Curiosity is the invitation
The Federal Trade Commission describes an unexpected-package scam: a note asks you to scan a code to identify the sender or arrange a return. The destination may be a phishing website seeking account details or payment information. The package supplies a reason to trust a link you did not request. [1]

A familiar pattern is not a verified sender
The FTC also warns about replacement QR-code stickers on parking meters and unexpected codes in messages. Its guidance is to inspect the destination before opening it and watch for lookalike addresses. A professional-looking label does not settle who controls the page behind it. [2]
Take a different route
For an unexpected message that appears to come from a company, the FTC recommends contacting it using a number or website you already know is real. If you entered account credentials into a suspicious destination, the agency advises changing the password and enabling two-factor authentication. [2] [1]
Curiosity without the hurry
Our interpretation: pause at the request, not just the design of the code. “Find out who sent this” can be persuasive without an urgent threat. You can leave the puzzle unanswered while checking the supposed sender through an independent route.
Go a little deeper
Optional reading · about 1 more minute
Try the decision in your head
Hypothetical: an unrequested parcel includes a note saying “scan to reveal your gift.” You recognize neither the company nor the sender. Would a more polished note resolve either uncertainty? This example is about the trust decision, not evidence that every unexpected parcel is fraudulent.
What this story does not claim
These are established FTC warnings from 2023 and 2025, revisited for practical understanding. We have not measured how common this scam is today. The useful takeaway is to verify an unexpected request independently; the article does not label all QR codes unsafe or diagnose any particular package.
Original sources
Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.
- FTC: QR code on an unexpected package ↗
January 2025 alert, reviewed September 13, 2026. Package scenario, phishing destination and response after entering credentials. No current prevalence estimate.
- FTC: Harmful links hidden in QR codes ↗
December 2023 guidance, reviewed September 13, 2026. Main agency guidance only; reader comments are not evidence.
