Skip to content

Are Fraudsters Now Able to Hack USPS Electronic Locks?

  • USPS’s electronic-lock initiative improves mailbox security but faces deployment and implementation challenges.
  • New tools may raise the difficulty of mail theft, but they do not eliminate the risk of signal compromise or criminal adaptation.
  • Banks should supplement USPS protections with technologies like Anywhere OnUs Fraud and Anywhere Deposit Fraud to detect check fraud.

In May 2023, the United States Postal Service (USPS) and the U.S. Postal Inspection Service (USPIS) announced Project Safe Delivery, a joint initiative designed to combat mail theft and letter-carrier robberies. One part of the initiative focused on improving the security of USPS blue collection boxes by replacing traditional arrow locks with electronic locks. The goal was to make it more difficult for criminals to access mail with a stolen arrow key alone.

Blue Post Office Box

The original plan called for 12,000 high-security blue collection boxes in high-risk areas, along with 49,000 electronic locks to replace antiquated arrow locks. By adding another authentication factor, USPS intended to make arrow keys less valuable to criminals and reduce the opportunity for mail theft and check fraud.

How Do the Electronic Locks Work?

Public technical details about the eLocks are limited. In early 2024, Kinective’s James Bi attended the SFE Annual Conference(opens in new tab) and a session titled “Safeguarding Against Check Fraud: Protecting Your Business Checks in a Digital Age.” During the session, USPIS agent Michael Maxey provided a high-level description of the system.

According to that description, the electronic mechanism functions as a secondary control. A postal employee uses a compatible mobile device—sometimes described as a scanner—to transmit an authorization signal before an arrow key can open the receptacle. If the device is lost or stolen, USPS can reportedly disable it. In practical terms, the system is intended to prevent an arrow key by itself from providing access.

What the USPS Audit Found

The USPS Office of Inspector General’s November 2024 audit report(opens in new tab) provides a more complicated picture of the rollout. As of June 11, 2024, USPS had purchased 49,537 eLocks for the first phase of the program, which called for 49,809 locks. However, installation of 12,270 of those purchased eLocks had been placed on hold for reasons that included incompatible collection boxes, missing equipment, contract installation delays, and collection boxes removed from USPS systems.

The audit also states that USPS canceled the second phase of 50,000 eLocks and planned to replace it with a new lock designed to work with more types of mail receptacles and reduce unlocking delays. That is different from saying that only 12,270 locks were installed. The 12,270 figure represented eLocks placed on hold, while the audit’s broader concern was whether USPS had a documented plan to complete the remaining installations.

So, are electronic locks improving mail security? In theory, yes. But the audit makes clear that the effectiveness of a security technology depends not only on its design, but also on deployment, compatibility, training, maintenance, and oversight.

USPS Audit Report Security Mail Scanners Report Cover

Do Electronic Locks Increase Mail Security?

The additional control is meaningful. USPS describes the eLocks as a form of multi-factor authentication that reduces the value of a lone arrow key. The USPS OIG also concluded that, when fully installed, the eLocks would enhance delivery security.

However, adding an electronic layer does not make a system invulnerable. Without complete technical specifications, it is reasonable to ask how the authorization signal is protected, whether it can be captured or replayed, and how quickly USPS can respond if a device or credential is compromised. These are security questions—not proof that USPS eLocks have been defeated.

The distinction matters. A technology can raise the cost of an attack without eliminating the risk. Criminals may adapt to new controls, target deployment gaps, or shift their efforts to another point in the check-fraud process.

Have Fraudsters Found a Workaround?

A recent mail-theft case illustrates why physical security remains only one part of the problem. ABC7 News reported(opens in new tab) that two people were arrested in Sunnyvale, California, after investigators recovered more than 80 pounds of suspected stolen mail. Authorities also recovered checks, credit cards, personal information, USPS mailbox locks, and burglary tools. The stolen mail was reportedly connected to community mailboxes across six Bay Area cities.

Mail theft abc7news
Mail theft tools abc7news

(Source: ABC7News.com)

In a LinkedIn post(opens in new tab), Frank Albergo, national president of the Postal Police Officers Association, drew attention to a HackRF One with a PortaPack H2 that investigators reportedly found among the other equipment. A HackRF One is a software-defined radio capable of transmitting and receiving across a broad range of frequencies. Equipment of this type can be used for legitimate testing and research, but software-defined radios can also capture, analyze, and retransmit signals in certain situations.

Albergo appropriately cautioned that the discovery does not prove the suspects used the device to defeat a USPS electronic lock. It does, however, underscore a broader point: security controls must be evaluated against the ways criminals may adapt. A lock can make unauthorized access more difficult, but it cannot by itself stop a stolen check from becoming a financial loss.

Banks Need More Than USPS Security

USPS hardening matters, but banks cannot treat it as a complete fraud strategy. Mail theft is only the first step in many check-fraud schemes; once a stolen, counterfeit, forged, altered, or duplicate check enters the banking system, the institution still needs to identify the risk before funds leave. A delayed or incomplete physical-security rollout creates residual risk that bank-side controls must catch. The question is not whether USPS can make mail theft impossible, but whether banks can detect suspicious instruments early enough to protect their customers and their own balance sheets.

That is why banks need layered, technology-based controls that operate independently of the mail stream. Technologies such as Anywhere On Us Fraud and Anywhere Deposit Fraud can help analyze check images and transaction behavior to surface indicators of counterfeit, forged, altered, duplicate, or otherwise suspicious activity. USPS can reduce the opportunity for theft, but banks still need their own detection and decisioning capabilities. Physical security at the mailbox and intelligent fraud detection at the bank should work together—not serve as substitutes for one another.

Leave a Comment