MalwareZero

"Scan to see who sent this gift" isn't a gift, it's a login page

Updated August 6, 2026

The box is open on the counter, and sitting on top of the packing paper is a small glossy card with a QR code on it. Scan to see who sent this gift, it says. There's no lookup service behind that code, because whoever shipped the box printed the card, and they already know exactly who they are. What the code opens is a page asking you to sign in or "verify" yourself, and that page is the reason the package was mailed at all.

REGISTER YOUR GIFT
Scan this QR code to see who sent your gift!
Scan within 48 hours to claim
Recreated example of a card like this. Not a photo of a real one; built to match the wording described on this page.

The FBI's Internet Crime Complaint Center published a warning about this on July 31, 2025. Its point was blunt: these packages arrive with no sender identification on purpose, because a mystery is what makes you pick up your phone. The trinket in the box is a prop. It probably cost the sender a dollar or two, shipping included.

Lines that keep turning up on these cards

It varies, which is why searching the phrase printed on your card often turns up nothing at all. The versions that keep appearing in police alerts, postal inspector notices and security vendor writeups include:

The physical details are steadier than the text. Thin glossy cardstock, business card size or slightly larger. No company name anywhere. No phone number, no support email, no return address, no terms. Spelling is usually clean now, so please don't use typos as your test.

What's actually on the other side of the code

The code almost never points straight at its destination. It goes to a link shortener or a throwaway domain that bounces you onward, which is how the operators swap in a fresh phishing page once the old one gets blocked. If you want to see where your particular code leads without opening it on your phone, photograph the card and decode the QR image in your browser, which hands you the URL as plain text.

Where you land is a copy of somewhere you already have an account. Amazon sign in pages are the most commonly reported imitation, then USPS delivery pages, and less often a bank login. Reported flows tend to run in three stages, and the order is deliberate.

One version deserves its own warning. If the page asks for the six digit code your bank or Amazon just texted you, someone is signing in as you at that moment and needs you to hand over the second factor. Nothing legitimate asks you to retype a code you received into a page you reached from a printed card.

Why there's no sender to find

The economics explain everything. A seller wants ratings, and a rating counts for more when the platform stamps it "verified purchase," which requires a real order shipped to a real address. So the seller buys their own product, ships it to an address pulled from a breach or a data broker, and writes the review in that name. Cheap item, real tracking number, real delivery. That's brushing, and the older version of it is covered on the page explaining why unordered packages arrive at your door.

The QR card is what happens when someone works out that a single shipment can be sold twice: once as a fake review, once as a lead into phishing. There's no sender database because there was never a sender relationship. You were an address, not a recipient.

The danger is real and also smaller than the headlines

Snopes examined the viral versions of this warning and found them overstated, and I think that's the right call. Scanning a QR code does not by itself hand over your contacts, drain an account or install anything. Your camera reads a string of characters and offers to open a URL. Current iPhones and Android phones show you that URL first, before anything loads.

Harm comes from what you do next: typing a password, typing a card number, approving a login prompt, installing an app the page pushes at you. That distinction matters more than it sounds. When a news segment tells people their phone is compromised the instant they scan, anyone who did scan assumes the damage is done and stops reading. It usually isn't done. Usually nothing has happened yet.

The ten minutes after you open the box

Keep the item or bin it, your choice. Under 39 U.S.C. 3009, merchandise mailed to you without your consent is legally yours to retain, use or discard with no obligation to the sender, and nobody is allowed to bill you for it. Recycle the card. Then spend ten minutes on the part that actually matters:

None of those reports will get you a call back. They feed pattern data, which is how postal inspectors eventually find the shipper accounts behind a run of packages. Low effort, mildly useful, worth doing once and then forgetting about.

If you already scanned it

Work out what you typed, because that's the only thing that changes your next move. Nothing typed means no action beyond a password check. A password, a card number or a texted code means you should move now, in a specific order, which is laid out on the page covering what to do after scanning a scam QR code.

I can't tell you whether the domain on your particular card is still live, and there's no reliable public list of them, because these pages rotate within days. If yours shows a browser warning or a dead link, that's normal, and it doesn't mean you were spared. It means someone else reported it first. So keep the rule simple: a QR code you didn't go looking for is a code you don't scan.