Not all cybercrime starts cyber

I have lived in my current place for almost two years. In that time I have received a steady stream of mail for the tenant before me. It started with the ordinary things, the sort of post everyone accumulates. Bank statements. Then forms from a share registry. Then a company registration pack from ASIC. Today it was their Medicare cards.

I know those last two from the outside, not from opening anything. We have just set up a company of our own, so I recognise the ASIC pack the moment it lands. I registered for a new Medicare card around the same time, so I know the feel of the card through the envelope. There are two of them in this one.

For a while I did the neighbourly thing. I had a phone number for them, so I called when something turned up and let them know. Nothing changed. The mail kept coming, so eventually I stopped chasing it and started writing "return to sender" on the envelopes, unopened. Two years on, they still have not updated their address with any of the people who matter.

The standard answer here is a mail redirect, and it is a smaller answer than it looks. Australia Post redirection is a paid service that runs for a few months or a year, then lapses. The trickle slows while it runs, and the day it expires the old address starts collecting again, precisely when the person has stopped thinking about it. My predecessor may well have done the standard thing. Mail still arriving two years later is what the standard thing looks like after it expires.

Nothing here was hacked. No password was guessed, no inbox was breached, no clever email was crafted. Every one of these documents arrived because a person moved house and did not tell the handful of institutions that hold their financial and legal identity. The system worked exactly as designed. It just delivered to the wrong letterbox, for two years, without complaint.

I have not read any of it, and I do not need to, because I get the same envelopes myself. A bank statement carries account and BSB numbers and a pattern of spending. A share registry form carries a holder number and a record of assets. A company pack ties a name to a directorship and an official address. A Medicare card is a genuine identity document, one of the pieces used to prove you are who you say you are. Any one of them is a nuisance. Arriving at the same address, to the same name, they are most of what someone would need to convincingly be that person.

The reason I return it rather than bin it is the same reason I do this work. I know what that mail is worth to the wrong person. What stays with me is how little skill it would have taken. The documents assembled themselves. All the effort sat on the victim's side, and the effort was the effort of doing nothing.

This is not only a personal problem. The same failure shows up in businesses constantly, and it rarely looks like a security issue until it is one. A former employee still on a payroll distribution. Post to an office you closed months ago, still collected by whoever has the key. Invoices and remittance advice going to an address you moved out of. Offboarding that carefully revokes the logins and forgets the letterbox. None of it touches a firewall. All of it leaks the same kind of information, quietly, to whoever happens to be standing where the mail lands.

Good security spends most of its attention on the digital front door and very little on the boring, physical, human processes around it, which is exactly where a patient person would start. The unglamorous admin, updating an address, redirecting mail, following the paper when a role or an office is retired, is not separate from security. It is the part most likely to be skipped, and the part that quietly hands out everything the front door was built to protect.

Back to Writing