THE MACHINE THRESHOLD
Cybersecurity / EXPLAINER / 2 MIN READ + OPTIONAL DEEP DIVE

A surprise package. A code worth questioning.

The invitation to find out who sent a gift can lead somewhere else entirely.

AI-assisted synthesis · Published 2026-09-13 · Updated & sources checked 2026-09-13
How we research and correct our work

An unfamiliar parcel can turn curiosity into a request to open an unfamiliar website.

Curiosity is the invitation

The Federal Trade Commission describes an unexpected-package scam: a note asks you to scan a code to identify the sender or arrange a return. The destination may be a phishing website seeking account details or payment information. The package supplies a reason to trust a link you did not request. [1]

Painted open parcel with an abstract square-pattern card and a phone lying face down
AI-generated conceptual still life · the square pattern is illustrative, not a code to scan

A familiar pattern is not a verified sender

The FTC also warns about replacement QR-code stickers on parking meters and unexpected codes in messages. Its guidance is to inspect the destination before opening it and watch for lookalike addresses. A professional-looking label does not settle who controls the page behind it. [2]

Take a different route

For an unexpected message that appears to come from a company, the FTC recommends contacting it using a number or website you already know is real. If you entered account credentials into a suspicious destination, the agency advises changing the password and enabling two-factor authentication. [2] [1]

Curiosity without the hurry

Our interpretation: pause at the request, not just the design of the code. “Find out who sent this” can be persuasive without an urgent threat. You can leave the puzzle unanswered while checking the supposed sender through an independent route.

Go a little deeper

Optional reading · about 1 more minute

Try the decision in your head

Hypothetical: an unrequested parcel includes a note saying “scan to reveal your gift.” You recognize neither the company nor the sender. Would a more polished note resolve either uncertainty? This example is about the trust decision, not evidence that every unexpected parcel is fraudulent.

What this story does not claim

These are established FTC warnings from 2023 and 2025, revisited for practical understanding. We have not measured how common this scam is today. The useful takeaway is to verify an unexpected request independently; the article does not label all QR codes unsafe or diagnose any particular package.

Original sources

Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.

  1. FTC: QR code on an unexpected package ↗

    January 2025 alert, reviewed September 13, 2026. Package scenario, phishing destination and response after entering credentials. No current prevalence estimate.

  2. FTC: Harmful links hidden in QR codes ↗

    December 2023 guidance, reviewed September 13, 2026. Main agency guidance only; reader comments are not evidence.

Suggest a correction

Know someone who would find this interesting?

Share this story on Facebook ↗ ·

Follow on Facebook ↗ for story highlights and questions to explore next.

Where this question leads next

Follow new explainers and updates →