Full Report
Threat actors are exploiting vacant homes as "drop addresses" to intercept mail and enable fraud. Flare shows how postal services and fake identities are abused to turn mail into a fraud vector. [...]
Analysis Summary
# Tool/Technique: Vacant Property "Drop Address" Interception
## Overview
This technique is a hybrid cyber-physical fraud methodology where threat actors identify and exploit vacant residential properties to serve as "drop addresses." By abusing legitimate postal services and digital monitoring tools, adversaries intercept sensitive physical mail—such as credit cards, financial statements, and government IDs—to facilitate identity theft and financial fraud.
## Technical Details
- **Type**: Technique (Hybrid Cyber/Physical Fraud)
- **Platform**: Physical infrastructure (residential addresses) and USPS/Postal digital services (Informed Delivery)
- **Capabilities**: OSINT-based property scouting, remote mail monitoring, fraudulent mail redirection.
- **First Seen**: Reported by Flare in April 2026 (based on Telegram-circulated tutorials).
## MITRE ATT&CK Mapping
- **[TA0043 - Reconnaissance]**
- **[T1594 - Search Open Public Technical Databases]**: Using real estate platforms (Zillow, Zoopla) to identify vacant properties.
- **[TA0001 - Persistence]**
- **[T1133 - External Remote Services]**: Abusing postal "Informed Delivery" or Change of Address (COA) web portals to maintain visibility over a physical location.
- **[TA0006 - Credential Access]**
- **[T1555 - Credentials from Password Stores]**: intercepting physical mail containing temporary PINs, new credit cards, or NRC (Non-Resident Correspondence).
## Functionality
### Core Capabilities
- **Property Scouting (OSINT)**: Utilizing real estate listing sites to filters for "recently listed" or "long-term vacant" rentals to ensure a low risk of occupant interference.
- **Remote Surveillance**: Registering for services like **Informed Delivery** using the target address to receive digital scans of incoming mail daily via email.
- **Mail Redirection**: Exploiting weak identity verification in Change of Address (COA) or Premium Forwarding services to reroute mail from a victim's actual residence to the controlled "drop address."
### Advanced Features
- **Physical Camouflage**: Threat actors may physically "maintain" the yard or appearance of an abandoned home to avoid suspicion from neighbors or law enforcement.
- **Verification Bypass**: Using stolen PII (Personally Identifiable Information) or burner credit cards to satisfy the small-fee identity verification required by postal services for digital registration.
## Indicators of Compromise
- **File Names**: Fraud "playbooks" or tutorials circulated on Telegram (e.g., "Drop Address Tutorial.pdf").
- **Network Indicators**:
- `zillow[.]com` (Abused for Reconnaissance)
- `zoopla[.]co[.]uk` (Abused for Reconnaissance)
- `usps[.]com` (Targeted for feature abuse)
- **Behavioral Indicators**:
- Multiple Informed Delivery accounts registered to a single IP address with different surnames.
- Frequent Change of Address (COA) requests originating from non-residential or VPN/Tor exit nodes.
- Physical observation of mail reaching a home listed as "vacant" or "under renovation."
## Associated Threat Actors
- **Cyber-Sourced Fraud Groups**: Specifically actors active on Telegram channels and Dark Web forums focused on "carding" and identity theft.
## Detection Methods
- **Behavioral Detection**:
- Postal services monitoring for high volumes of Informed Delivery registrations from specific IP ranges.
- Real estate platforms detecting automated scraping or high-frequency filtering of rental listings in specific geolocations.
- Financial institutions flagging "new account" applications where the address matches a "Recently Listed" rental on OSINT sites.
- **Physical Detection**: Neighbors or real estate agents noting mail accumulation or unauthorized persons "maintaining" vacant lots.
## Mitigation Strategies
- **Prevention Measures**: Implementing "Strong ID Binding" for postal services, such as requiring in-person identity verification at a post office for all Change of Address or digital mail requests.
- **Hardening Recommendations**:
- Homeowners should proactively register for Informed Delivery for their own properties to prevent attackers from claiming the address first.
- Real estate platforms can implement CAPTCHAs or rate-limiting to prevent bulk scouting of vacant properties by bad actors.
## Related Tools/Techniques
- **Carding**: The practice of using stolen credit card information.
- **Synthetic Identity Fraud**: Creating new identities using a mix of real and fake information, often requiring a physical address for document delivery.
- **Mule Accounts**: Using third-party addresses or individuals to move illicit goods or funds.