"Scan to see who sent this gift" isn't a gift, it's a login page
Updated August 6, 2026
The box is open on the counter, and sitting on top of the packing paper is a small glossy card with a QR code on it. Scan to see who sent this gift, it says. There's no lookup service behind that code, because whoever shipped the box printed the card, and they already know exactly who they are. What the code opens is a page asking you to sign in or "verify" yourself, and that page is the reason the package was mailed at all.
- 1No company name, phone number, or return address anywhere on the card
- 2Code routes through a link shortener that can swap in a new phishing page
- 3"Verify identity" step asks for DOB and SSN digits, never needed to find a sender
- 4Nothing legitimate asks you to retype a six-digit code just texted to you
The FBI's Internet Crime Complaint Center published a warning about this on July 31, 2025. Its point was blunt: these packages arrive with no sender identification on purpose, because a mystery is what makes you pick up your phone. The trinket in the box is a prop. It probably cost the sender a dollar or two, shipping included.
Lines that keep turning up on these cards
It varies, which is why searching the phrase printed on your card often turns up nothing at all. The versions that keep appearing in police alerts, postal inspector notices and security vendor writeups include:
- "Scan this QR code to see who sent your gift!"
- "REGISTER YOUR GIFT" across the top in capitals, sometimes with a fake serial number under it
- "Scan to confirm delivery"
- "Activate your free product warranty"
- "Claim your bonus reward"
- Something short and warm, along the lines of "A little something for you. Scan to find out who from."
The physical details are steadier than the text. Thin glossy cardstock, business card size or slightly larger. No company name anywhere. No phone number, no support email, no return address, no terms. Spelling is usually clean now, so please don't use typos as your test.
What's actually on the other side of the code
The code almost never points straight at its destination. It goes to a link shortener or a throwaway domain that bounces you onward, which is how the operators swap in a fresh phishing page once the old one gets blocked. If you want to see where your particular code leads without opening it on your phone, photograph the card and decode the QR image in your browser, which hands you the URL as plain text.
Where you land is a copy of somewhere you already have an account. Amazon sign in pages are the most commonly reported imitation, then USPS delivery pages, and less often a bank login. Reported flows tend to run in three stages, and the order is deliberate.
- Stage one, "confirm your delivery address." Feels harmless. You already gave that address to a courier. It also tells the operator a real person read the card.
- Stage two, "verify your identity." Full name, date of birth, phone number, sometimes the last four digits of your Social Security number. None of that is needed to look up a sender.
- Stage three, the money. A card number for a small activation or shipping fee, often a couple of dollars. That variant has its own mechanics, which I've broken down on the page about the register your gift card insert.
One version deserves its own warning. If the page asks for the six digit code your bank or Amazon just texted you, someone is signing in as you at that moment and needs you to hand over the second factor. Nothing legitimate asks you to retype a code you received into a page you reached from a printed card.
Why there's no sender to find
The economics explain everything. A seller wants ratings, and a rating counts for more when the platform stamps it "verified purchase," which requires a real order shipped to a real address. So the seller buys their own product, ships it to an address pulled from a breach or a data broker, and writes the review in that name. Cheap item, real tracking number, real delivery. That's brushing, and the older version of it is covered on the page explaining why unordered packages arrive at your door.
The QR card is what happens when someone works out that a single shipment can be sold twice: once as a fake review, once as a lead into phishing. There's no sender database because there was never a sender relationship. You were an address, not a recipient.
The danger is real and also smaller than the headlines
Snopes examined the viral versions of this warning and found them overstated, and I think that's the right call. Scanning a QR code does not by itself hand over your contacts, drain an account or install anything. Your camera reads a string of characters and offers to open a URL. Current iPhones and Android phones show you that URL first, before anything loads.
Harm comes from what you do next: typing a password, typing a card number, approving a login prompt, installing an app the page pushes at you. That distinction matters more than it sounds. When a news segment tells people their phone is compromised the instant they scan, anyone who did scan assumes the damage is done and stops reading. It usually isn't done. Usually nothing has happened yet.
The ten minutes after you open the box
Keep the item or bin it, your choice. Under 39 U.S.C. 3009, merchandise mailed to you without your consent is legally yours to retain, use or discard with no obligation to the sender, and nobody is allowed to bill you for it. Recycle the card. Then spend ten minutes on the part that actually matters:
- Sign in to Amazon and any other marketplace account you hold, through the app or by typing the address yourself, and look for orders you didn't place and reviews posted under your name.
- Change that account's password if you've reused it anywhere, and switch on two factor authentication.
- Report the delivery to the retailer. Amazon keeps a dedicated unsolicited package form in its customer service help pages.
- Report the card to the FTC at ReportFraud.ftc.gov, to the Postal Inspection Service at uspis.gov/report or 1-877-876-2455, and to the FBI at ic3.gov. If you're 60 or older, the Justice Department's Elder Justice hotline is 1-833-FRAUD-11.
None of those reports will get you a call back. They feed pattern data, which is how postal inspectors eventually find the shipper accounts behind a run of packages. Low effort, mildly useful, worth doing once and then forgetting about.
If you already scanned it
Work out what you typed, because that's the only thing that changes your next move. Nothing typed means no action beyond a password check. A password, a card number or a texted code means you should move now, in a specific order, which is laid out on the page covering what to do after scanning a scam QR code.
I can't tell you whether the domain on your particular card is still live, and there's no reliable public list of them, because these pages rotate within days. If yours shows a browser warning or a dead link, that's normal, and it doesn't mean you were spared. It means someone else reported it first. So keep the rule simple: a QR code you didn't go looking for is a code you don't scan.