What we found
- Rests on a single official FTC consumer alert with no independent corroboration in our harvested rows.
- The advisory is directly on point and describes the mechanics, contents and QR-code phishing step in its own words.
- No figures on scale, losses or specific sellers are given, so the scope of the activity cannot be sized.
- Reviewed by 3 models, 2 from independent houses.
What we don’t know
- How many people have received these packages and over what period.
- Whether anyone lost money after scanning a QR code from a package.
- Which sellers, marketplaces or regions the reports to the FTC came from.
- How senders obtained the names and addresses used on the packages.
The bench — who voted
3 INDEPENDENT AI MODELS REVIEWED THIS. ALL 3: MODERATE RISK.
The card names a count. Here are the seats behind it, with what each one said.
DISSENT, PRESERVEDThe headline CLAIM — unordered packages can be brushing, and an enclosed QR code can lead to phishing — is squarely carried by the one row and should not be softened. My objection is to the ornamentation around it, not the core.
DISSENT, PRESERVEDBuilding a public alert on a single sourced row and then populating it with unattributed detail is the failure mode worth naming here. The disclosure paragraph is honest, but honesty about sourcing does not license extrapolation beyond the source.
DISSENT, PRESERVEDOn danger: I grade moderate rather than high because the direct loss vector requires the reader to scan and then actively enter credentials or card data. Credential and card capture is a real harm, but the pattern is interruptible at two points and the defensive action (do not scan) is simple and costless. I would defend moderate against a push to high.
Reviewed by 3 independent models; all judged the finding to go beyond the evidence.
▼ Protocol & challenge record
ON THE RECORDThe advice sentence as drafted is the most consequential defect in this packet, and I do not accept it. The finding tells the reader the package may mean someone already holds their personal information, then gives them one action: change shopping passwords. The FTC's own advisory, in the same harvested row, tells them to check their credit weekly at AnnualCreditReport.com, watch for identity-theft signs, notify the marketplace, and report at ReportFraud.ftc.gov. Dropping four of five steps while keeping the alarming framing leaves the reader worried and under-equipped. If the Desk ships this as written, my position on the record is that the advice line is materially incomplete relative to the source it claims to summarise.
ON THE RECORDI also dissent on the word 'instead'. It tells the reader a password change is what you do rather than scanning the code. That is the draft's construction, not the FTC's, and it invites the inference that the two are alternatives addressing the same exposure. They are not.
ON THE RECORDOn date currency I want it recorded that I flagged a source dated 2026-08-20 as requiring live re-verification before publication, and that no evidence of such verification appears in this packet. The entire alert rests on that one row. If the date or the page turns out to be wrong, nothing else in the alert survives, and the check as drafted would not have caught it.
ON THE RECORDFinally, I regard the presence of 'ATTENTION: SCAMMERS', 'Send this to any scammer you know' and 'Send this to any monitor you know' in the candidate pools as a signal that something upstream is malfunctioning or has been tampered with. The correct selections were made this time. I do not think that should be treated as evidence the pool is safe.
The sources
Official sourceThat unexpected package you got could be a brushing scam2026-08-20
The FTC describes brushing scams in which unordered packages arrive so a seller can claim delivery and post fake reviews using your name, sometimes with a QR code inside that leads to a phishing site.
Other checks
Published under standing founder pass (A9) — every claim source-mapped by the machine.
▼ What the machine checked
- ✓ Not a community submission.
- ✓ No entity is named.
- ✓ All 5 material sentence(s) map to FTC.
- ✗ anthropic returned "overstated"; groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
- ✓ No audience band is set.
No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-25.
Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.
Phishy? Send it → sharelivefraud.com/squire-it
Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.
Naming a source is not an endorsement, and being named here is not an accusation against any company.
Powered by SquireIt™