
FBI Warns Smartphone Users – Avoid QR Scams and Smishing Now
The FBI has issued a series of urgent warnings to smartphone users across the United States, alerting iPhone and Android owners to escalating threats involving app tracking, QR code scams, and smishing text attacks. These warnings come as cybercriminals increasingly exploit the seamless connectivity of mobile devices to harvest personal data, drain bank accounts, and install malware on unsuspecting victims’ phones.
Federal authorities first began documenting these schemes in early 2025, with the Federal Trade Commission issuing alerts in January and the United States Postal Inspection Service following in February. By mid-year, the FBI had taken notice of a troubling evolution in scam tactics that combined physical mail with digital phishing techniques, creating new vulnerabilities for smartphone users who might otherwise consider themselves cautious. The convergence of these attack vectors represents a sophisticated shift in how criminals target everyday consumers through devices they trust most.
Understanding these threats has become essential for anyone who uses a smartphone for banking, shopping, or communication. While law enforcement agencies continue to investigate and prosecute those responsible, experts emphasize that user awareness and preventive measures remain the most effective defense against these increasingly elaborate schemes. The following breakdown provides a comprehensive overview of what federal investigators have uncovered and what steps users should take to protect themselves.
What Is the FBI Warning for Smartphone Users?
Federal investigators have identified three primary threat categories affecting smartphone owners, each employing distinct tactics designed to exploit different user behaviors and expectations. The FBI’s Internet Crime Complaint Center has logged thousands of complaints related to these schemes, with victims reporting losses ranging from hundreds to tens of thousands of dollars. The following overview summarizes the key warning areas that every smartphone user should understand.
Alerts regarding excessive data collection by mobile applications installed on smartphones.
Fraudulent packages containing malicious QR codes designed to steal personal and financial information.
Fake SMS messages impersonating toll authorities, delivery services, and payment processors.
Review and strengthen privacy settings across all installed applications and device systems.
Each of these threat categories has demonstrated measurable impact on victims, with some individuals experiencing unauthorized charges on credit cards while others have had entire bank accounts drained. Criminals behind these schemes typically combine social engineering techniques with readily available technology to create convincing scenarios that trick even vigilant users into revealing sensitive information or clicking malicious links.
Key Insights from FBI Smartphone Warnings
Federal authorities have distilled several critical takeaways from their investigations into these emerging threats. These insights reflect patterns observed across thousands of reported incidents and provide guidance on recognizing and avoiding the most common attack vectors currently targeting smartphone users.
- Never scan QR codes from mystery packages, unsolicited flyers, or public stickers without first verifying the source and previewing the destination URL by long-pressing on mobile devices.
- Delete suspicious text messages immediately if they arrive unexpectedly, contain urgent language demanding action, or request personal information—legitimate organizations do not communicate sensitive matters via SMS.
- Install reputable antivirus and mobile security applications that can block access to malicious websites, detect QR code threats, and alert users to potentially harmful downloads.
- Use official applications and verified websites when managing toll payments, package deliveries, or financial transactions rather than clicking links provided in unsolicited messages.
- Limit online data exposure by utilizing data removal services that reduce the amount of personal information readily available to scammers targeting specific individuals.
- Avoid granting unnecessary permissions to unfamiliar websites or applications, particularly those requesting access to contacts, messages, or device controls.
- Report all incidents to the FBI’s Internet Crime Complaint Center at www.ic3.gov to assist authorities in tracking trends and identifying perpetrators.
These recommendations emerge from documented cases where victims followed instructions contained in fraudulent messages or scanned QR codes from seemingly harmless sources. Investigators have found that even cautious users can fall victim when criminals create convincing scenarios that exploit trust in familiar brands or authorities.
Snapshot of FBI Warnings and Related Scams
| Warning Date | Scam Type | Platform Affected | Source |
|---|---|---|---|
| January 2025 | FTC Alert on Brush Scams | iPhone/Android | FTC Consumer Protection |
| February 2025 | USPS Alert on Mystery Packages | All Smartphones | USPS Inspection Service |
| June 2025 | Smishing Text Scams | iPhone/Android | FBI IC3 |
| Late July 2025 | QR Code Quishing Scams | All Smartphones | FBI Public Warning |
| August 2025 | QR Package Fraud | iPhone/Android | Tom’s Guide Coverage |
| April 2026 | App Tracking Concerns | iPhone/Android | Industry Reporting |
What Is the Latest FBI Warning Today?
Federal investigators have most recently focused their attention on two distinct but related threats: QR code scams delivered through physical mail and smishing attacks transmitted via SMS messages. Both tactics represent evolutions of older fraud schemes that have proven particularly effective against smartphone users who may not expect threats to arrive through multiple channels simultaneously.
How QR Code Scams Work
Criminals have begun mailing unsolicited packages to residential addresses throughout the United States, with each package containing nothing more than a printed QR code and minimal packaging. Recipients find no return address, no sender information, and no explanation beyond a prompt to scan the code for “more information” or to track a delivery they do not remember ordering.
When users scan these QR codes, they are redirected to fraudulent websites designed to mimic legitimate banking portals, credit card login pages, or cryptocurrency exchanges. According to investigators, these fake sites harvest entered credentials directly, allowing criminals immediate access to financial accounts. In other instances, scanning triggers automatic malware installation that tracks device activity, logs keystrokes, or facilitates unauthorized cryptocurrency transfers.
The effectiveness of this approach stems from several factors. Attackers already possess the recipient’s name and address, gathered through data breaches or purchased from illicit marketplaces, which lends credibility to their communications. The physical package creates a tangible connection that many users associate with legitimate deliveries, while the QR code leverages the convenience that makes smartphone scanning so appealing in the first place. This tactic represents a modern variation of brushing scams, where fraudsters ship empty packages to establish fake reviews or delivery confirmations, but has escalated into direct financial theft.
If you receive a package with no return address or sender information containing only a QR code, do not scan it. Legitimate deliveries include tracking information, sender details, and clear delivery confirmation from recognized carriers.
How Smishing Text Attacks Work
Smishing, a portmanteau of SMS and phishing, involves fraudulent text messages designed to trick recipients into believing they owe money, have missed deliveries, or must verify account information urgently. These messages typically impersonate toll road authorities, package delivery services, or payment processors, using language that creates immediate pressure to act without thinking.
Investigators have identified over 10,000 fraudulent domains associated with smishing campaigns, many of which produce remarkably realistic websites that dupe even security-conscious users. The messages direct victims to enter credit card numbers, login credentials, or other sensitive data that criminals then exploit for financial gain or identity theft.
Reports have surfaced from major metropolitan areas including Dallas, Atlanta, Los Angeles, Chicago, Orlando, Houston, San Diego, Phoenix, and Seattle. The geographic spread suggests automated systems capable of targeting large populations simultaneously, selecting phone numbers based on area codes or purchased contact databases. Attack patterns consistently include urgent language demanding immediate payment or verification, links to phony payment or login pages, and malware installation upon submission of requested information.
- Messages claiming unpaid tolls requiring immediate payment to avoid penalties
- Alerts about missed package deliveries needing address confirmation
- Requests to verify account information due to security concerns
- Fake notifications about payment failures for recent purchases
How to Access More Privacy and Security Settings?
Both iPhone and Android devices offer extensive privacy controls that can significantly reduce exposure to the threats outlined in federal warnings. While no setting guarantees complete protection, understanding and implementing available options represents one of the most effective defensive measures available to smartphone users.
Reviewing App Permissions
Applications frequently request access to features beyond their core functionality, including contacts, location data, camera access, and microphone controls. Federal guidance recommends auditing these permissions regularly and revoking access that seems excessive for an application’s stated purpose. A flashlight app, for example, requires no access to contacts or location information, yet many users grant such permissions without examination.
On iPhone devices, navigate to Settings, then Privacy and Security to review permission categories individually. Each application listed under a permission type shows its current access level, with options to allow access while in use, allow once, or deny entirely. Android users find similar controls under Settings, then Privacy and Security Manager, with comparable granularity in permission management.
Limiting Data Collection
Major platform operators have faced increasing scrutiny regarding the extent of data collection performed by default settings. Users who wish to minimize exposure should disable advertising identifiers, limit app activity tracking, and consider whether cloud synchronization services that store sensitive information remotely align with their security priorities.
The FBI has specifically recommended utilizing data removal services that scrub personal information from data broker databases, reducing the likelihood that scammers obtain accurate contact details for targeted attacks. While such services require ongoing subscriptions for comprehensive coverage, the reduced attack surface often proves worthwhile for users concerned about unsolicited contact. The Cybersecurity and Infrastructure Security Agency also provides guidance on minimizing personal data exposure across online platforms.
Enabling Built-in Protections
Both major mobile platforms offer built-in security features that require activation rather than operating by default. These include automatic security updates, which install critical patches as they become available, and safer app installation sources that reduce the likelihood of inadvertently installing malicious software.
Users should ensure that automatic updates remain enabled, that device lock screens require meaningful authentication (PIN, password, fingerprint, or facial recognition), and that any available encryption options are turned on. These baseline protections cost nothing to implement yet provide meaningful barriers against many common attack vectors. The Federal Trade Commission’s consumer resources offer additional recommendations for securing mobile devices against emerging threats.
What Is the Warning About Amazon Account Attackers?
While the FBI’s primary warnings have focused on QR code scams and smishing attacks, investigators have also documented schemes targeting users of major e-commerce platforms. These attacks exploit the trust that customers place in familiar shopping brands, sending communications that appear to originate from legitimate sellers or platform administrators.
Recognizing Account Compromise Attempts
Criminals operating these schemes typically send messages claiming unusual activity on the victim’s account, requesting immediate verification to prevent closure or unauthorized charges. The communications often include links to fake login pages designed to harvest credentials that criminals then use to access genuine accounts, make unauthorized purchases, or sell access to other bad actors.
Federal authorities have noted that these attacks frequently coincide with data breaches at third-party services, as criminals obtain username and password combinations from multiple sources and test them against major platforms where users often reuse credentials. The success rate for such attacks depends largely on whether victims have implemented unique passwords for each service and enabled multi-factor authentication. Organizations like the Better Business Bureau regularly publish alerts about current e-commerce fraud patterns affecting consumers.
Responding to Suspicious Communications
Users who receive unexpected communications regarding account activity should not click included links or call phone numbers provided in the message. Instead, navigate directly to the platform’s website by typing the address manually or using a previously saved bookmark, then log in through standard channels to verify any claimed issues.
Legitimate businesses never request passwords, credit card numbers, or sensitive information via unsolicited messages. Any communication making such requests should be treated as fraudulent and reported to the platform’s abuse team. Users who may have already entered information should immediately change passwords, enable additional authentication factors, and monitor accounts for unauthorized activity.
Always access shopping accounts through official applications or bookmarks rather than links in unexpected messages. Enable two-factor authentication on all accounts that support it, and use unique passwords for each service to limit the impact of any single breach.
Timeline of FBI Smartphone User Warnings
Federal warnings regarding smartphone threats have evolved rapidly over the past eighteen months, with agencies progressively expanding their guidance as new attack patterns emerged. The following timeline documents key milestones in this escalation, illustrating how quickly criminals adapt their tactics and how federal response has tracked alongside these developments.
- January 2025 — The Federal Trade Commission issues initial consumer alerts regarding brushing scams and unsolicited package fraud, warning that recipients should not engage with unexpected deliveries.
- February 2025 — The United States Postal Inspection Service publishes guidance on mystery packages containing promotional materials or QR codes, noting that recipients should verify senders before engaging.
- June 2025 — The FBI’s Internet Crime Complaint Center reports significant increases in smishing complaints, particularly those impersonating toll authorities and delivery services in major metropolitan areas.
- Late July 2025 — The FBI publicly highlights the emergence of quishing (QR phishing) schemes involving physical packages, marking the first federal acknowledgment of this combined attack vector.
- August 2025 — Coverage in technology publications expands public awareness of QR code package scams, with detailed breakdowns of victim experiences and investigative findings.
- April 2026 — Industry reporting surfaces concerns about extensive app tracking practices, prompting renewed focus on privacy settings and data collection controls across mobile platforms.
This progression demonstrates a clear pattern of escalating sophistication, with criminals moving from simple brushing scams to multi-channel attacks that blend physical and digital vectors. Federal agencies have adjusted their guidance accordingly, emphasizing the importance of vigilance across all communication channels rather than focusing exclusively on email-based threats.
Confirmed Facts vs Remaining Uncertainties
Investigators have established clear facts regarding many aspects of these threats, but certain details remain under active investigation or depend on information that authorities have not publicly confirmed. The following comparison helps clarify what is definitively known versus what remains under examination.
| Category | Established Information | Remaining Uncertainties |
|---|---|---|
| Threat Scope | FBI has confirmed thousands of complaints related to smishing and QR scams through IC3. | Total victim count and aggregate financial losses have not been publicly quantified. |
| Attack Origins | Reports indicate domestic victims across multiple major metropolitan areas. | Exact locations where criminals operate remain under investigation. |
| Technical Methods | Over 10,000 fraudulent domains identified in smishing campaigns. | Full technical infrastructure, including hosting providers, remains partially unclear. |
| Victim Impacts | Documented cases show unauthorized charges, identity theft, and drained accounts. | Recovery rates for stolen funds and typical timelines for victim resolution are not publicly available. |
| Prevention Effectiveness | Security researchers confirm that proper settings reduce successful attack rates. | Precise effectiveness percentages for various protective measures have not been independently verified. |
| Law Enforcement Response | FBI has issued public warnings and maintains IC3 reporting portal. | Active investigations, arrests, or prosecutions have not been publicly disclosed. |
Analysis: Why the FBI Is Issuing These Warnings
Federal investigators have intensified public warnings in response to measurable growth in smartphone-related fraud complaints. The FBI’s Internet Crime Complaint Center consistently ranks financial losses from online scams among the largest categories of reported economic harm, and mobile device attacks now represent an increasing share of these overall numbers. The decision to issue public warnings reflects both the scale of victimization and the effectiveness of preventive measures when properly implemented.
The sophistication of current schemes far exceeds earlier iterations, with criminals leveraging automation, purchased databases, and commercially available website templates to create convincing scenarios at minimal cost. This democratization of fraud tools means that even small-scale operations can generate substantial victim pools, while larger enterprises produce correspondingly larger losses. The combination of physical and digital attack vectors specifically targets the assumption that threats arrive through a single channel, catching cautious users off guard when packages and texts arrive in rapid succession.
Investigators have observed that many victims consider themselves security-conscious but nonetheless fall prey to carefully crafted communications that exploit trust in familiar brands, urgency created by fabricated deadlines, and the convenience impulse that makes QR scanning so appealing. Breaking these behavioral patterns requires consistent public education that acknowledges the legitimacy of these impulses while providing clear guidance on verification procedures.
Official Sources and Reporting Guidance
Federal authorities have established clear channels for reporting incidents and obtaining authoritative guidance. The FBI’s Internet Crime Complaint Center serves as the primary portal for submitting complaints related to online fraud, including smartphone-based scams. This information contributes to aggregate threat assessments and supports ongoing investigations that may not result in immediate prosecutions but contribute to larger enforcement efforts.
The FTC maintains consumer protection resources that complement federal law enforcement efforts, providing practical guidance on recognizing and avoiding common schemes. For seniors specifically, the Department of Justice operates the Elder Justice Hotline at 1-833-FRAUD-11, offering dedicated support for older adults who may require additional assistance navigating fraud situations or recovering from victimization.
“Report all incidents to the FBI’s Internet Crime Complaint Center at www.ic3.gov for all incidents involving smartphone scams, data theft, or financial fraud. This centralized reporting helps authorities track emerging threats and identify patterns across geographic regions.”
Additional reporting mechanisms include forwarding suspicious text messages to 7726 (SPAM), which alerts mobile carriers to potentially fraudulent senders. Victims who may have entered financial information should immediately contact their banks to place alerts on accounts, change passwords on potentially compromised services, and monitor credit reports for unauthorized activity.
What Smartphone Users Should Do Next
The convergence of multiple threat vectors targeting smartphone users demands a comprehensive response that addresses behavioral habits, device settings, and awareness of current scam tactics. Federal authorities recommend a multi-layered approach that begins with immediate actions and continues through ongoing vigilance practices. Those who use mobile devices for financial management, shopping, or communication should treat these recommendations as essential maintenance rather than optional enhancements.
Begin by reviewing app permissions on your device and removing any access that seems excessive for the application’s purpose. Check that automatic security updates are enabled, that your lock screen requires meaningful authentication, and that any available encryption options are turned on. Delete suspicious text messages without clicking included links, and report smishing attempts to your carrier by forwarding to 7726. For more detailed guidance on securing your personal information and devices, consult additional resources on smartphone privacy practices. Staying informed about emerging threats and sharing prevention knowledge with friends and family creates community resilience against these sophisticated schemes.
Frequently Asked Questions
What should I do if I already scanned a QR code from a mystery package?
If you scanned a suspicious QR code, immediately disconnect your device from the internet, run a full security scan using updated antivirus software, change passwords for any accounts you accessed recently, and monitor your financial statements for unauthorized transactions. Consider placing fraud alerts on your credit reports.
How can I tell if a text message is a smishing attack?
Smishing messages typically contain urgent language demanding immediate action, include links to unfamiliar websites, request personal or financial information, and claim to represent legitimate organizations without providing verifiable contact details. When in doubt, contact the claimed sender through official channels rather than responding to the message.
Where should I report smartphone scam incidents?
Report all incidents to the FBI’s Internet Crime Complaint Center at www.ic3.gov. For smishing specifically, forward the message to 7726 to alert your carrier. If money was stolen, also contact your local FBI field office and your bank’s fraud department.
Can mobile security apps actually prevent these attacks?
Reputable mobile security applications can block access to known malicious websites, detect malware infections, and alert users to potentially harmful downloads. However, no application provides complete protection, making user vigilance and safe browsing habits equally important components of any security strategy.
Are iPhone users less vulnerable than Android users?
Both platforms have documented vulnerabilities and both have received FBI warnings regarding these specific threats. While certain security features differ between platforms, the fundamental advice about avoiding suspicious QR codes, deleting unknown texts, and reviewing app permissions applies equally regardless of which operating system users prefer.
How do criminals obtain my address for mystery package scams?
Address information circulates through data breaches, illicit data broker marketplaces, and information volunteered through online forms, loyalty programs, or social media. Using data removal services and limiting publicly shared personal information reduces exposure but cannot guarantee complete privacy given the complexity of modern data flows.
What recovery options exist for victims of these scams?
Victims should immediately contact their financial institutions to attempt charge reversals or account freezes, place fraud alerts with credit bureaus, file reports with the FBI’s IC3 and local law enforcement, and consider credit monitoring services. Recovery success varies depending on how quickly action is taken and the methods criminals employed.