News

Fraudsters Are Using Vacant Homes to Steal Your Mail. Here’s the Full Playbook.

Fraudsters Are Using Vacant Homes to Steal Your Mail. Here's the Full Playbook.

Threat actors are identifying vacant homes using platforms like Zillow and Rightmove, registering for USPS Informed Delivery at those addresses to monitor incoming mail digitally, then filing Change of Address requests to forward victims’ mail, including credit cards, bank statements, and verification letters, to addresses under their control. Mail theft reports rose 139% between 2019 and 2023. Check fraud linked to mail schemes costs hundreds of millions annually. Tutorials on this technique are being sold on dark web markets and shared freely on Telegram.

You don’t have to be a hacking target for someone to intercept your financial mail. You just need to have recently moved, be going on an extended holiday, or have your address appear in one of 2026’s many data breaches, and the people circulating fraud tutorials on Telegram will do the rest from their keyboards.

A step-by-step tutorial circulating across fraud-focused Telegram channels, analysed by dark web intelligence firm Flare and reported through BleepingComputer, reveals how criminals are turning empty residential properties into interception points for sensitive mail. The method requires no hacking, no malware, and no technical expertise. It relies entirely on legitimate services used in the wrong sequence.

How the Attack Works, Step by Step

Step one: Find an empty home.

The tutorial instructs buyers to search rental listing platforms, specifically Zillow, Rightmove, and Zoopla, filtering for recently listed properties. A newly listed rental is often vacant and between tenants. Older listings that have sat on the market for months are even better candidates because they’re more likely to have remained unoccupied.

Some actors go further. The tutorial recommends physically maintaining the appearance of an occupied property, mowing the lawn, checking for accumulated flyers, to avoid drawing attention while using the address as a collection point. This isn’t sophisticated. It’s just careful.

Step two: Sign up for mail monitoring.

USPS Informed Delivery is a free service that emails users daily previews of their incoming letter-sized mail and tracks packages. Legitimate users sign up so they know what’s arriving. Fraudsters sign up at a vacant address they don’t own so they know what’s arriving there, without ever touching the mailbox.

This is the intelligence-gathering phase. An attacker who can see that a credit card, a bank statement, or a tax document is incoming to an address they’re watching knows exactly when to act and what to look for.

Step three: Redirect the mail.

USPS allows users to submit Change of Address requests online. Permanent or temporary forwarding can redirect all incoming mail from one address to another for periods of several weeks up to 12 months. Premium Forwarding consolidates and redirects on a recurring schedule.

The tutorial acknowledges that these services include verification steps, a small online payment tied to a billing address, or in-person identity presentation. But it frames these controls as “potentially insufficient or inconsistently enforced,” particularly when the attacker has access to fabricated identity documents or purchased personal data. The ability to submit forwarding requests remotely, with address-linked rather than identity-bound verification, is what creates the opening.

Step four: Set up persistent access.

Once mail is being forwarded, attackers establish personal mailbox accounts in fake names to maintain long-term redirection. To pass identity verification for these services, they use Credit Privacy Numbers (CPNs), nine-digit numbers marketed fraudulently as legal “alternative SSNs”, or purchased identity documents sourced from dark web credential markets.

Once forwarding is in place, the attacker no longer needs to visit the physical address. Everything arrives to them.

Where the Physical World Meets the Digital Underground

This attack belongs to a growing category that security researchers call hybrid cybercrime: schemes that blend digital reconnaissance with physical-world access in ways that defeat purely digital security controls.

A tutorial for this specific method is being sold on underground dark web markets, including Mist Market. Free versions circulate on Telegram channels. Some are paid, some are free, but they’re widely available, which means the technique isn’t limited to one sophisticated group. Anyone willing to follow instructions can run it.

The physical component is often outsourced. Some tutorials describe recruiting individuals, sometimes from vulnerable populations, to physically collect mail from drop locations, distancing the operator from the physical crime entirely. This mirrors the mule recruitment networks used in financial fraud to cash out stolen funds. As we covered in our breakdown of how the dark web carding economy operates, criminal operations increasingly outsource their riskiest physical steps to recruited intermediaries. At the same time, they coordinate the fraud remotely.

How Big Is This Problem?

USPIS-published data show mail theft from mail receptacles rose 139% between 2019 and 2023. The agency links mail theft schemes to hundreds of millions of dollars in check fraud-related suspicious activity annually.

Change-of-address fraud has been growing sharply year over year, though postal services haven’t published centralized figures that isolate COA fraud from legitimate COA submissions. The fraud tutorials themselves make it clear that practitioners are actively adapting to detection. Flare’s analysis notes that financial institutions are increasingly flagging virtual addresses and commonly reused locations, so attackers specifically seek “clean” residential addresses with no prior fraud history.

This technique connects directly to the synthetic identity fraud supply chain we covered in detail. A full fake identity package costs around $200 on dark web markets. CPNs, the fake SSN substitutes used to set up mailbox accounts in this scheme, are a standard component of those packages. The mail intercept technique connects those synthetic identities to real financial correspondence: once you can redirect a real person’s mail to a fake identity’s mailbox, you can intercept credit cards, account verification letters, and two-factor authentication documents.

Who Is Most at Risk

Your address appearing in a data breach is now a direct fraud risk beyond the usual phishing and identity theft concerns. The 153 million driver’s licenses exposed through IDScan.net included home addresses. The CenterPoint Energy breach exposed service and billing addresses for millions of utility customers. Any of those addresses can now be cross-referenced with property listing platforms to determine whether it has recently become vacant.

People who have recently moved are at elevated risk during the window between vacating and settling in, when the previous address may briefly be empty and the new one not yet fully established as the mailing point. Landlords with properties between tenants face the same exposure window.

What You Can Actually Do

Register for Informed Delivery at your own address. Go to informeddelivery.usps.com and register yourself. If someone has already done it for your address, USPS will flag the duplicate registration attempt. If you’re already registered and receiving the daily previews, you also get immediate visibility if something you expect doesn’t arrive.

Set up mail forwarding alerts. USPS sends a physical notification to your address when someone files a change-of-address request for it. If you receive a confirmation notice for a COA request you didn’t make, call USPS at 1-800-275-8777 immediately and report it to the US Postal Inspection Service.

Request a mail hold when you travel. USPS Hold Mail prevents mail from accumulating at a vacant address during extended absences. The local post office holds deliveries and releases them when you return.

If you recently moved, file your own Change of Address immediately rather than waiting. Fraudsters look for the gap between when you vacate and when forwarding is established.

If your address has been in a breach, treat it as a targeted risk. Our guide on what to do when your personal data is on the dark web covers the broader checklist, but adding proactive mail monitoring is a specific step that rarely appears in standard breach response advice.

If you suspect mail fraud is already happening, file a report with the USPIS at postalinspectors.uspis.gov and the FTC at reportfraud.ftc.gov.

The Broader Shift

This case is part of a 2026 pattern: attackers are increasingly exploiting gaps between digital and physical security systems. The SilentRansomGroup physically walked into law firm offices posing as IT support to steal data. Dark web drug networks shipped product through Canada Post. Now fraud playbooks teach criminals to exploit postal services the same way supply chain attackers exploit software pipelines: by targeting the most trusted, least-monitored layer.

The attack surface has expanded beyond screens and servers. It now includes the mailbox at the end of your driveway.

Frequently Asked Questions

What is a drop address?

A vacant residential property fraudsters use to receive redirected mail from victims, either by intercepting it directly or by filing change-of-address requests to forward it to a controlled location.

What is USPS Informed Delivery and can it be abused?

Yes. It’s a legitimate free service that emails daily previews of incoming mail. Fraudsters register for it at vacant homes to monitor what’s arriving before physically intercepting it.

How do criminals bypass COA verification?

By using fabricated identities, Credit Privacy Numbers (CPNs), or purchased personal data from breach markets. The address-linked rather than identity-bound verification creates the opening.

Who is specifically at risk?

People who recently moved, whose addresses appear in data breaches, or whose properties are temporarily vacant are at elevated risk.

What should I do immediately?

Register for USPS Informed Delivery at your own address, file your own COA when you move, and report any unexpected COA confirmation notices to USPS immediately.

Muhammad Anas

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

πŸ“‹ Latest Articles

View all →
Is your Social Security number on the dark web?
Monitoring

Is Your Social Security Number on the Dark Web?

If you just got an alert saying your Social Security number showed up on the dark web, take…

Sep 22, 2026
6 min read
ShinyHunters hacks cl0p ransomware
News

ShinyHunters Didn’t Just Deface Cl0p’s Site. They Took the Keys to It.

ShinyHunters breached cl0p’s dark web leak site on September 19, 2026, by exploiting an unauthenticated file upload vulnerability…

Sep 21, 2026
6 min read
How to Use Ahmia Search Engine
Guides

How to Use Ahmia Search Engine: A Safe, Step-by-Step Guide

Most search engines can’t see the Tor network at all. Google doesn’t index .onion sites, and neither does…

Sep 21, 2026
7 min read
ShinyHunters Just Hijacked Cl0p's Dark Web Site
News

ShinyHunters Just Hijacked Cl0p’s Dark Web Site. Here’s the Beef Behind It.

When criminals fall out, they don’t call lawyers. They go after each other’s infrastructure. On September 19, 2026,…

Sep 21, 2026
4 min read
News

South Cotabato School Shooter Was β€˜Heavily’ Into Deep Dark Web, DILG Says

The deadly shooting at Banga National High School in South Cotabato, Philippines, has taken a new turn after…

Sep 19, 2026
6 min read
Telegram Credential Leak Channels
Data Breaches

Top 5 Telegram Credential Leak Channels: How Stolen Logins Are Traded

Telegram is no longer just a messaging app for chatting and sharing files. Security researchers have found that…

Sep 18, 2026
5 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted