Back to news
Cybersecurity Alert
September 20, 2026 by EmailMeNow IT Consulting

Houston Warning: Unexpected Packages Can Be QR Phishing

Click2Houston warned Sept 15 that unsolicited Amazon-style packages can hide QR phishing. FTC Aug 20 alert and FBI IC3 PSA match. Audits (ideal 100%): ic3.gov 87%, usps.com 77%, ftc.gov 72%, amazon.com 54%.

Source: Click2Houston · Federal Trade Commission

NewsPhishingTexasHoustonConsumer AlertMFAYubiKeyAuthenticator AppsCybersecurity
Unexpected porch package with a scan-to-return card and a phone that has not scanned the code

Click2Houston warned Houston viewers on September 15, 2026: an unexpected package can be a brushing scam, and the real hit is often the QR code, link, or “return” note inside — not the cheap lotion or hair product. Scan that code and you can land on a phishing site or install malware.

This is not a report that Amazon, Temu, USPS, or the FTC were hacked. It is a consumer-alert phishing pattern. The FTC published the same QR-inside-the-box warning on August 20, 2026. The FBI IC3 flagged the QR variation on July 31, 2025.

We scanned ic3.gov, usps.com, ftc.gov, and amazon.com. 100% is the ideal overall domain-security score. None reach it.

Unexpected porch package with a scan-to-return card and a phone that has not scanned the code

Snapshot

FieldDetail
Local alertClick2Houston · Sept 15, 2026
Federal alertFTC · Aug 20, 2026
QR / malware PSAFBI IC3 I-073125-PSA · July 31, 2025
Postal guidanceUSPIS — Brushing Scam
ReportReportFraud.ftc.gov · ic3.gov

Two scams in one box

Classic brushing is a fake-review trick. A seller ships something you never ordered — often under a known marketplace name — then uses the delivery as “proof” you bought it so they can post a review in your name. The FTC says recent reports describe cheap, random items: baby wipes, toothpaste, seeds.

The phishing twist is what Houston TV is stressing. The Postal Inspection Service calls it quishing: a card that says scan to learn who sent the gift or how to return it. The FBI says packages often arrive without a sender so you feel you have to scan. The site can harvest card numbers, usernames, and passwords, or drop malware that steals data from the phone.

Click2Houston cites the Better Business Bureau on the same don’t-scan, don’t-click advice. Treat a lookalike Amazon or eBay label as a costume, not proof the real retailer sent it.

Opened box with a scan-to-see-who-sent-this card beside a generic fake login screen

What to do with the package

Federal and local advice overlap on the dangerous part: do not scan the QR code, click the link, or follow the card’s return website.

StepWhy
Leave the code unscannedQR can open a phishing page or malware
Change shopping passwordsAddress on the box may mean the account was already abused
Message the real retailerFTC: tell Amazon or the marketplace so they can pull a fake seller
Check creditAnnualCreditReport.com weekly

Keeping it. The FTC says you generally may keep unordered merchandise and are not required to pay or return it. USPIS says the same if you opened it and want it — and that you may throw it away if it is safe. USPIS also says an unopened box with a return address can be marked RETURN TO SENDER. Click2Houston’s local warning is stricter: don’t try to return using the package’s own instructions. Those two are compatible if you treat the card’s QR / “return portal” as the trap, not a USPS window.

Do not eat, plant, or use mystery seeds, food, or unknown liquids. USPIS: call the proper authorities for organic or unknown contents.

If you already scanned and typed a password, change that password now, turn on a stronger second factor, and report the lure.

MFA on the accounts this lure hunts

A QR page that looks like Amazon or USPS still works if you type the password. Hardware keys and authenticator apps raise the cost after you lock the real account. They do not make a porch QR safe.

GradeMeaning
FailSMS, email OTP, or no public key / open TOTP
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Amazon shoppingFailNoYes
USPS / Informed DeliveryFailNoYes

Amazon’s two-step help documents a code by text message or authenticator app. Passkeys exist on the shopping account. Amazon does not name a YubiKey enrollment button for retail two-step. SMS stays in the public docs, so the row stays Fail. (AWS IAM security keys are a different login.)

USPS MFA help and the August 17, 2026 customer guide name SMS, email OTP, or an authenticator app — including Google Authenticator. New accounts after March 6, 2025 must enroll; older accounts can skip. USPS does not name YubiKey. SMS and email OTP keep the row Fail. Enroll the authenticator anyway, and use Informed Delivery to see what is actually coming — do not treat a digest email link as automatically safe.

Directory: MFA support directory · Category → Business Apps.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside phones showing an authenticator code and a weaker SMS one-time code

Independent cybersecurity audits

We audited the official report, postal, regulator, and marketplace hosts on September 20, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean a retailer was breached.

OrganizationDomainOverallvs 100%
FBI IC3ic3.gov87%−13
USPSusps.com77%−23
Federal Trade Commissionftc.gov72%−28
Amazonamazon.com54%−46
DomainIdentityTransportWebsite
ic3.gov90%45%97%
usps.com75%15%87%
ftc.gov95%45%40%
amazon.com55%15%37%

Audit links: ic3.gov · usps.com · ftc.gov · amazon.com

usps.com and amazon.com sit at 15% transport (MTA-STS / related). A spoofed “your package / return this item” message is easier to deliver than the overall scores suggest. Type usps.com and amazon.com yourself. Do not use the QR.

Postal Inspection Service host uspis.gov scored 53% (Identity 50 / Transport 45 / Website 37). Use it as the guidance page, not a login you reach from a box card.

Domain audit scoreboard versus the 100 percent ideal

Website stack

Passive homepage + Certificate Transparency probes (September 20, 2026). Versions only — not a claim the sites were compromised.

DomainStack note
ic3.govCMS undetected; DigiCert TLS expires 2027-01-05
usps.comCMS undetected; Sectigo TLS expires 2027-03-25
ftc.govDrupal 10 (probe latest 11.4.7); IdenTrust TLS expires 2027-03-01
amazon.comCMS undetected; DigiCert TLS expires 2027-01-23
uspis.govCMS undetected; Sectigo TLS expires 2027-03-25; HTTP→HTTPS redirect not confirmed on probed hosts

Drupal 10 vs 11.x on ftc.gov is a probe comparison, not a brushing finding.

Blacklist and lookalikes

Email blacklist checks (public DoH, September 20, 2026): ic3.gov, ftc.gov, and amazon.com were clear on mail/domain lists we can query. usps.com and uspis.gov share Proofpoint-hosted MX; one IP showed SpamRATS all. That is shared-gateway noise, not a finding that USPS is a spam source. We do not lead on it.

Registered lookalikes that matter for this lure (BEC / standard squat scan):

LookalikeTechniqueSignal
amaz0n.com / ama2on.comhomoglyphLive NS + A
aazon.comomissionNS + A + MX
amazon.netTLD swapNS + A + MX
iusps.com / usp5.cominsert / homoglyphNS + A + MX
usps.orgTLD swapNS + A + MX
ic3.comTLD swapBEC staging (NS + MX, no site A)
ftc.bizTLD swapBEC staging (NS + MX)

Amazon also owns many defensive redirects (amazon.org, aamazon.com, and peers). Type amazon.com, usps.com, ftc.gov, and ic3.gov — not a near-spell from a package card. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener RECAP searches for “brushing scam,” quishing, and unsolicited package + QR did not turn up a matching 2025–2026 federal QR-package docket. This remains a consumer-alert story, not a filed Houston case we can cite.

Sources: Click2Houston, Sept 15, 2026 · FTC — unexpected package / brushing, Aug 20, 2026 · FBI IC3 PSA I-073125-PSA · USPIS — Brushing Scam · Amazon two-step verification and passkeys · USPS MFA FAQ. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 20, 2026. Domain scores: audit.emailmenow.com only.