Drop Address

A drop address is a delivery address a fraudster controls but has no legitimate connection to — used to receive goods bought with stolen payment details, or documents and cards issued against a stolen or fabricated identity. It is the physical endpoint of an otherwise digital fraud, and it is usually the most traceable thing in the chain.

Also called Drop, mule address, reshipping address
Purpose Receive goods or documents without linking them to the fraudster’s real address
Common forms Vacant property, short-term rental, a recruited resident, a parcel locker, a small business accepting deliveries
Used for Card fraud, application fraud, reshipping schemes, receiving cards issued on fraudulent accounts
The reshipping variant A recruited ‘package handler’ receives goods and forwards them abroad
Why it recurs A working drop is reused until it is burned
Strongest detection signal Repetition — the same address across unrelated orders or applications
Related weakness Address data that is never verified against anything

How drops are obtained

The requirement is an address that receives deliveries reliably and cannot be traced back. Several routes produce that, and they differ in how much the occupant knows.

Vacant or transitional property. An empty house, a property between tenancies, a short-term rental booked for the delivery window. Nobody is there to question a parcel.

A recruited resident. The reshipping variant, where someone answers an advertisement for a work-from-home “package handling” or “quality inspection” role, receives goods, and forwards them on. They are frequently unaware the goods are stolen, and they are the ones who appear in any investigation — the same structure as a money mule, with parcels instead of payments.

Intercepted at a legitimate address. The genuine occupant’s address is used and the parcel is taken before they see it, sometimes by redirecting it after dispatch.

Parcel lockers and accommodation addresses. Collection points and small businesses that accept deliveries for others provide separation without requiring a property at all.

Why the address is the traceable part

Everything else in a card fraud is disposable. The card details were stolen, the email was created that morning, the device can be reset, the IP can be routed anywhere. The delivery address cannot be virtualized — a physical object has to arrive somewhere a person can reach.

That makes address repetition one of the more reliable fraud signals available, and it only works at the level of the population rather than the individual order. One order to an address is ordinary. The same address appearing across unrelated accounts, different cardholder names, or multiple applications is the signature of a drop — and it is invisible to any check that considers one transaction alone.

This is the same technique that detects a fraud ring, and it is the reason entity resolution matters: linking records on a normalized address, rather than on an exact string match, is what turns “Flat 2, 14 High St” and “14a High Street” into one node.

Why this matters for identity verification

The gap a drop address exploits is that delivery addresses are typically accepted rather than verified. A shipping address is an input field. Nobody establishes that the person ordering has any connection to it, because in ordinary commerce nobody needs to.

That is a defensible position for a low-value purchase and a poor one where a drop address is being used to receive something that grants ongoing access — a payment card issued on a fraudulent account, or documents supporting application fraud. There the address is not a shipping detail; it is the point where a fabricated identity becomes a physical foothold.

Two controls close it. Verifying the applicant’s identity properly at the point of application means a fabricated or stolen identity does not reach the delivery stage, which is what identity document verification does upstream of the problem. And proof of address evidence connects a real person to a real location, which is exactly the link a drop is designed to break. Synthetic and stolen identity controls address the accounts these addresses serve.

What address checks can’t do

Address verification does not verify a person. Confirming that an address exists, or that it matches a billing record, says nothing about who will collect the parcel.

Reshipping recruits look legitimate. A genuine person at a genuine address, receiving a parcel addressed to them, fails no check that examines the delivery alone.

Repetition detection needs a population. A single merchant sees a single order. The signal emerges across accounts and, often, across organizations.

Blocking addresses creates collateral damage. Shared buildings, student housing and genuine forwarding services generate the same repetition pattern as a drop.

Frequently asked questions

What is a drop address in fraud?

A delivery address the fraudster controls but has no legitimate connection to, used to receive goods bought with stolen payment details or documents issued against a false identity. It provides a physical endpoint that cannot easily be traced back to them.

What is reshipping fraud?

A scheme where someone is recruited through a fake work-from-home job to receive parcels and forward them, usually abroad. The goods were bought with stolen card details. The recruit is frequently unaware and is the person who appears in any investigation — the parcel equivalent of a money mule.

How are drop addresses detected?

Mainly through repetition. The same address appearing across unrelated accounts, different names or multiple applications is the signature. It requires matching on normalized addresses rather than exact strings, and it only becomes visible at the population level, not within a single order.

Can a delivery address be verified?

Its existence can be, and its match to a billing record can be. Neither establishes that the person ordering has any connection to it. Linking a real person to a real location requires identity verification and proof-of-address evidence, which is the connection a drop is designed to break.

Related reading

  • Money mule — the same recruitment structure, moving funds instead of parcels
  • Fraud ring — how shared attributes like an address expose coordinated activity
  • Proof of address — the evidence class that connects a person to a location
  • Application fraud — what a drop address is often collecting the proceeds of

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data