Two scripts are surging together: a fake shipping label text (“Your USPS / UPS / FedEx package needs a $1.90 label fee—scan this QR”) and a QR payment poster or flyer that quietly points to the scammer’s checkout, not the store’s. Both steal card data, credentials, or small “fees” that unlock bigger account takeovers.
Broader shipping and invoice fraud: Fake shipping and invoice scams. Login theft patterns: Phishing and account takeover. Alert spoofs that harvest logins the same way: Fake bank and brokerage alerts.
How the shipping-label script works
| Step you see | What is actually happening |
|---|---|
| Text: “Package held—pay postage / relabel” | Spoofed USPS, UPS, Amazon, or “local depot” branding |
| Link or QR to a payment page | Lookalike domain harvests card + address + sometimes SSN “for customs” |
| Small fee ($1.90–$9.99) | Tests the card; then friendly-fraud or card-not-present charges follow |
| “Print your label” PDF | Sometimes malware or a useless image; fee already taken |
Real carriers collect postage inside their official apps and sites (usps.com, ups.com, fedex.com) that you type—never from a random SMS QR. Amazon and big retailers show tracking inside the account you already use.
QR payment and “park-and-scan” tells
- Stickers placed over real parking-meter, EV-charger, or restaurant QR codes
- Flyer QR promising a “refund label” or “customs clearance”
- QR that opens a shortened link (bit.ly-style) to a card form with bad TLS or odd URLs
- Requests for gift cards, Apple Cash, or Crypto to “release” a package Gift cards and prepaid debit risks
- Urgency: “Label expires in 2 hours—package returned to sender”
Landscape of related fraud: Credit and debt scams.
Worked example
Morgan gets a text: “UPS: Delivery exception. Pay $2.95 to generate a new shipping label.” A QR in the message opens ups-label-secure.com (not ups.com) and asks for name, card, and “customs ID.”
Morgan does not pay. Morgan opens the real UPS app, finds no exception, and deletes the text. Morgan also checks the porch camera: no failed delivery that day. No card shared; no second loss.
If Morgan had paid, next steps would be: call the number on the back of the card, freeze/replace the card, watch statements, and dispute unauthorized charges Disputing a credit card charge. Report at ReportFraud.ftc.gov.
Hard rules
- Never scan a QR from an unsolicited shipping text.
- Type carrier and retailer URLs yourself or use the official app.
- Treat “tiny postage fees” as a card-testing red flag.
- Inspect physical QR stickers for overlays before paying for parking or charging.
- Do not pay package problems with gift cards or crypto.
- If you already entered a card, contact the issuer the same day.
Checklist
- Verify tracking only inside official apps or bookmarked sites.
- Reject SMS/email QR codes that demand postage or label fees.
- Peek under parking/charger QR stickers when something looks newly pasted.
- Use credit cards over debit for any online fee you did intend to pay (stronger dispute rights).
- Save screenshots of scam texts for the FTC and your bank.
- Warn household members who accept porch packages for you.
Street parking-meter and lot QR sticker overlays (not shipping texts): Fake QR code parking scams.
Marketplace seller scripts that swap buyer-supplied Mercari labels: Fake Mercari shipping-label scams.
Facebook Marketplace shipping / fake tracking cousins that push off-app payment: Fake Facebook Marketplace shipping scams.
Educational only. Not legal or fraud-recovery advice. Scam tactics change. Verify contacts through official apps and statements and report fraud to the FTC and your financial institution.