
A new “free phone” scam is making the rounds, and it adds a stranger twist to an already crowded category of mobile fraud. Instead of stealing a handset you ordered, the scam places an unexpected phone on your doorstep in the hope that you’ll power it up, enter personal details, and hand scammers the very information they need to take over accounts or steal identities.
The latest twist on an old trick
“Free phone” scams have been around for years, but the newest version reported by CNET is notably devious. In the classic version, a scammer impersonates a victim to a mobile carrier, orders a replacement phone, and waits for the device to be delivered. Because the scammer knows when the package is coming, they can try to intercept it near the victim’s home before the real owner gets to it.
That makes it a form of porch piracy with an advance warning: the scammer already knows what’s in the box and when it will arrive. In that scenario, the criminal ends up with the “free” phone, while the victim has to deal with the carrier and the fallout from an account compromise.
How scammers have exploited deliveries before
Another long-running version of the scam targets people who have actually ordered a phone themselves. The victim receives a call that appears to be from the company supplying the device, with the caller claiming the wrong phone was sent by mistake. The customer is then instructed to return it. In reality, the victim is sending their brand-new handset to the scammer.
Both versions depend on trust, urgency, and the assumption that a delivery-related problem should be handled quickly. That pressure can cause people to ignore warning signs and comply without verifying the request through official channels.
What makes the newest scam different
The newer version described by CNET does not require the scammer to steal your money to buy the phone in the first place. Instead, a package addressed to you arrives containing a phone you never ordered. The aim is to convince the recipient that they have been lucky enough to receive a surprise device and should activate it.
That is where the trap begins. According to the report, the phone is designed to collect personal data during setup. Once the victim enters information and completes activation, the device can lock up, freeze, or go dark. The result is a useless phone for the recipient and potentially valuable personal information for the scammer.
Why these scams work
Scams involving phones are effective because phones sit at the center of modern digital life. They are tied to bank accounts, identity verification, email access, messaging apps, and two-factor authentication systems. A scam that gets control of a phone number or persuades someone to disclose setup credentials can quickly become a much larger security incident.
In addition, many people are conditioned to view a new device as valuable and urgent. A package that appears to be a bonus, replacement, or mistake can prompt someone to act first and verify later. Scammers exploit that instinct by creating a situation where the safest response feels wasteful or overly cautious.
Expert advice: don’t interact with unexpected devices
CNET cites expert guidance that is simple but important: if you receive an unexpected package containing a phone or other electronics, do not engage with the contents.
That means avoiding actions that can expose your information or device to compromise. As quoted in the report:
“Engaging means plugging it in, powering it on, scanning a QR code or inserting a SIM card,” Coughlin says. “Any one of those can hand a scammer access to your accounts, your identity, or your phone number.”
Coughlin also warned that some devices may be preloaded with malware, while others may be used to route fraudulent activity through the victim’s name or to send them to credential-stealing pages via QR codes. His advice is blunt:
“We’ve seen cheap phones preloaded with malware, SIM cards designed to route fraudulent activity through your name and QR codes that drop credential-stealing pages on your device the second you scan them. So leave it alone.”
How to reduce your risk
While the latest scam is unusual, the defenses are familiar. Consumers can reduce the odds of being hit by taking a few basic precautions:
- Use 2FA protections on your mobile account wherever available.
- Do the same on other accounts that support two-factor authentication.
- Be suspicious of unexpected packages, especially electronics you never ordered.
- Never activate, scan, insert, or connect a device just because it arrived in your name.
- Verify any return or replacement request directly through the company’s official support channels.
The broader lesson is that a package arriving at your door is not proof that the item is yours to use. If you did not order it, the safest path is to set it aside and avoid interacting with it until you can confirm what it is and who sent it.
A crowded scam landscape
Phone-related scams continue to evolve because they can be scaled, disguised, and timed around ordinary delivery habits. The latest variation is especially effective because it doesn’t rely on a stolen order or a stolen card. Instead, it attempts to turn curiosity and convenience into a data harvest.
For consumers, that means the “free phone” you didn’t buy could cost far more than the device itself if you treat it like a legitimate gift. In a scam ecosystem full of fake replacement calls, porch interception, and bogus deliveries, this is another reminder that not every surprise package is a win.
Source: Original report
Was this helpful?
Last Modified: July 7, 2026 at 9:26 pm
3 views

![Hackers tricked Instagram AI into letting them take over 20,000 accounts [U] 3 hackers tricked instagram ai into letting them](https://www.hashe.com/wp-content/smush-webp/2026/06/Hackers-tricked-Meta-AI-into-letting-them-take-over-high-profile-accounts.jpg.webp)