Skip to content

Diversion Theft

Diversion theft manipulates a person, process, or workflow to redirect something of value to an unauthorised destination.

The diverted asset may be physical, financial, digital, or informational. Goods, payments, equipment, access items, documents, credentials, and sensitive records can all be redirected through an apparently routine administrative change.

Attackers may impersonate a person or function with plausible authority over delivery, collection, payment, or release. Changes to an address, account, collector, mailbox, portal, or contact path create the mechanism for diversion.

Small operational changes are common and often time-sensitive. Requests arriving close to dispatch, collection, payment, onboarding, or handover can exploit the pressure to keep work moving. The attacker only needs the change to appear practical, authorised, or too minor to warrant scrutiny.

Diversion theft appears through email, phone contact, supplier and courier workflows, messaging platforms, helpdesk requests, procurement and finance processes, visitor procedures, delivery points, and in-person interactions.

The requested change may affect:

  • delivery or collection destination
  • authorised collector or recipient
  • payment account
  • document mailbox or portal
  • contact person controlling a workflow
  • email address, telephone number, or physical address treated as authoritative

Most diversion attempts combine:

ElementWhat it meansExamples
Object of valueThe asset, payment, information, or access item being redirected.Goods, laptops, access cards, payments, invoices, records, documents, credentials.
Destination changeThe altered address, account, person, mailbox, portal, or collection point.New delivery address, changed bank details, alternate collector, new email address.
Claimed authorityThe role or relationship used to justify the change.Supplier contact, courier, employee, project manager, assistant, contractor, customer.
Operational reasonThe explanation given for altering the destination or release path.Travel, office closure, urgent delivery, missed pickup, system issue, staff absence.
Timing pressureThe condition that makes immediate action appear operationally necessary.Courier waiting, payment due, dispatch cut-off, executive request, deadline, handover.

Diversion theft indicators cluster around changes to destination, custody, release authority, and authoritative contact details. Administrative wording may conceal a material change to where value or control is being transferred.

IndicatorWhat to look for
Unexpected destination changeA delivery address, payment account, pickup location, mailbox, portal, or release instruction changes without an established business reason or prior notice.
New contact detailsA new email address, telephone number, messaging account, supplier contact, courier instruction, or external mailbox is introduced into the workflow.
Late-stage changeThe request arrives close to dispatch, collection, payment, onboarding, travel, project delivery, or another operational deadline.
Third-party collectionGoods, documents, equipment, badges, or records are to be released to a different person on behalf of the expected recipient.
Record mismatchThe requested address, account, contact, collector, purchase order, delivery note, supplier record, or employee record conflicts with existing information.
Verification avoidanceCallback checks are discouraged, prior approval is asserted without supporting record, or requester-supplied contact details are used for confirmation.
Unusual release pressureA waiting courier, payment failure, customer impact, senior expectation, or deadline is used to accelerate release or change.
High-value or sensitive itemThe request concerns equipment, access items, identity documents, financial information, credentials, customer data, or sensitive business records.
Unclear approval ownershipThe approver, asset owner, release authority, or accountable function cannot be identified from the established workflow.
Informal workaroundProcurement, finance, facilities, courier, visitor, asset, records, or security processes are bypassed through an ad hoc arrangement.