What Should You Do If You Receive a Package or Purchase Confirmation for an Order You Did Not Make?

Getting a package or a purchase confirmation for something you never ordered can be unsettling. Sometimes it’s a harmless “brushing” scam where a seller ships low-value items to create fake “verified” reviews. Other times, it signals account takeover, stolen card activity, or exposure of your personal information in a data breach. This step-by-step guide shows you how to figure out what’s going on, stop any fraud quickly, and reduce the odds it happens again.

First, Identify What You Actually Received

Start by separating the facts. Your next steps depend on whether money was charged, which account was used, and where the item came from.

  • Did you get a shipping notice or a purchase confirmation? Check if the message is legitimate by hovering over the sender’s email address, inspecting the domain, and avoiding any links. If it’s a text, don’t click short links. Go directly to the retailer’s website or app instead.
  • Were you charged? Review recent credit card and bank transactions for any unknown charges. If you see an unfamiliar charge, note the date, amount, merchant, and last four digits of the card used.
  • Is the package addressed to you? Look at the shipping label for the sender, marketplace, and order ID. Keep the packaging and packing slip for reference.
  • Do you have an account with that retailer or marketplace? If yes, log in directly (do not use links in emails) and review recent orders, addresses, payment methods, and sign-in history.

Quick-Action Decision Tree

Use this simple flow to choose your immediate next step:

  • Case A: You see a charge you don’t recognize.
    • Call the card issuer’s number on the back of your card to dispute the charge and request a new card number.
    • Change the password on the retailer account (and email account) and enable multi-factor authentication (MFA).
    • Check shipping addresses, payment methods, and saved cards in that retailer account for unfamiliar details and remove them.
  • Case B: No charge appears, but the order shows up in your retailer account.
    • Change the account password and enable MFA immediately.
    • Remove unknown addresses, devices, and payment methods; sign out of all sessions.
    • Contact the retailer’s support to cancel any pending shipments and to flag unauthorized activity.
  • Case C: No charge appears and the order is not in any of your accounts.
    • This is likely a brushing scam or a mis-shipment. Do not pay return postage or provide personal information to “return” it.
    • Report the suspicious shipment to the marketplace or carrier using the order or tracking number on the label.
    • Monitor your financial accounts and credit for a few weeks to be safe.

How to Handle Each Scenario Safely

If It’s a Likely Brushing Scam

In a brushing scam, a third-party seller sends low-value items to real addresses so they can post fake “verified purchase” reviews using your name and address. Your payment method typically isn’t used, but your address may have been scraped from data brokers or public records.

  • Don’t return items to unknown senders. You’re not obligated to pay return shipping for unsolicited goods.
  • Report the incident through the marketplace’s fraud or seller-abuse portal, attaching photos of labels and packing slips.
  • Search for your name on the marketplace to see if a fake review was posted under your profile and report it for removal.
  • Reduce address exposure by opting out of common data brokers and removing old listings where possible.

If It Looks Like Account Takeover

Signs include password reset emails you didn’t request, unfamiliar devices or locations in your account history, and orders placed or canceled without your knowledge.

  • Secure the account: change the password to a unique 16+ character passphrase, turn on MFA (preferably an authenticator app), and sign out of all devices.
  • Audit the account: remove unknown payment methods and addresses; set alerts for new logins, orders, and changes to security settings.
  • Check your email security: if attackers control your email, they can reset other accounts. Change your email password and enable MFA there as well.
  • Contact support to lock the account if necessary and to reverse fraudulent orders.

If It Involves a Stolen Card or Bank Account

If there’s an unfamiliar charge, act fast—card issuers typically offer stronger protections when you report unauthorized transactions promptly.

  • Call the issuer right away using the number on the card or statement; dispute the charge and request a replacement number.
  • Review recent transactions for more unauthorized activity and set up real-time transaction alerts.
  • Update autopay accounts that use the compromised card once you receive the new number.
  • File a report with the retailer or marketplace to aid their fraud investigation.

Don’t Get Hooked by Confirmation Phishing

Scammers often send fake “order confirmations” or “failed delivery” notices to get you to click a link and enter credentials or card data.

  • Verify through the source: Ignore links in messages; open the retailer’s official app or type the site manually.
  • Check sender details: Look for off-domain emails, spelling errors, and urgent language.
  • Never provide codes: No retailer needs your MFA code via phone, text, or email.
  • Use a masked email or unique aliases for shopping accounts so phishing stands out when it hits the wrong inbox.

Document Everything

Good notes make disputes easier and help you spot patterns if this happens again.

  • Keep the email headers, tracking numbers, photos of the label, and any chat transcripts with support.
  • Write down dates, times, and representatives’ names when you call your bank or a retailer.
  • If losses occurred, consider filing an identity theft report with your local authorities or the appropriate federal complaint portal to create a paper trail.

Strengthen Your Privacy and Reduce Future Risk

Unexpected orders often trace back to exposed personal information, weak passwords reused across sites, or prior data breaches. These steps lower your exposure and make you a harder target.

  • Use unique passwords and MFA everywhere: A password manager makes this practical.
  • Enable purchase, login, and password-change alerts across major retailers and your email provider.
  • Review saved payment methods in retailer accounts and remove any you no longer use.
  • Opt out of data brokers to reduce the spread of your name, addresses, phone numbers, and relatives’ links that can be exploited.
  • Freeze your credit with the three major bureaus to block new-account fraud, and add fraud alerts if you suspect identity misuse.
  • Monitor your financial identity: Keep an eye on credit reports, dark web breach alerts, and high-risk changes to your accounts.

When to Involve the Retailer, Carrier, or Authorities

  • Retailer or marketplace: Unauthorized orders, account takeover, fake reviews, or brushing scams tied to a seller.
  • Shipping carrier: Packages with altered labels, suspicious return addresses, or repeat deliveries you didn’t authorize.
  • Card issuer or bank: Any unauthorized charges, even small “test” transactions.
  • Local authorities: Packages containing restricted items, threats, or evidence of targeted harassment.

Red Flags That Deserve Extra Attention

  • Multiple small charges from unfamiliar merchants within days of each other.
  • Account recovery emails you didn’t request or new-device login notices.
  • Shipping address changes or added payment methods you don’t recognize.
  • Orders shipping to pick-up lockers or different regions than your own.
  • Notifications that your return or refund was processed for an order you never made.

Frequently Asked Questions

Do I have to return an unsolicited package?

If you truly did not order it and were not charged, you generally are not required to pay for return shipping. Be cautious about instructions from unknown senders that request payment or personal information to process a return.

Could this be caused by a data breach?

Yes. Breached emails and passwords enable account takeover, while exposed addresses can enable brushing. If you suspect a breach, change passwords and enable MFA on all high-value accounts and monitor for unusual activity.

Is it safe to open the package?

For ordinary retail shipments, the risk is typically low, but inspect the label and sender first. If the package appears tampered with, contains unknown substances, or looks suspicious, do not open it and contact local authorities if necessary.

What if a family member placed the order?

It happens. Check with household members who might share accounts or cards. Still review account security settings to ensure nothing else is amiss.

Related Learning

Optional Next Step

If you want a simple way to watch for unfamiliar accounts, changes, and transaction activity connected to your financial identity, consider evaluating a credit and identity monitoring service. You can review an option here: SmartCredit for privacy, credit monitoring, and identity protection.

Conclusion

An unexpected package or purchase confirmation is a signal to pause and verify. Confirm whether a charge exists, secure any affected accounts, and work through the appropriate channel—retailer, card issuer, or marketplace—based on what you find. Treat suspicious confirmations as potential phishing, maintain good documentation, and strengthen privacy fundamentals like unique passwords, MFA, data-broker opt-outs, and credit freezes. With fast action and a few ongoing safeguards, you can resolve the incident and dramatically cut the risk of repeat surprises.

Good to Know

An unexpected package can be part of a “brushing” scam that uses your address to post fake reviews, but it can also signal account takeover or stolen payment cards. Your next steps depend on whether you were charged and whether the item came from an account you own.