Blog post

What a Fraud Factory Looks Like

Burt Helm

Published

September 14, 2026

The storefront on Burbank Boulevard looked forgettable; that was probably the point. Next door to an auto body shop, with blinds half-drawn across a window advertising shipping, receiving, and a scan-to-PDF service, it offered passersby only a partial glimpse inside: rows of small mailboxes and a clerk at the desk sorting mail.

SentiLink, in partnership with CBS News, later identified the location as something far more suspicious: an alleged mailbox fraud hub tied to hundreds of financial applications and roughly 200 identities. When investigators returned, the rows of mailboxes were gone.

In Intercept, SentiLink’s investigation tool for reviewing identity and fraud signals, the address all but blares red: “cluster behavior strongly suggests fraud,” “address is associated with a synthetic hub,” and a high fraud risk score of 908.

image5

Below the warnings are rows of identities tied to the same location.

How do you know when a busy mailbox business is actually a fraud hub? That was the question behind SentiLink’s work with CBS News, and the kind of question Intercept is built to help answer. A mailbox business is supposed to receive mail for lots of people, so the address alone was not enough. The answer was in the patterns around it: strange similarities among the recipients, bursts of applications that did not look normal, and details our investigators found that simply did not add up.

Many identities, many red flags

The investigation began with the address. SentiLink reviewed applications that listed the Burbank location between August 2024 and March 2026. We found more than 490 applications tied to over 200 unique identities and nearly 70 mailbox numbers. The applications arrived in bursts, including a March 2025 spike of 115 applications, nearly a quarter of the location’s total volume. And they clustered around one product category: about 80% of the identities tied to the address were used to open bank or checking accounts.

None of this proved fraud on its own. But was the behavior unusual? For the sake of comparison, we selected the ten closest privately-operated mailbox businesses certified as Commercial Mail Receiving Agencies (CMRAs) by the United States Postal Service. They included three chain locations (all UPS stores) and seven independents, all within 2 miles of our suspected hub in Burbank. Like our target, they had many identities tied to the address, as expected.

 

Application activity at the Burbank address was unusually high and concentrated among a small number of partners. The address received 490 applications—1.8 times the 268 received by the busiest comparison store—yet those applications came through only 29 partners, compared with 41 at the typical comparison store. Just four partners generated 80% of Burbank’s applications, and one bank alone accounted for 58%. This level of concentration is significantly greater than would be expected if applications were randomly distributed across partners.

 

Next, SentiLink ran the applications through several identity fraud-risk models. One signal was synthetic identity fraud risk: identities that appeared fake or stitched together from mismatched personal information. About 28% of applications tied to the Burbank address scored highly for synthetic fraud risk, compared with 5.5% in the control group.

The remaining application identities appeared to be linked to real people with real histories. But those histories had odd things in common: They had been issued Social Security numbers years after birth. Their earlier applications came from elsewhere in the U.S. Then they went quiet, often for years. Then they all reappeared in the same place: this Burbank mailbox storefront with rows of small P.O. boxes.

These signals — late-issued SSNs, gaps in application history and geography — are consistent with a form of identity theft that we at SentiLink call Assumed Identity Abuse (AIA). The victims are often immigrants who come to the U.S. for a limited period, receive Social Security numbers to work or study, build short but legitimate identity histories, and then return home. Once they leave, their U.S. identity records can sit dormant, sometimes for years, before someone else finds and steals them.

In the suspected hub, 54% of applications were flagged for AIA by our identity fraud risk model. Manual review by our Fraud Intelligence Team found that an additional 12% – 66% of applications in all — appeared to be associated with identities stolen from former legal immigrants as well. By comparison, around 1% of the control group applications were flagged for AIA by the model.

Four packages, zero deliveries

Our head of fraud insights, Dr. David Maimon, visited the location personally. Most of the building belonged to the auto repair shop, but in the far corner he found the mailbox storefront. Inside were three towers of mailboxes, a table listing P.O. box rates, and a clerk behind a desk. When Dr. Maimon asked to rent a box, the clerk said none were available. Dr. Maimon asked what he did there.

image1-1image7

“I just sit here every day and put mail into these mailboxes,” the clerk told him.

Dr. Maimon tried another tack: sending mail. He bought four Starbucks gift cards and shipped them to a random selection of four of the associated P.O. boxes with signature confirmation.

Each package went out for delivery. Each delivery attempt failed. After multiple attempts, all four packages were returned. The mailbox address did not work as a mailbox.

So the team checked the paperwork with the United States Postal Service. Private businesses must register as Commercial Mail Receiving Agencies, or CMRAs, to receive mail on behalf of customers. This storefront did not appear to be registered. It also advertised an affiliation with a chain called Anytime Mailbox; when CBS News checked with the company, Anytime said it had no record of an operation at that address.

When Dr. Maimon returned three months later, the operation had vanished. The rows of mailboxes were gone; an empty room remained.

image3

One hub in a broader system of fraud

The Burbank storefront is one address. In Intercept, it is one of over 10,000 addresses flagged as a “synthetic hub”: an address — sometimes CMRAs, sometimes single-family homes — where the identities and their application histories raise suspicion of fraud. It looked unassuming from the street and nondescript on a map. But in Intercept, it appears in red, part of a broader map of suspected fraud infrastructure.

For fraud risk analysts, that red flag is an invitation to slow down and investigate — to catch the infrastructure before more fraud gets through.

 

 

Content

Share

Learn how we can help.

Schedule a demo with a fraud expert and evaluate our solutions.