An unexpected package from an unknown sender arrives in your name. You open it and find a note that says it’s a gift, but it doesn't say who sent it. The note also says to scan a QR code to find out who sent it — or to get instructions on how to return it. Did someone really send you a gift? Or is it an attempt to steal your personal information?

If you know it’s really a gift, you can keep it. But know that the unexpected package could be a new twist on a brushing scam that could steal your personal information.

If you scan the QR code, it could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords. It could also download malware onto your phone and give hackers access to your device.

If you scanned the QR code and entered your credentials, like your username and password, into a website, change your password right away. Create a strong password that is hard to guess, and turn on two-factor authentication.

If you’re concerned someone has your personal information, get your free credit report at AnnualCreditReport.com. Look for signs that someone is using your information, like accounts in your name you don’t recognize. (You can get a free credit report every week.)

Also review your credit card bills and bank account statements and look for transactions you didn’t make. And consider taking other steps to protect your identity, like freezing your credit or putting a fraud alert on your credit report.

If you think someone stole your identity, report it, and get a personal recovery plan at IdentityTheft.gov.

What else can you do to protect your personal information? Regularly update your computer software and your phone to get the latest security patches. And learn to recognize a phishing email or text message.

And what about the package? The law says you can keep it as a gift.