes. While they’re at it: run a fingernail over printed codes. A sticker over ink has an edge you can feel. That’s the FBI’s tampering warning turned into a chore anyone can do.

    Watch the money like a control, not a report. Whoever reconciles giving should treat an unexplained dip in online gifts as a security signal worth a same-week look, not a trend to discuss at the quarterly meeting. In the sticker version of this scam, the finance spreadsheet is the only alarm that ever goes off.

    Tell givers the one rule that survives everything. In the bulletin, once a season: our giving page is yourchurch.org/give — if a code ever takes you anywhere else, close it and tell the office. You’re not teaching the congregation to distrust the plate. You’re giving them the same gift every post in this series comes down to: a known-good channel to fall back on.

    The QR code turned your congregation’s generosity into a single point of failure. It can stay — it should stay — but it graduates from decoration to infrastructure. Infrastructure gets an owner, a checklist, and an alarm.

    The MissionDefend assessment asks who owns your giving links, who can edit what gets printed, and whether anyone would notice a swap — along with the rest of your baseline. Join the launch list.


    Sources: FBI Internet Crime Complaint Center, Cybercriminals Tampering with QR Codes to Steal Victim Funds, Alert I-011822-PSA (January 18, 2022); Federal Trade Commission, Scammers hide harmful links in QR codes to steal your information (December 6, 2023).

  • The Package Nobody Ordered: Brushing Scams and the QR Code in the Box

    The Package Nobody Ordered: Brushing Scams and the QR Code in the Box

    It’s a Tuesday, and there’s a box on the counter in the church office.

    Nobody remembers ordering it. It’s addressed to the church, correctly, with the right street number and the right suite. Inside is a phone case in a color nobody would choose, or a set of silicone kitchen rings, or a keychain flashlight — something cheap, sealed in plastic, with no packing slip and no invoice.

    There is one other thing in the box: a small printed card.

    Thank you for your order! Scan the QR code below to see who sent this gift and claim your free item.

    The volunteer who opens the mail on Tuesdays holds up her phone, taps the camera, and the code resolves into a link.

    That is the whole attack. It took nine seconds, and nothing about it felt like an attack.

    What a brushing scam actually is

    Start with the original version, because it explains why the box exists at all.

    A brushing scam is a fake-review scheme. A seller on a large marketplace wants better ratings, so they ship a cheap item to a real name at a real address — pulled from a data set they bought or scraped — and record it as a completed sale. Then they write a glowing review in that person’s name. Because a package genuinely shipped and genuinely arrived, the platform marks it a “verified purchase,” which is exactly the label shoppers trust most.

    The US Postal Inspection Service describes the goal plainly: the packages are sent so as “to give the impression that the recipient is a verified buyer who has written positive online reviews.”

    For years that was the end of it. Annoying, faintly creepy, mostly harmless to the recipient. You kept the phone case.

    The new part: the card with the QR code

    The scheme has been repurposed, and the second version is not harmless.

    A QR code — short for Quick Response code — is that square pattern of black and white blocks. Your phone’s camera reads it and turns it into a web address, then usually offers to open it. It is a link with the letters hidden.

    In the current variant, the package contains a card with a QR code and a reason to scan it. Scan to see who sent this. Scan to register your gift. Scan for a free item. Scan to leave a review. The code leads to a page that either asks for information — name, address, card number, or a username and password for an account you already have — or prompts you to install an app that gives an attacker access to the phone.

    That is phishing: a message built to look like it comes from someone you’d trust, designed to get you to hand over information or install something. When the bait is a QR code rather than a link in an email, the security world calls it quishing. The Postal Inspection Service now names this pattern directly, warning that “cards with QR codes are being sent inside packages as a part of brushing scams.”

    The FBI issued a public service announcement about it on 31 July 2025 — PSA I-073125-PSA, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes. The Bureau’s description: criminals “send unsolicited packages containing a QR code that prompts the recipient to provide personal and financial information or unwittingly download malicious software.” The Federal Trade Commission flagged the same thing in a consumer alert in January 2025, noting that scanning “could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords,” or “download malware onto your phone.”

    Three government bodies describing the same box. That’s about as verified as a threat gets.

    And a QR code is worse than a link in an email, for two reasons, neither of them technical.

    It hides where it goes. In an email you can hover over a link and see the address it leads to. You can notice that “your bank” is actually a string of nonsense followed by .ru. A QR code shows you nothing. It’s a picture. By the time the address appears, it’s in a small gray bar at the top of a browser window that has already loaded the page.

    It moves the attack onto a personal phone. Nobody scans a QR code with the church’s desktop computer. They scan it with the phone in their pocket — a device the organization doesn’t own, doesn’t manage, and can’t inspect. Whatever protections your email system has, they aren’t in the room for this. And a credential typed into a fake login page on a phone — a username and password — works just as well for an attacker as one typed on a laptop.

    This is a different problem from the one where an attacker sticks a fraudulent sticker over the QR code printed in your Sunday bulletin. That’s a code your church published, replaced. This is a code that arrived at your church uninvited.

    Why a church office is close to an ideal target

    Here is the part that makes this specifically your problem.

    Unexpected packages are normal at a church. At a house, a box you didn’t order is strange, and that strangeness is the one instinct protecting the average consumer. At a church, boxes arrive constantly — VBS curriculum, communion supplies, replacement bulbs, a case of coffee, something a small group leader ordered on the ministry card three weeks ago, a donated item somebody mailed in. Five different people can order things, and none of them tells the office. An unaccounted-for package doesn’t raise a flag because there is no baseline to raise it against.

    The person opening the mail is rarely the person who got the training. Mail-opening lands on a volunteer, a part-time administrator, or whoever is at the desk that morning. They’re helpful by disposition — that’s why they’re there. Solving the mystery of a strange package by scanning the code that offers to solve it is the natural, generous, competent-seeming thing to do.

    There’s no policy to violate. Nobody has ever written down what to do with an unexpected box, because until recently there was nothing to write.

    Churches are easy to research. Your address, your staff names, and often their email addresses are on your website. That is all the data set a brushing operation needs.

    It’s a symptom, not just an incident

    Even if nobody scans anything, the package tells you something.

    The USPIS point is worth taking seriously: “scammers obtain personal information through nefarious means.” The box arrived because your organization’s details are sitting in somebody’s list. Not necessarily from a breach of your systems — far more often from a vendor, a mailing list, a directory, or a public filing. But circulating, in the hands of people running fraud schemes.

    If the package was addressed to the church generally, that’s your organizational data. If it was addressed to a named staff member at the church address, that person’s details are circulating too — and the same list is likely being used for email and phone attacks that will arrive later and won’t come in a box.

    Treat it as a prompt, not an emergency. Two things are worth doing: confirm that multi-factor authentication is turned on for church email and any financial accounts, and mention to the named staff member that they may want to watch their own accounts for a while. That’s it. No panic required.

    What to tell your older members

    This lands hardest at home, and hardest on the people least likely to have anyone to ask.

    The FBI’s 2025 Internet Crime Report logged 201,266 complaints from victims aged 60 and over, with losses totaling $7.748 billion — losses up 59% in a single year, and averaging $38,500 per report. Those are the figures for all internet crime, not brushing alone, but the direction tells you who is being worked hardest right now.

    A church is one of the very few institutions that can warn that age group and actually be believed. Not a bank’s form letter, not a news segment. A line in the newsletter and a sentence from the front on a Sunday morning:

    If a package arrives that you didn’t order, don’t scan any code inside it. You can keep the item — you’re not obligated to pay for it. But the card with the QR code is the scam, and scanning it can hand over your accounts. If it happens, tell the office and we’ll help you sort it out.

    That last sentence matters more than the rest. People who have been caught by something like this tend to go quiet out of embarrassment, and the quiet is what turns a small problem into a big one.

    If you can’t identify what’s inside

    One physical-safety note the Postal Inspection Service raises, and it’s short.

    If an unsolicited package contains organic material — seeds, plant matter, food — or a substance you cannot identify, don’t handle it, don’t open it further, and don’t throw it in the trash. Set it down and report it. The Postal Inspection Service takes these reports, and unsolicited seed shipments in particular have been the subject of federal and state agricultural warnings. This is rare. It costs nothing to know.

    For an ordinary unwanted package, you’re within your rights to keep it or discard it. If it’s unopened, you can mark it “RETURN TO SENDER” and hand it back to the carrier. You are never obligated to pay for something you didn’t order.

    What to do this week

    Add one line to whatever passes for your mail routine. Say it out loud to whoever opens the mail, and write it on a sticky note on the mail table if that’s what it takes:

    If a package arrives that nobody can account for, don’t scan anything inside it. Set it aside and ask.

    Ten seconds to say. It closes the entire category, because it doesn’t require the volunteer to judge whether a particular card looks legitimate — only to notice that nobody ordered the box.

    Put four sentences in the next newsletter warning members about unexpected packages and the codes inside them. Use the language above. Aim it at the people in your congregation who live alone and get few visitors, because they’re the ones for whom a surprise package is a small bright spot rather than a question.

    Fifteen minutes, total, and no budget.

    If someone did scan a code and enter a password, treat it like any other stolen credential: change that password immediately from a different device, sign out of all sessions, turn on multi-factor authentication, and watch the account. If money moved, report it to the FBI at ic3.gov the same day — speed is most of what determines whether funds can be frozen. If personal information was entered, identitytheft.gov walks through the recovery steps.

    MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts — including the small physical habits like this one — and returns a baseline score with a ranked list of what to fix first.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: US Postal Inspection Service, Brushing Scam; FBI Internet Crime Complaint Center, Unsolicited Packages Containing QR Codes Used to Initiate Fraud Schemes, I-073125-PSA; Federal Trade Commission, Scam alert: QR code on an unexpected package; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.