Diversion Theft
Diversion theft manipulates a person, process, or workflow to redirect something of value to an unauthorised destination.
The diverted asset may be physical, financial, digital, or informational. Goods, payments, equipment, access items, documents, credentials, and sensitive records can all be redirected through an apparently routine administrative change.
Attackers may impersonate a person or function with plausible authority over delivery, collection, payment, or release. Changes to an address, account, collector, mailbox, portal, or contact path create the mechanism for diversion.
Small operational changes are common and often time-sensitive. Requests arriving close to dispatch, collection, payment, onboarding, or handover can exploit the pressure to keep work moving. The attacker only needs the change to appear practical, authorised, or too minor to warrant scrutiny.
How it appears
Section titled “How it appears”Diversion theft appears through email, phone contact, supplier and courier workflows, messaging platforms, helpdesk requests, procurement and finance processes, visitor procedures, delivery points, and in-person interactions.
The requested change may affect:
- delivery or collection destination
- authorised collector or recipient
- payment account
- document mailbox or portal
- contact person controlling a workflow
- email address, telephone number, or physical address treated as authoritative
Most diversion attempts combine:
| Element | What it means | Examples |
|---|---|---|
| Object of value | The asset, payment, information, or access item being redirected. | Goods, laptops, access cards, payments, invoices, records, documents, credentials. |
| Destination change | The altered address, account, person, mailbox, portal, or collection point. | New delivery address, changed bank details, alternate collector, new email address. |
| Claimed authority | The role or relationship used to justify the change. | Supplier contact, courier, employee, project manager, assistant, contractor, customer. |
| Operational reason | The explanation given for altering the destination or release path. | Travel, office closure, urgent delivery, missed pickup, system issue, staff absence. |
| Timing pressure | The condition that makes immediate action appear operationally necessary. | Courier waiting, payment due, dispatch cut-off, executive request, deadline, handover. |
Indicators
Section titled “Indicators”Diversion theft indicators cluster around changes to destination, custody, release authority, and authoritative contact details. Administrative wording may conceal a material change to where value or control is being transferred.
| Indicator | What to look for |
|---|---|
| Unexpected destination change | A delivery address, payment account, pickup location, mailbox, portal, or release instruction changes without an established business reason or prior notice. |
| New contact details | A new email address, telephone number, messaging account, supplier contact, courier instruction, or external mailbox is introduced into the workflow. |
| Late-stage change | The request arrives close to dispatch, collection, payment, onboarding, travel, project delivery, or another operational deadline. |
| Third-party collection | Goods, documents, equipment, badges, or records are to be released to a different person on behalf of the expected recipient. |
| Record mismatch | The requested address, account, contact, collector, purchase order, delivery note, supplier record, or employee record conflicts with existing information. |
| Verification avoidance | Callback checks are discouraged, prior approval is asserted without supporting record, or requester-supplied contact details are used for confirmation. |
| Unusual release pressure | A waiting courier, payment failure, customer impact, senior expectation, or deadline is used to accelerate release or change. |
| High-value or sensitive item | The request concerns equipment, access items, identity documents, financial information, credentials, customer data, or sensitive business records. |
| Unclear approval ownership | The approver, asset owner, release authority, or accountable function cannot be identified from the established workflow. |
| Informal workaround | Procurement, finance, facilities, courier, visitor, asset, records, or security processes are bypassed through an ad hoc arrangement. |