Bleeping Computer reports that a new fraud tutorial circulating in online chat groups details how threat actors are exploiting legitimate services and real-world infrastructure to conduct identity theft and financial fraud. This method moves beyond traditional cybercrime, focusing on abusing postal services and vacant properties to intercept sensitive mail.The tutorial, analyzed by Flare, outlines a low-cost, difficult-to-detect workflow that begins with identifying vacant residential properties, often found by searching real estate listings for recently rented or long-term unoccupied homes. Threat actors then use legitimate postal services like USPS Informed Delivery to remotely monitor incoming mail, identifying valuable documents such as financial statements or credit cards. The process escalates by submitting change-of-address requests, sometimes using fake identities or forged documents, to redirect mail to a location controlled by the fraudster. This hybrid model blends open-source intelligence, physical property exploitation, and digital manipulation to gain persistent access to victims' mail and sensitive information.This evolving fraud tactic highlights a significant challenge as it operates outside traditional cybersecurity defenses, leveraging legitimate services like real estate platforms and postal systems. The U.S. Postal Inspection Service reported a 139% increase in mail receptacle theft between 2019 and 2023, underscoring the growing impact of mail-enabled fraud. Organizations must adopt cross-domain signal correlation, including address usage patterns and identity inconsistencies, to detect these sophisticated attacks that bypass conventional security controls.Source: Bleeping Computer
Identity, Threat Intelligence

Fraudsters exploit vacant properties and postal services for identity theft

(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



