惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LINUX DO - 最新话题
NISL@THU
NISL@THU
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Privacy & Cybersecurity Law Blog
Schneier on Security
Schneier on Security
宝玉的分享
宝玉的分享
Cisco Talos Blog
Cisco Talos Blog
Help Net Security
Help Net Security
月光博客
月光博客
V
V2EX
量子位
T
Threat Research - Cisco Blogs
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
Google DeepMind News
Google DeepMind News
P
Privacy International News Feed
S
Secure Thoughts
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
C
CXSECURITY Database RSS Feed - CXSecurity.com
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
Arctic Wolf
S
Schneier on Security
H
Hacker News: Front Page
P
Proofpoint News Feed
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cisco Blogs
G
GRAHAM CLULEY
The Cloudflare Blog
博客园 - Franky
N
News and Events Feed by Topic
TaoSecurity Blog
TaoSecurity Blog
云风的 BLOG
云风的 BLOG
H
Heimdal Security Blog
The GitHub Blog
The GitHub Blog
C
Check Point Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
T
The Blog of Author Tim Ferriss
小众软件
小众软件
Hacker News: Ask HN
Hacker News: Ask HN
T
Tenable Blog
The Last Watchdog
The Last Watchdog
J
Java Code Geeks
T
Troy Hunt's Blog
B
Blog
Blog — PlanetScale
Blog — PlanetScale
腾讯CDC

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition Roblox executors: It’s all fun and games until someone gets hacked DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception Watch out for SVG files booby-trapped with malware Gamaredon X Turla collab Small business, big risk: How SMBs can fight back against ransomware HybridPetya: A Petya/NotPetya copycat comes with a twist Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass Are cybercriminals hacking your systems – or just logging in? Preventing business disruption and building cyber-resilience with MDR Under lock and key: Safeguarding business data with encryption GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes This month in security with Tony Anscombe – August 2025 edition Don’t let “back to school” become “back to bullying”
A brush with online fraud: What are brushing scams and how do I stay safe?
Phil Muncaster · 2025-12-23 · via WeLiveSecurity

Scams

Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow.

23 Dec 2025  •  , 5 min. read

A brush with online fraud: What are brushing scams and how do I stay safe?

Global e-commerce sales are predicted to exceed $6.4 trillion in 2025. And a large share of these will come via marketplaces. But while they ostensibly offer convenience and safety for consumers and expanded reach for businesses, there is a darker side to the industry. In 2024, Amazon alone proactively blocked over 275 million suspected fake reviews, and took “enforcement actions” against thousands of individuals.

This underground industry has grown to the point where everyday consumers might find themselves unwittingly conscripted into the creation of fake reviews. The bottom line is this: if an item turns up at your door that you have no memory of ordering, don’t ignore it. Read on to find out what it could mean.

What’s a brushing scam?

Brushing scams are a type of e-commerce fraud where a seller sends a package to an apparently random person’s address. The item is usually of low value and is not intended as a show of altruism. Rather, it’s an attempt by the seller to fraudulently inflate the product’s rating on e-commerce marketplaces.

It works like this:

  1. A scammer gets hold of a list of names and mailing addresses — typically listed on cybercrime forums after data breaches, or via people search sites. They may even scrape this info from publicly available sources.
  2. The fraudster creates a fake buyer account on an e-commerce platform or marketplace where they sell their products.
  3. The fraudster uses the account to “buy” their product on that platform and ships the product to the victim’s address.
  4. The scammer uses the fake account to post a 5-star review, boosting (or “brushing up”) the item’s reputation and visibility.

The first the victim usually hears about the scam is when they receive the unsolicited parcel.

brushing-scam-example
Source: Reddit

What could it mean?

Why would anyone mind receiving free goods through the post, even if they are cheap and lightweight? It’s not as harmless a scam as it seems. For one thing, the fact that you’re being targeted in a brushing scheme at all could mean that your personal data is being shared on the cybercrime underground. For another, the scammers might be testing your details are correct, in order to move onto a second stage, which involves more serious identity fraud.

There are also more malign versions of the scheme where a QR code is included inside the package you receive. Scanning it will most likely take you to a malicious/phishing site designed to install malware or trick you into sharing more personal information.

Finally, there’s an indirect cost related to such scams. They slowly and insidiously erode the trust consumers place in marketplace/e-commerce review systems.

How do I know if I’ve been victimized?

It shouldn’t take too much effort to work out if you’ve been singled out by brushing scammers. If you receive a low-value, poor quality item in the post that you have no memory of purchasing, this should be an immediate red flag. A vague or missing return address, and a possible QR code inside the package, are also warning signs.

To double check, review your emails and any accounts you have with e-commerce/online marketplace platforms, to look for recently purchased goods. It’s worth also checking your bank accounts and credit reports for suspicious activity, as the scammers may have already moved on to the next stage of the scheme.

What should I do if I receive a package?

If you receive something in the post that you can’t remember ordering, minimize risk by taking the following steps.

  • Double check it’s not a gift by asking your household/friends/family if they’ve ordered anything in your name recently.
  • Don’t scan any QR codes that may be dispatched inside the parcel
  • Check no money has left your bank account and/or new credit lines haven’t been opened in your name
  • Ensure you have multi-factor authentication (MFA) set up on your online banking/credit card accounts
  • Enable MFA on all online shopping and email accounts
  • Report the fraud to the relevant marketplace (eg Amazon). Most should have a dedicated place to report brushing fraud
  • Don’t bother trying to return the item to sender. It’s yours to keep, if you want to

How do I stay safe from brushing scams?

There are steps you can also take to stop brushing scams from even targeting you. It all goes back to what personal data of yours is available to the fraudsters.

Granted, there’s not much you can do if an organization you do business with gets breached, spilling your details. But there are identity protection services you can use which scan the dark web for potentially compromised information. Some of them are available as part of a general home security package. If you find that any accounts have been compromised, change your passwords immediately. It’s also worth putting a credit freeze in place to block any attempts to use your name in order to run up debt on new cards.

As scammers also harvest data from the public web, it’s important to get into good privacy habits. That means minimizing what you share on social media, locking your accounts down so only friends can view your posts, and remove any personal details like home addresses, birthdates and phone numbers.

Finally, reduce the likelihood of scammers getting your details from data brokers, by opting out on “people finder” sites like BeenVerified, Spokeo, and TruthFinder. It will require a bit of work, and you will likely need to revisit these sites every few months to repeat the process, but is worth the extra effort.

Brushing scams are just one of many ways fraudsters weaponize your personal information against you. Unfortunately, mitigating this risk is not a case of “one and done”. You’ll need to maintain continuous vigilance over your digital world. Ultimately, it’s the price we pay for access to the services we love.


Let us keep you
up to date

Sign up for our newsletters