Stanford updates package retrieval system following security concerns

Published Sept. 25, 2026, 12:18 a.m., last updated Sept. 25, 2026, 12:18 a.m.

On Aug. 3, Stanford Mail and Packing Services (MPS) began requiring physical or mobile identity (ID) cards instead of QR codes to retrieve mail and packages. The previously-used QR codes contained only students’ Stanford University Network (SUNet) IDs. This gave potential package thieves the ability to retrieve mail intended for other students if they knew the target’s email address, which is often publicly available.

MPS maintains that the previous system was “consistent with practices implemented at universities across the United States,” the department said in an email statement to The Daily. The University has received no reports of package theft via fraudulent QR codes, spokesperson Luisa Rapport said in a statement to The Daily.

Under the previous mail and package system, QR codes were complemented by a required signature for in-person retrieval and a Personal Identification Number (PIN) code for locker pickups. This system was approved by University Information Technology (UIT) following a data risk assessment, according to Rapport.

“No concerns related to [package theft using QR codes] were identified during the data risk assessment review process or through other approval channels,” Rapport said.

Daniel Richman, a second year Ph.D. student in computer science, said he was surprised to discover the potential vulnerability last November.

“That seems to me to be a way that we’re not comfortable with receiving our mail,” he told The Daily in April. “It feels as though, if [package theft using QR codes] hasn’t happened yet, a large part of the reason may just be because no one has realized that this is the way that it’s set up.”

Richman reached out to MPS last fall to notify them of the concern, according to emails reviewed by The Daily.

In September, Richman said that he was perplexed by the delay in changing the package retrieval system since MPS learned of the issue. “It might have taken them a while to develop a permanent solution for the problem, but they could have applied a temporary fix by simply not accepting the QR codes,” he said. “I think they could have implemented that 15 minutes after they heard about the problem back in November.”

When asked about the possibility of package theft using maliciously generated QR codes, Rapport stressed that this would be against University policy. “This type of behavior is not permitted under Stanford policy and may also violate applicable law,” she wrote.

Kayla Chan '28 is the Vol. 268 Head Copy Editor and the Desk Editor for Local News.

Login or create an account