Skip to main content

The Money Overview

A \”brushing\” scam sends an unordered package to use your stolen personal data

An unordered package arriving on a doorstep can look like a harmless mistake or an unexpected gift, but investigators treat it as a warning light. In a “brushing” scam, a seller ships merchandise to a real name and address in order to post a fake “verified purchase” review, and the reason it should worry the recipient is simple: it means someone already has enough personal information to use it. The free box is not the crime. The exposed data behind it is.

What an unordered package really signals

Brushing exists to game online reviews. A third-party seller wants a stack of five-star “verified purchase” ratings, so it creates fake buyer accounts and ships cheap goods, such as seeds, jewelry or gadgets, to real people whose names and addresses it has obtained. The delivery lets the seller mark the purchase as verified and then post a glowing review under the recipient’s identity.

The recipient never paid, which is why the package feels like a windfall rather than a threat. But the shipment confirms that at least a name and mailing address are circulating, and often those details arrived bundled with more sensitive data from an earlier breach or leak.

The Federal Trade Commission’s consumer alerts flag an unexpected package as a prompt to check whether accounts have been tampered with, because the same data that fueled the fake review can fuel fraud that actually costs money.


Free retirement updates: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.

The money at risk when data is loose

Exposed personal information is the raw material of financial fraud. A name and address paired with a date of birth, a Social Security number or a compromised login can be enough to open a credit card, hijack an online shopping account or redirect a delivery, and older adults are frequent targets because they tend to have established credit and savings.

The danger compounds when a marketplace account has been taken over. If a scammer is placing orders through a real account to run the brushing scheme, that account may also hold saved payment cards, stored addresses and order history, all of which can be turned toward genuine theft.

The federal recovery hub, IdentityTheft.gov, walks victims through the exact steps to take when personal data has been misused, from disputing fraudulent charges to placing recovery documentation on file. Treating the package as a cue to visit that resource turns a strange delivery into an early-warning system.

Health and insurance data raise the stakes further. When a leak bundles medical or coverage details with a name and address, exposed information can enable medical identity theft, in which a fraudster obtains care or prescriptions under someone else’s benefits. Untangling a falsified medical or claims record is far harder, and slower, than reversing a single fraudulent charge on a card.

The moves that lock down the exposure

The first step is a review of the accounts most likely to be abused. Checking recent orders and login activity on major shopping accounts, changing the password on any account that shows unfamiliar activity, and turning on two-factor authentication all shut down the most direct path from exposed data to real charges.

A credit freeze is the strongest and cheapest safeguard. The FTC explains that a credit freeze is free at each of the three major bureaus and blocks new accounts from being opened in a person’s name until the freeze is lifted, which is precisely the kind of fraud loose personal data enables. Reviewing bank and card statements for small test charges catches theft in its earliest stage.

Opting out of data brokers shrinks the target over time. Much of the name-and-address data that fuels brushing is bought from list brokers and people-search sites, and requesting removal from the largest ones reduces how often those details are traded. Pulling the free reports available at AnnualCreditReport.com adds a periodic check for accounts a person never opened.

The merchandise itself can be kept or discarded; there is no obligation to pay or return it. What should not be ignored is the tell it carries, that data linked to the household is already in the wrong hands.

Spotting the follow-on scams

Brushing rarely travels alone. Some packages include a QR code or a slip inviting the recipient to scan it to “find out who sent this” or claim a reward, and scanning can lead to a phishing page built to harvest logins or payment details. The safe response is to ignore any code or link that arrives with an unexpected shipment.

Impersonation messages often follow. The FTC’s guidance on recognizing and avoiding phishing notes that texts or emails claiming a problem with a delivery, and urging a click to “reschedule” or “verify,” are a standard hook, and an unexpected package can make those messages feel legitimate.

The steady rule underneath all of it is that a mystery package is information, not a gift. The recipient paid nothing for the box, but the data that put it on the porch is worth guarding before it costs real money.

This article was researched and drafted with the assistance of AI and reviewed by The Money Overview editorial team.

More Financial Reading