Normal view

There are new articles available, click to refresh the page.
Before yesterdayThe Conversation

What are ‘mule addresses’? Criminologists explain how vacant properties serve as depots for illegal online purchases

Nobody's home, just as the sender intended. AndreyPopov/ iStock via Getty Images Plus

Online shopping isn’t just a convenient way to buy batteries, diapers, computers and other stuff without going to a brick-and-mortar store.

Many Americans also use the internet to quietly acquire illegal, fake and stolen items. Guns, prescription drugs no doctor has ordered and checks are on this long list, as well as cloned credit cards, counterfeit passports and phony driver’s licenses.

Because buyers and sellers alike realize that the authorities can detect illegal online transactions, criminals and their customers prefer covert online platforms that protect user anonymity, such as Tor, or encrypted messaging applications like Telegram and WhatsApp. Buyers and sellers also use digital wallets and cryptocurrencies to further conceal their identities.

As scholars of high-tech crime, we were eager to solve a riddle. Having these items shipped to the buyers’ homes or offices would make it easy for authorities to catch them. So how do people who buy these illegal items maintain their anonymity when they take possession of items they purchased on the dark web?

They mostly use vacant residential properties, called “mule addresses” or “drop addresses.” Once the illegal goods or phony documents get delivered – presumably without the owners’ knowledge – to the doorstep of the uninhabited home, the buyer or a middleman picks it up. This practice makes it very hard to trace these transactions.

Penchant for sharing

To discover where these items change hands, we took advantage of the inclination of some of the criminal vendors to share images on Telegram of the parcels they send, along with the illicit items.

They use this strategy to build their reputations, earn the trust of buyers and market their services.

Not all users of online underground markets do this, but we still spotted thousands of packages delivered this way over a period of two years.

In one case, we found a photo of a forged or stolen check alongside the mailed envelope used for its delivery on a Telegram channel dedicated to trading stolen and counterfeit checks.

The label on the envelope bears not only the shipping date but also the Wyoming address where it was sent. Armed with this information, anyone can retrieve related details by searching online. We found an apartment complex at that address with several units for rent.

A mailed envelope and a check with names obscured
A forged or stolen check alongside the envelope used to mail it to the person who bought it on the dark web. Screen capture by David Maimon, CC BY-NC-ND

Guns, drugs and rentals

We also found that criminal vendors use mule addresses as their sender address. In one example, we found a video, uploaded in April 2023, of an assault rifle shipped from an Arizona address. At the time, that property was for sale.

The video displays an assault rifle apparently shipped from that address after being purchased online on an underground gun market. At the time, that property was for sale.

An assault rifle and an address label
An illegal firearm vendor uploaded a video of an assault rifle being shipped to a customer. Screen capture by David Maimon, CC BY-NC-ND, CC BY-NC-ND

We found a similar video documenting the punctual delivery of what we believe to be illegal drugs. Considering that the video has been circulating in illegal drugs markets that we monitor, it’s reasonable to assume that the package contains narcotics or prescription drugs.

The footage portrays a satisfied customer who has just gotten the drugs. We looked up the recipient’s address, which is discernible in the video.

It’s a property in North Las Vegas, Nevada, which was listed for sale at the time of delivery – although it seems to have later been sold. The anticipated delivery date, March 28, 2023, coincided with the day the package in the video was received.

One of the illegal digital marketplaces we identified is a hub for prescription sales of OxyContin, Viagra, Adderall and Valium. It’s linked to an administrator who presides over several Telegram channels.

The administrator has shared photos on those channels that allowed us to see tracking numbers associated with packages they’d mailed. By collating the tracking numbers from April 20 to May 23, 2023, we compiled a comprehensive database of those addresses and the statuses of those properties when the packages were delivered.

We found that 72% of the 650 deliveries in this database were to properties listed for sale, and the rest were to properties unoccupied for other reasons. The average time that elapsed between a property listing and an illicit package being delivered there was nine days.

Be on guard

We haven’t yet learned of any criminals who were convicted of criminally using mule addresses to deliver illegal packages.

Because criminals take advantage of vacant residential properties listed for sale or rent by unsuspecting homeowners to protect their anonymity, we believe that it’s important for landlords and people who are selling or renting homes to protect themselves from these crimes of commerce.

Some of the same strategies that enhance safety in other regards can help, such as installing surveillance cameras and employing property managers.

The Conversation

David Maimon receives funding from Department of Homeland Security and other private organizations.

Saba Aslanzadeh does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.

Behind the scenes of the investigation: Heists Worth Billions

David Maimon's cybersecurity research group noticed a flood of checks in underground markets, which opened a window into much broader criminal activity. Collage by Kimberly Patch

Professor David Maimon is director of the Evidence-Based Cybersecurity Research Group at Georgia State University.

He and his group are well familiar with what happens on the dark web, which consists of websites that look like ordinary websites but can be reached only using special browsers or authorization codes and are often used to sell illegal commodities.

In this behind-the-story video, Maimon shows some of the hundreds of thousands of bank-related images that he and his team have collected from the dark web and text message applications, and the research these discoveries spurred them to do. That research sparked the investigative story Heists Worth Billions, which Maimon teamed up to write with The Conversation’s senior investigative editor Kurt Eichenwald. Here’s how Maimon and colleagues uncovered the crimes, and his remarks from a follow-up interview.

Maimon’s group was monitoring images posted on the dark web when it found the initial clues that something big was afoot.

My group and I spend a lot of time on underground markets in which criminals sell all kinds of illicit commodities. We see a lot of counterfeit products. We see a lot of identities. And in mid-2021 we started to see a lot of checks flooding the markets.

Those checks led us down a path where we realized that thousands of sham bank accounts were being created to steal and launder money.

The group’s first realization was about the volume of deposits.

Folks were using multiple accounts simultaneously to deposit the high volume of checks. They were simply purchasing from the markets and depositing on different accounts.

For example, three checks would be deposited into three different bank accounts by a single criminal.

Group members connected another clue that showed them how the criminals were getting access to multiple accounts.

We saw numerous debit cards and realized that the criminals were using those debit cards to deposit all the checks they stole or purchased.

Then, in June 2022, the group made a key observation.

Criminals were posting screenshots from bank accounts with balances showing zero.

We realized that these screenshots of zero-balance bank accounts were advertisements – they were selling bank accounts that had zero balances.

This led the group to an investigation.

Over six months we tracked a single criminal, counting the number of images of credit cards and the number of screenshots of bank accounts showing zero balances that he posted.

We’re seeing this increasing trend from one single actor and, of course, being out there in the ecosystem, we are able to see more and more copycats: more and more folks like the individual we’re monitoring, offering their services.

And a conclusion about what allowed this to happen.

If a criminal opens a credit card under someone else’s name, when the person realizes something is wrong and freezes the credit card, the criminal can’t use that identity anymore.

But with bank accounts, it’s a different story, because the credit freeze does not affect your ability to establish a new bank account under someone else’s name.

Maimon gives some advice on how to protect your identity.

Make sure you freeze your credit. Make sure you purchase some kind of identity theft protection plan, which will alert you every time someone is using your identity. And simply monitor your bank account on a daily basis, monitor your credit card.

Freezing your credit ensures that no one can access your credit report unless you actively lift the freeze.

He talks about what’s next for his research group.

We’re trying to understand how all those identities are actually being used in the context of money laundering and, more specifically, sports betting.

And he sounds the alarm.

This is a serious problem that is largely being ignored. It’s our hope that exposing the magnitude of this will help spur action, because far too many people are losing far too much money to this type of crime.


Graphic showing a masked criminal on a stamp and saying 'Heists worth billions'
This article accompanies Heists Worth Billions, an investigation from The Conversation that found criminal gangs using sham bank accounts and secret online marketplaces to steal from almost anyone – and uncovered just how little being done to combat the fraud.

How to protect yourself from drop account fraud – tips from our investigative unit.

Announcing The Conversation’s new investigative unit

The Conversation

David Maimon receives funding from the National Science Foundation, the Criminal Investigations and Network Analysis Center at George Mason University, and other private grants which support the Evidence Based Cybersecurity research group.

Heists Worth Billions: An investigation found criminal gangs using sham bank accounts and secret online marketplaces to steal from almost anyone – and little being done to combat the fraud

In January 2020, Debi Gamber studied a computer screen filled with information on scores of check deposits. As a manager for eight years at a TD Bank branch in the Baltimore suburb of Essex, she had reviewed a flurry of account activity as a security measure. These transactions, though, from the ATM of a tiny TD location nestled in a nearby mall, struck her as suspicious.

Time and again, Gamber saw that these checks were payable to churches – many states away from the Silver Spring shopping center branch – yet had been deposited into personal accounts, a potential sign of theft.

Digging deeper, she determined that the same customer service representative, Diape Seck, had opened at least seven of the accounts, which had received more than 200 church check deposits. Even fishier, the purported account holders had used Romanian passports and driver’s licenses to prove their identities. Commercial bankers rarely see those forms of ID. So why were all these Romanians streaming into a small branch located above a Marshall’s clothing store?

Suspecting crimes, Gamber submitted an electronic fraud intake form, then contacted TD’s security department to inform them directly of what she had unearthed. Soon, the bank discovered that Seck had relied on Romanian documents for not just seven accounts but for 412 of them. The bank phoned local police and federal law enforcement to report that an insider appeared to be helping criminals cheat churches and TD.

Nine months after TD’s tip, agents started rounding up conspirators, eventually arresting nine of them for crimes that netted more than US$1.7 million in stolen checks. They all pleaded guilty to financial crimes except for Seck, who was convicted in February 2023 for bank fraud, accepting a bribe and other crimes. He was sentenced in June 2023 to three years in prison.

Sophisticated crimes

How could it happen? How could criminals engineer a yearlong, multimillion-dollar fraud just by relying on a couple of employees at two small bank branches in a scheme with victims piling up into hundreds?

The answer is, because it’s easy. Crimes like these happen every day across the country. Scams facilitated by deceiving financial institutions – from international conglomerates to regional chains, community banks, and credit unions – are robbing millions of people and institutions out of billions and billions of dollars. At the heart of this unprecedented crime wave are so-called drop accounts created by street gangs, hackers and even rings of friends. These fraudsters are leveraging technology to obtain fake or stolen information to create the drop accounts, which are then used as the place to first “drop” and then launder purloined funds.

A person in a white hooded sweatshirt walks toward a U.S. postal carrier
An October 2022 surveillance photo of an armed robber approaching a mail carrier. The Conversation/court records

To better understand the growing phenomenon of drop accounts and their role in far-reaching crime, the Evidence-Based Cybersecurity Research Group at Georgia State University joined The Conversation in a four-month investigation of this financial underworld. The inquiry involved extensive surveillance of criminals’ interactions on the dark web and secretive messaging apps that have become hives of illegal activity. The reporting shows:

  • The technological skills of street gangs and other criminal groups are exceptionally sophisticated, allowing them to loot billions from individuals, businesses, municipalities, states and the federal government.
  • Robberies of postal workers have escalated sharply as fraudsters steal public mailbox keys in the first step of a chain of crimes that ends with drop accounts’ being loaded with millions in stolen funds.
  • A robust, anonymous online marketplace provides everything an aspiring criminal needs to commit drop account fraud, including video tutorials and handbooks that describe tactics for each bank. The dark web and encrypted chat services have become one-stop shops for cybercriminals to buy, sell and share stolen data and hacking tools.
  • The federal government and banks know the scope and impact of the crime but have so far failed to take meaningful action.

“What we are seeing is that the fraudsters are collaborating, and they are using the latest tech,” said Michael Diamond, general manager of digital banking at Mitek Systems, a San Diego-based developer of digital identity verification and counterfeit check detection systems. “Those two things combined are what are driving the fraud numbers way, way up.”

Criminals target letter carriers for their arrow keys, giving them access to public mailboxes. Via Evidence-Based Cybersecurity Research Group.

Billions stolen

The growth is staggering. Financial institutions reported more than 680,000 suspected check frauds in 2022, nearly double the 350,000 such reports the prior year, according to the Treasury Department’s Financial Crimes Enforcement Network, also known as FinCEN. Through internet transactions alone, swindles typically facilitated by drop accounts cost individuals and businesses almost $4.8 billion last year, a jump of about 60% from comparable fraud losses of more than $3 billion in 2020, the Federal Bureau of Investigation reported.

Plus, a portion of the estimated $64 billion stolen from just one COVID-19 relief fund went to gangsters who rely on drop accounts, according to a congressional report and an analysis from the University of Texas at Austin. Criminals using drop accounts also hit the pandemic unemployment relief funds, which experienced improper payments of as much as $163 billion, the Labor Department found. Indeed, experts say the large sums of government money meant to combat economic troubles from COVID-19 fueled the rapid growth of drop account fraud, as trillions of dollars in rescue funds were disbursed in the form of wires and paper checks.

“There were a huge range of criminals who were trained in this during the pandemic,” said one banking industry official who spoke on condition of anonymity because of the sensitivity of the matter. “A lot of them have grown up in the pandemic and seen that it is easy to make a lot of money with these schemes, with very little risk of prosecution.”


Graphic showing a masked criminal on a stamp and saying 'Heists worth billions'
This article is an excerpt from Heists Worth Billions, an investigation from The Conversation that found criminal gangs using sham bank accounts and secret online marketplaces to steal from almost anyone – and uncovered just how little being done to combat the fraud.

How to protect yourself from drop account fraud – tips from our investigative unit.

Behind the scenes of the investigation

Announcing The Conversation’s new investigative unit

The Conversation

David Maimon receives funding from the National Science Foundation, the Criminal Investigations and Network Analysis Center at George Mason University, and other private grants which support the Evidence Based Cybersecurity research group.

Kurt Eichenwald does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.

❌
❌