Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Empty Envelopes in Your Mailbox Are a Known Scam Setup. Here Is What They Are After.

What the Empty Envelope Actually Signals
A plain white envelope shows up addressed to you. There is a tracking number. The sender name is unfamiliar. You open it and find nothing inside.
Most people's first instinct is confusion, then curiosity. That curiosity is exactly the opening scammers need.
According to Fox News, consumer protection investigators have connected these mystery mailings to a practice called brushing, where a third-party seller mails a cheap item, or sometimes an empty envelope, to a real address they do not own. The delivery gets logged as complete. The seller then posts a fake "verified buyer" review under your name on a marketplace like Amazon.
It is a simple fraud: manufacture proof of a transaction that never happened, attach a glowing five-star review, and make junk products look popular to real shoppers.
The QR Code Escalation
Brushing alone is obnoxious but relatively low-stakes for the recipient. The version that causes real harm is when the envelope contains a QR code.
Fox News reported that a growing number of these packages include QR codes designed to redirect targets to fake websites built to steal login credentials or financial information. This tactic is sometimes called "quishing" — phishing via QR code — and it has picked up because QR codes are harder for email spam filters to catch than traditional malicious links. You are scanning a physical object, not clicking a digital one, so the usual defenses do not apply.
A 2024 security survey cited in Fox News's coverage found that 73% of Americans scan QR codes without checking where they lead. Scammers know this. An envelope arriving at your home address carries an implicit legitimacy that a cold email does not, which raises the odds you act without thinking.
How They Got Your Address
The brushing scam requires a real name, a real address, and a real delivery. That information comes from somewhere.
Fox News outlined the common sourcing pipeline: data brokers, public records, old breach databases, and online leaks. If your name and home address appeared in any of the thousands of data breaches over the past decade, they are almost certainly for sale. Services like data brokers aggregate that information legally and sell it openly. Criminal marketplaces sell it illegally.
Receiving one of these envelopes means someone, somewhere, is using your address as a prop. It does not mean they have access to your accounts or finances, but it does confirm your personal information is in circulation.
The Strongest Counter-Concern
Some privacy advocates argue that data brokers operating legally in the United States face almost no federal regulation, and that vacuum is what makes brushing economically viable at scale. The scammer is exploiting a legal market. Critics of the current framework contend that until Congress passes comprehensive federal data privacy legislation, the advice to "opt out" of data brokers places an unreasonable burden on ordinary people to plug a hole that should not exist. The FTC has taken enforcement actions against specific bad actors but has not moved to structurally restrict the data broker industry. There is no comprehensive federal data privacy law as of June 27, 2026.
That said, individual action still reduces exposure meaningfully, even within the current legal landscape.
What to Do If One Arrives
Fox News and cybersecurity commentator Kurt "CyberGuy" Knutsson offered the following guidance:
- Do NOT scan any QR code inside an unsolicited package, regardless of how official it looks.
- Do not call any phone number printed in the envelope.
- Do not enter personal information on any site the envelope directs you to.
- Report the package to the FTC at ReportFraud.ftc.gov.
- If you have an account on a major marketplace, log in directly — not through any link or code in the envelope — and check whether a review has been posted under your name.
- Consider running your email address through a breach-check service like HaveIBeenPwned.com to gauge how widely your data has spread.
- Submitting opt-out requests to major data brokers (Spokeo, Whitepages, BeenVerified) is tedious but does reduce your visibility over time.
What Remains Unresolved
The brushing scam has been documented for years, primarily tied to sellers operating through Chinese-based third-party storefronts on Amazon and similar platforms. Amazon has stated it investigates and removes sellers found to be brushing, but the scale of the problem and the company's actual removal rate are not publicly reported in any consistent, verifiable format.
The more pressing open question is the QR code variant. There is no centralized tracking of how many financial or credential thefts have originated from physical mail QR codes specifically, which makes it difficult to size the risk precisely. The FBI's Internet Crime Complaint Center (IC3) tracks quishing losses broadly but does not break out the physical-mail vector in its published annual reports. Until that data exists, the actual harm rate from envelope-delivered QR codes remains genuinely unknown.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.