A small town government in Maine lost $189,199 in May 2026. Staff wired a routine payment to a “vendor” that had supposedly updated its payment details. The vendor never sent that email. A criminal did. Nine hundred miles away, a homeowner found the same trick working a different angle. Someone had quietly filed a change of address with USPS, rerouting bank statements and credit card offers to an apartment three states away. Different targets, same move. This is why change of address monitoring has become one of the more overlooked pieces of identity protection.

Last Updated: August 2026

Both incidents above share a mechanic that fraud investigators see constantly. Control where something goes, and you control what happens to it next. Redirect a person’s mail and you get first access to new credit cards and bank statements. Redirect a business’s payment and you get the money directly, with no theft of the underlying account required. The tactic itself is old. What has changed by 2026 is the volume, the sophistication, and the way it now hits SMB owners and their employees from two directions at once.

What Change of Address Monitoring Actually Catches

Change of address monitoring watches for one thing. It flags whether someone has filed a request to redirect your mail, and whether that request actually came from you. USPS processes more than 33 million change of address transactions every year. The overwhelming majority are people moving, exactly as intended. The problem is the minority that are not.

Fraudulent change of address requests do not require access to your home or your mailbox. In many cases, a criminal only needs your name and old address. That information often turns up through data broker sites, prior breaches, or a piece of mail pulled from an unlocked box. Once the redirect goes through, the thief gets a window, sometimes weeks, before missing bills tip you off. That window is when the real damage happens. A redirected bank statement reveals account numbers and spending patterns. A redirected credit card offer can be activated in your name without you ever seeing it arrive. Some thieves use intercepted mail to intercept one-time verification codes sent by banks or brokerages, which lets them pass identity checks that would otherwise stop them. None of these steps require breaking into an account. They only require controlling where your mail lands.

How Criminals Redirect Mail, Then Money

The scale here is bigger than most people assume. A USPS Office of Inspector General report released in May 2026 found that the Postal Inspection Service received more than 800,000 mail theft complaints between fiscal years 2023 and 2025. Complaints rose again in fiscal year 2025 across nearly every Postal Inspection Service division. This pattern has been building for years. An earlier Inspector General analysis found that online change of address fraud jumped 167 percent in a single year. Cases went from 8,857 in 2020 to 23,606 in 2021, a spike documented in a 2022 congressional letter pressing USPS for stronger identity checks.

USPS responded by rolling out two-factor identity verification for online change of address requests in 2023. That closed off one entry point. It did not close all of them. Criminals still use forged paper forms, in-person requests with stolen ID, and look-alike websites that mimic the real USPS portal. Each of these collects personal and payment information under false pretenses. None of this requires a sophisticated hacker. It requires patience, a name, an old address, and the knowledge that most people do not check their mail forwarding status the way they check a bank balance.

The Business Version: Vendor Payment Redirect Fraud

SMB owners who treat this as a consumer problem are missing the half that costs the most money. The FBI’s Internet Crime Complaint Center describes a textbook business email compromise scenario in plain terms. A vendor your company regularly deals with sends an invoice with an updated mailing address, except the vendor never sent it. A criminal compromised or spoofed the vendor’s email and asked for future payments to go somewhere new. That single sentence describes the exact fraud that cost Harpswell, Maine nearly $190,000 this year. It also describes thousands of similar cases nationwide.

The numbers back up how expensive this has become. According to the FBI’s 2025 Internet Crime Report, business email compromise generated $3.05 billion in reported losses in 2025. That came from 24,768 complaints, up from $2.77 billion the year before. The report also notes that most BEC losses move by wire transfer or ACH. Both clear fast and are hard to reverse once the money lands. For a small business, one successful vendor payment redirect can wipe out a quarter’s margin in a single transaction.

This is a distinct threat from the personal mail fraud described above, and the distinction matters. Personal change of address monitoring protects an individual’s identity, credit file, and mail. It does not protect a company’s accounts payable process from a spoofed vendor email. That takes internal controls instead: verified callback numbers, dual approval on payment changes, and staff training on the exact pattern the FBI describes. The two threats share a root cause, an unverified change of address, but they need two different fixes.

Warning Signs You Are a Target

  • Missing mail: Bills, statements, or credit card offers that simply stop arriving, especially all at once.
  • An unexpected change of address confirmation: USPS sends a confirmation to both the old and new address for every change filed. Treat one you did not request as an active incident.
  • New credit inquiries or accounts you do not recognize: A common next step once a thief controls your incoming mail.
  • A vendor email requesting updated payment or address details: Especially one with urgency, or one that asks you to skip your normal verification “just this once.”
  • A slightly altered vendor email domain: A single swapped letter is often the only visible tell in an otherwise convincing message.

How to Strengthen Change of Address Monitoring for Your Household and Your Business

For individuals and families, the fix is layered but not complicated. Enroll in change of address monitoring as part of a broader identity protection plan. That way, any USPS forwarding request tied to your name triggers an alert before mail actually starts moving. Check your credit file periodically instead of assuming no news is good news. Go directly to usps.com for any postal transaction. Do not click a search ad or an email link, since look-alike sites are built to catch people mid-move, right when they are least likely to double check a URL.

For businesses, the fix lives in process, not software alone. Any request to change a vendor’s payment details or address should require a verification call. Use a phone number you already have on file, never one provided in the request itself. Put dual approval on payment detail changes so one compromised inbox cannot redirect funds alone. Train accounts payable staff specifically on the vendor email compromise pattern, since general phishing training often skips this scenario entirely.

One employer-side move connects both problems at once. Offering identity theft protection, including change of address monitoring, as a voluntary employee benefit protects your workforce’s personal identities. Meanwhile, your business can separately harden its own payment verification process. Employees who understand how address-based fraud works on a personal level are also more likely to catch the business version when it lands in their inbox.

Frequently Asked Questions About Change of Address Monitoring

What is change of address monitoring?

Change of address monitoring is a service that alerts you when someone files a change of address request with USPS using your name or personal information. It gives you a chance to catch and reverse a fraudulent mail redirect before it causes lasting damage.

How do I know if someone filed a fraudulent change of address on my mail?

Watch for a USPS change of address confirmation letter you did not request. Also watch for a sudden stop in expected bills or statements, or credit inquiries you do not recognize. USPS mails a confirmation to both the old and new address for every change filed, which is your earliest warning sign.

What should I do if my mail is being redirected without my knowledge?

Contact the U.S. Postal Inspection Service to report the fraud. Cancel the unauthorized forwarding request directly through USPS. Place a fraud alert with the three major credit bureaus, then review recent account statements for unauthorized activity.

Can businesses be targeted by change of address fraud too?

Yes. The business version usually shows up as a vendor payment redirect scam. A criminal spoofs or compromises a vendor’s email account, then asks for future payments to go to a new address or bank account. The FBI tracks this under business email compromise, which caused $3.05 billion in reported losses in 2025.

How can I verify a vendor’s request to update payment or address details?

Call the vendor using a phone number from a prior invoice or your existing records. Never call a number listed in the request itself. Confirm the change verbally before processing any payment to the new details.

Does the Postal Service verify who requests a change of address?

USPS added two-factor identity verification for online change of address requests in 2023 after fraud rates climbed sharply. The protection is not absolute, though. Forged paper forms, in-person requests using stolen identification, and look-alike scam websites can still get through.

Does identity theft protection cover vendor payment fraud for my business?

No. Personal identity theft protection, including change of address monitoring, protects an individual’s mail, credit file, and personal information. It does not replace internal accounts payable controls, which are the correct defense against vendor payment redirect fraud.

How long do I have to reverse a fraudulent change of address?

Act as soon as you notice a confirmation notice you did not request. USPS can cancel a pending or recent change of address request once you report it, but the window narrows the longer mail keeps flowing to the wrong location. Every week of delay gives a thief more time to open accounts or activate stolen cards using your redirected mail.

Change of address fraud is not a new threat. The 2026 version of it is faster, better documented in enterprise threat data, and increasingly aimed at the gap between what a person notices and what a business verifies. Whether it shows up as a stranger redirecting your mail or a criminal redirecting a vendor payment, the fix starts the same way. Treat any change of address as an event worth confirming, not assuming. Visit defend-id.com to see how change of address monitoring fits into a full identity protection plan for you and your family.

Related articles:

error

Enjoy this blog? Please spread the word :)