The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model
Arjun Arunasalam
Network and Distributed System Security (NDSS) Symposium 2024 · Day 3 · Authentication & E-Commerce · Authentication & E-Commerce
Overview
In an era where e-commerce has become a global cornerstone of retail, experiencing a 55% surge in online spending pre-pandemic and transactions exceeding half a trillion dollars, the proliferation of independent sellers has introduced both innovation and new vulnerabilities. This talk, presented by Arjun Arunasalam, sheds light on a pervasive yet underexplored dark side of this digital economy: abusive dropshipping. While traditional dropshipping is a legitimate retail model involving formal agreements between sellers and suppliers, abusive dropshipping operates covertly, exploiting platform mechanisms and deceiving customers and original merchants alike for illicit economic gain.

Key moments
- 0:40 Defining abusive dropshipping and its mechanics
- 1:10 Negative impact on customers, sellers, and platforms
- 2:00 Key contributions and unique findings of the study
- 2:50 In-depth comparison: compliant vs. abusive dropshipping
- 3:40 The economic incentives and methods for profitability
- 4:25 How abusive dropshipping differs from other e-commerce fraud
- 4:55 Overview of data collection and research methodology
The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model
Speakers: Arjun Arunasalam
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=SOiLd9tHQKY
Overview
In an era where e-commerce has become a global cornerstone of retail, experiencing a 55% surge in online spending pre-pandemic and transactions exceeding half a trillion dollars, the proliferation of independent sellers has introduced both innovation and new vulnerabilities. This talk, presented by Arjun Arunasalam, sheds light on a pervasive yet underexplored dark side of this digital economy: abusive dropshipping. While traditional dropshipping is a legitimate retail model involving formal agreements between sellers and suppliers, abusive dropshipping operates covertly, exploiting platform mechanisms and deceiving customers and original merchants alike for illicit economic gain.
The presentation unveils a comprehensive study characterizing these exploitative operations, detailing the harmful strategies abusive dropshippers employ to list items, evade account suspension, and persist across major e-commerce marketplaces. By analyzing web crawls, online forums, instructional materials, and specialized software, alongside interviews with e-commerce experts, the research constructs an end-to-end lifecycle of this abuse. It culminates in the identification of five distinct, observable characteristics that provide a crucial foundation for the automated detection of abusive dropshippers, laying critical groundwork for future investigations into countering this evolving threat.
This talk is particularly significant because it addresses a critical gap in security research, which has historically focused on buyer-initiated e-commerce fraud. By focusing on seller-initiated fraud, specifically abusive dropshipping, the work exposes how these operations harm multiple stakeholders: customers endure inflated prices, neglected orders, and missing tracking information; original e-commerce sellers suffer reputational damage from unauthorized listings and poor service; and e-commerce platforms contend with eroding trust, negative user experiences, and potential impacts on traffic. The findings motivate the development of robust safeguards essential for protecting the integrity of the e-commerce ecosystem.
Background
▶ Watch: Defining abusive dropshipping and its mechanics (0:40)
To understand the intricacies of abusive dropshipping, it's essential to first differentiate it from its legitimate counterpart. Compliant dropshipping involves a formal, established agreement between an e-seller (the dropshipper) and a third-party source vendor. In this model, the dropshipper's contact information is typically used on packaging, legal liability for customer interactions is transferred to the dropshipper, and fulfillment occurs either directly from the source vendor or via third-party services like Amazon FBA. This structure ensures guaranteed stock, consistent delivery, and proper handling of returns, adhering to e-commerce platform regulations.
In stark contrast, abusive dropshipping operates without any formal agreements. As depicted in Figure 1-b of the original research, the abusive dropshipper selects a source domain (e.g., Amazon US) from which to procure items and a target domain (e.g., Amazon MX) where they list these items for sale, often at significantly inflated prices. When a customer places an order on the target domain, the abusive dropshipper simply purchases the item from a private seller on the source domain, using the customer's name and shipping address. The original private seller then ships the item with their own label, completely unaware they are fulfilling an order for an abusive dropshipper. The customer, similarly, remains oblivious to the middleman and the often-inflated price they have paid.
This model is particularly attractive due to its minimal overhead, as it requires no physical inventory or warehouse management. It offers dropshippers immense flexibility to list almost any item and exploit international shipping discrepancies, selling items in one country that are either unavailable or much more expensive, and sourcing them from another where they are cheaper, often leveraging free or low-cost international shipping options. For example, a dropshipper in Turkey might sell a popular cosmetic product on a Mexican marketplace, sourcing it from a US seller at a much lower price, effectively arbitraging the price difference and shipping costs.
The malicious effects are profound: customers face uncertainty, potential delays, and inflated prices; original sellers can suffer reputational damage if the abusive dropshipper provides poor service or fails to deliver; and e-commerce platforms struggle with effective prevention because these non-conventional methods circumvent traditional detection mechanisms. Current platform protection measures largely rely on reactive manual reporting, allowing abusers to persist until a critical mass of complaints is accumulated.
The research further distinguishes abusive dropshipping from gray-market sellers. While gray-market sellers deal in goods obtained through unauthorized channels, they still purchase goods in bulk and hold physical inventory. Abusive dropshippers, however, hold no physical stock, fulfilling orders directly from private sellers using customer addresses, making them a more obscured and remote risk. Previous technical community efforts have predominantly focused on buyer-initiated e-commerce fraud, such as credit card fraud or reshipping mule scams. This study fills a critical gap by focusing on the mechanisms and impact of seller-initiated e-commerce fraud, specifically the covert operations of abusive dropshipping.
Key Findings
▶ Watch: Key contributions and unique findings of the study (2:00)
The comprehensive study revealed a sophisticated ecosystem of exploitative behavior driven by two primary operations: abusive item sourcing and volatile order fulfillment, which collectively lead to significant complications in returns and are characterized by distinct traits crucial for detection.
Abusive Item Sourcing
Abusive dropshippers meticulously select items from private sellers on source platforms to list on target marketplaces. This process often involves manual browsing or the use of specialized dropshipping software to identify gap items—products either unavailable or significantly more expensive on the target platform. Two main motivations drive this selection:
- Exclusivity-Motivated Gap Items (F:a, I:s, M:a): These are items unavailable on the target platform but readily accessible on the source. For instance, popular US products desired by Canadian or Mexican customers. Abusive dropshippers exploit this scarcity, often selling items at three times their original price, a markup noted by interviewed participants. This inflated pricing directly harms customers and can indirectly damage the source merchant's reputation due as customers perceive poor value.
- Competitive Profit-Motivated Gap Items (F:a, I:s, M:a): These items are sold for less than existing listings of the same product on the target platform. An illustrative example cited in the talk is a baby product listed on Amazon MX for $15, sourced from Amazon US for $7 with free international shipping, yielding a $5 profit. Forum users reported substantial margins, with some claiming "10k... a 40% margin in a month from Mexico-based operations."
Beyond profit, a critical priority for abusive dropshippers is avoiding trademarked items (F:a, I:a, M:a). Selling branded goods like Adidas or Nike often leads to swift platform removal following a few sales or a complaint from the trademark owner. To ensure the longevity of their operations, they deliberately opt for non-risky items, typically from smaller, lesser-known brands, which are less likely to be scrutinized by platform enforcement.
A notable finding is the practice of underground collaboration (F:s), where abusive dropshippers leverage collective experience to identify non-risky brands and profitable gap items. This collaboration often manifests as shared resources, such as a Google Sheets document containing 2,814 unique non-risky brands, continuously updated based on successful sales without issues. They also identify "winning products"—gap items with proven demand. Analysis of a publicly referenced data dump (PasteFS 74) of 4,411 gap items listed over 15 months on Amazon MX, sourced from Amazon US private sellers, provided concrete evidence. These items showed an average listing price of $43.70 (±$19) on Amazon MX, sourced for $21.40 (±$10.20) from Amazon US, resulting in a 104% average price increase. For example, a Hot Wheel Star Wars Stellar Vehicle Toy was listed for $29.75 on Amazon MX, sourced for $11.61, yielding an $18.14 profit (156% increase). The CDF of item prices (Figure 4) showed that 90% of these gap items were priced under $61.09 USD. Electronics and Home & Kitchen were the most popular categories (Figure 5), and the top 20 brands were consistently lesser-known, confirming the preference for non-risky items (Figure 6).
When brand owners do file complaints, abusive dropshippers resort to forging documents (F:f, I:s, M:f), such as Letters of Authorization, to circumvent platform checks. Instructional videos even provide sample texts for this purpose. If a listing is removed, they update their collaborative "allow list" to mark the item as problematic and then source similar items from different private sellers.
A key enabler of these operations is the exploitative use of dropshipping software. Both benign and malicious tools facilitate item selection (Figure 7). Benign tools, listed in Table II, include product research software (e.g., Helium 10, AMZScout) for identifying profitable gap items with geographic filtering, repricing tools (e.g., Informed Repricing) for competitive pricing, and product review software (e.g., Feedback Express) to solicit positive customer feedback. Malicious software, exemplified by Software-Mal (Figure 8), is specifically designed for abuse. It crawls listing pages, collects item names and brands, filters out brands from a user-maintained "Brand Deny List," and gathers price, shipping, and stock information. Crucially, it performs secondary filtering for trademark status by querying public services like Bulk-SEO-Tools and Trademarkia, rejecting trademarked items. Finally, it filters items to minimize listing competition by checking for existing ASINs on the target domain.
Volatile Item Fulfillment
Once a customer places an order, the abusive dropshipper fulfills it by ordering from a private seller using the customer's shipping details. The private seller ships the item with their return address, unaware of the dropshipping scheme (Figure 9).
Abusive dropshippers frequently withhold shipment information (F:s, I:m), avoiding tracking numbers for two main reasons: to prevent platform suspension if the shipping region differs from their listed address, and to prevent customers from becoming suspicious if tracking reveals a foreign origin. An interviewed participant stated, "if customers know the products come from outside where I am, I'll lose credibility." This lack of transparency harms customers who cannot track their orders. When platforms mandate tracking numbers, dropshippers resort to generating fake tracking numbers (F:f, I:f) using services like BlueCare Express or Packtrack (Figure 10). These services generate invalid or fake numbers that match input delivery deadlines and destination zip codes, sometimes manipulating status (e.g., always "shipped" or "delivered") or recycling existing tracking numbers from random orders.
The absence of formal agreements means abusive dropshippers have no guarantee of item stock. This leads to neglected or delayed orders (F:s, I:m) if the private seller runs out of stock, causing significant inconvenience for customers and potential reputational damage to the original seller's product.
Handling Returns
Returns also present significant complications (F:f, I:m). The return address on the package belongs to the private seller, creating logistical issues for the dropshipper. If the dropshipper provides their own address, they may lack a physical presence or storage, especially when operating internationally. To avoid negative reviews and platform reports, abusive dropshippers often prefer to issue a full refund and let the customer keep the item, particularly for lower-priced goods.
Strategies Across Marketplaces
Abusive dropshippers primarily target popular platforms like Amazon and eBay due to their vast customer bases. They employ generic countermeasures against platform protections, such as using fake tracking numbers, forging authorization letters, avoiding trademarked goods, and soliciting fake positive reviews. While smaller platforms might have looser enforcement, they are less attractive targets due to smaller market shares.
Five Abusive Dropshipping Characteristics
The research identified five distinct, observable characteristics (Table IV) that result from abusive dropshippers' behavior, designed for longevity, convenience, and profit:
- Item Categories (a1): Abusive dropshippers list a variety of categories (e.g., Electronics, Home & Kitchen) to cater to a broad customer base and maximize arbitrage opportunities.
- Items per Brand (a2): They typically have few listings per brand to minimize dependency and isolate delistings, reducing the impact of a single brand complaint.
- Brands Offered (a3): They source from many non-trademarked brands to strategically avoid infringement complaints and account suspension.
- Location (a4): Abusive dropshippers often operate from a different country than their target market, exploiting international shipping and pricing discrepancies.
- Prices of Items (a5): They prefer listing lower-priced items to minimize financial risk from trademark complaints and reduce losses when issuing full refunds to avoid negative feedback.
These aggregate characteristics, prevalent in forum discussions and observable on seller storefronts, stand in contrast to legitimate sellers who typically focus on niche products with many listings per brand and operate locally.
Technical Deep Dive
▶ Watch: In-depth comparison: compliant vs. abusive dropshipping (2:50)
The study employed a rigorous multi-faceted methodology (outlined in Figure 2 of the original research) to characterize abusive dropshipping, addressing key research questions about their methods, tools, and impact.
Data Collection and Analysis:
The process began with a query-based web search using terms like "dropshipping" and "dropship." An initial crawl of 238 web pages revealed that only 24% discussed abusive dropshipping. To improve relevance, phrases describing abusive operations, such as "dropshipping without permission," were extracted to enrich the query list, leading to a subsequent crawl of 931 web pages. The researchers then curated a dataset with a high density of abusive dropshipping content by identifying seven prominent online forums (listed in Table I-A). These forums were notably global, including non-English communities (Turkish, Vietnamese, Indonesian), which were translated using the Python Google Translate API. A targeted recrawl of these forums, using site filters and the enriched query list, yielded a total of 3,651 relevant discussion threads.
For forum analysis, a random sample of 30 threads from each of the seven forums was initially taken, totaling 210 threads per round. Two authors independently performed inductive coding to identify themes related to abusive dropshipping methods, tools, and harms. This iterative process continued until thematic saturation was reached at 1,050 threads, representing approximately 30% of the collected data. The high inter-coder agreement, with Cohen's Kappa greater than 0.80, underscored the reliability of the coding. Analysis revealed that approximately 25% of threads included discussions from private sellers alleging exploitation, while 70% involved discussions among abusive dropshippers themselves.
External Resources Analysis:
During forum analysis, two categories of external resources were identified and studied:
- Instructional Materials (Table I-B): Four widely-leveraged online courses and guides (text-based and video tutorials) were analyzed. For paid materials, only free previews were reviewed. Non-English content was processed using automated subtitles.
- Software Tools (Table II): Thirteen software tools frequently mentioned in forums as effective for dropshipping were investigated. These tools are often benign in their intended use but are exploited by abusive dropshippers. Their documentation was analyzed, and where possible, Chrome extensions were installed locally to understand their operational mechanics. The researchers deliberately excluded tools explicitly marketed for malicious use from Table II to avoid indirectly supporting abusive activities. However, one such malicious tool, Software-Mal, was analyzed separately to comprehend its capabilities.
Malicious Software Deep Dive (Software-Mal):
The analysis of Software-Mal provided a detailed understanding of how specialized tools facilitate abusive dropshipping. As illustrated in Figure 8, its execution flow involves several key steps:
- It crawls listing pages on source e-commerce platforms.
- It collects item names and brands.
- It filters out brands from a user-maintained Brand Deny List to avoid complaints and account suspensions.
- It then gathers crucial data such as price, shipping costs, and stock information.
- Crucially, it performs secondary filtering for trademark status by querying public services like Bulk-SEO-Tools and Trademarkia, automatically rejecting trademarked items from consideration.
- Finally, it filters items to minimize listing competition by checking if the same item is already listed on the target domain using ASINs (Amazon Standard Identification Numbers), saving the filtered results for manual inspection by the dropshipper.
Semi-Structured Interviews:
To bridge the gap in understanding the real-world impact, six semi-structured interviews were conducted with individuals possessing e-commerce expertise, including legal consultants advising affected sellers and experienced e-commerce sellers with at least two years of experience. Participants were recruited using purposive and snowball sampling. The interview protocol, designed to gather insights into the impact on customers, sellers, and platforms while minimizing bias (initially framed as "alternative dropshipping"), is publicly available. All participants were aware of both compliant and abusive dropshipping. Interview transcripts were inductively coded, reaching thematic saturation.
Ethical Considerations:
The researchers upheld strict ethical standards throughout the study. This included preserving privacy by not collecting personally identifiable information (PII), anonymizing participant identities, and paraphrasing forum quotes. They did not pay for any tools or guides marketed for abusive purposes. Importantly, the research findings were compiled into a detailed report and shared with ten e-commerce platforms and the Federal Trade Commission (FTC), with ongoing coordination for next steps, demonstrating a commitment to real-world impact and responsible disclosure.
Demo / Proof of Concept
▶ Watch: How abusive dropshipping differs from other e-commerce fraud (4:25)
While the talk did not feature a live, interactive demonstration of a proof-of-concept exploit in the traditional sense, the speakers meticulously detailed the operational mechanics and provided compelling evidence of abusive dropshipping through the analysis of real-world data and specialized software. This effectively served as a "proof of concept" for the scale and technical underpinnings of the abuse.
Specifically, the presentation offered a deep dive into the functionality of Software-Mal, a malicious tool designed to automate various aspects of abusive dropshipping. As described in the technical deep dive, this software's execution flow (illustrated in Figure 8) demonstrates a sophisticated, automated approach to item sourcing. It crawls listing pages, gathers item names and brands, and crucially, integrates with public services like Bulk-SEO-Tools and Trademarkia to identify and filter out trademarked items. This automated trademark evasion mechanism is a powerful illustration of how abusers leverage technology to circumvent platform policies. The tool also filters for existing ASINs on the target domain to minimize competition, showcasing a calculated strategy for market dominance.
Further "proof" of the widespread nature and economic impact of this abuse was presented through the analysis of a publicly referenced data dump, PasteFS 74. This dataset comprised 4,411 gap items listed over 15 months on Amazon MX, all sourced from Amazon US private sellers. The statistical breakdown of this data provided concrete evidence of the abusive dropshipping model in action:
- The items showed an average listing price of $43.70 (±$19) on Amazon MX, sourced for $21.40 (±$10.20) from Amazon US, resulting in a 104% average price increase.
- A specific example highlighted was a Hot Wheel Star Wars Stellar Vehicle Toy listed for $29.75 on Amazon MX, sourced for $11.61 from Amazon US, yielding an $18.14 profit—a 156% increase.
- The CDF of item prices (Figure 4) indicated that 90% of these gap items were priced under $61.09 USD, suggesting a focus on lower-value items to minimize risk.
- The most popular categories were Electronics and Home & Kitchen (Figure 5), and the top 20 brands were consistently lesser-known (Figure 6), reinforcing the strategy of avoiding trademarked goods and focusing on high-demand, low-visibility items.
This rigorous analysis of both specialized tools and extensive real-world transaction data served as a compelling demonstration of the operational capabilities and economic motivations behind abusive dropshipping, effectively proving its existence, scale, and the technical methods employed.
Defensive Implications
▶ Watch: Overview of data collection and research methodology (4:55)
The findings of this study offer crucial insights for e-commerce platforms, original sellers, and customers seeking to mitigate the pervasive threat of abusive dropshipping. The current reliance on manual reporting is demonstrably ineffective, allowing abusers to persist and inflict harm. A proactive, multi-pronged defensive strategy is urgently required.
- Automated Detection Mechanisms: The most significant defensive implication is the call for automated detection. The study's identification of five distinct, observable characteristics (variety in item categories, few listings per brand, many non-trademarked brands, international operation, and preference for lower-priced items) provides a robust foundation. These characteristics can serve as critical features for developing supervised or unsupervised machine learning models to identify abusive dropshippers. Platforms need to invest in research and development to integrate these features into their fraud detection systems. This would, however, require access to ground-truth labeled datasets from e-commerce platforms for training and validation. Furthermore, platforms must anticipate and account for adaptive dropshippers who may modify their behavior to evade detection, necessitating dynamic and continuously evolving detection models.
- Enhanced Platform Collaboration and Data Sharing: E-commerce platforms possess vast amounts of private attributes, such as payment methods, IP addresses, and intricate supply chain data, which are inaccessible to external researchers. By combining the study's findings with this internal data, platforms could establish more robust connections between abusive dropshippers, their source vendors, and consumers. For example, cross-referencing customer purchase addresses on a target domain with shipping addresses from private sellers on a source domain could effectively unmask abusive dropshipping operations. This necessitates greater inter-platform collaboration and potentially secure, anonymized sharing of transaction records to identify patterns that span multiple marketplaces.
- Improved Original Seller Reporting Interfaces: Original sellers are often the first to notice suspicious activity (e.g., a single customer placing multiple orders to different addresses, or unusual shipping destinations). Marketplaces should provide more intuitive and streamlined interfaces for original sellers to report suspected abusive dropshippers. These interfaces should allow sellers to easily flag suspicious orders and provide mechanisms for updating reports on verification status. Empowering original sellers with effective reporting tools can turn them into a crucial first line of defense, providing valuable intelligence for platform investigations.
- Proactive Monitoring for Deceptive Tactics: Platforms must implement more sophisticated systems to detect common deceptive tactics. This includes:
- Monitoring for forged documents: Implementing AI-driven document analysis to detect anomalies or known templates used for forged Letters of Authorization.
- Detecting fake tracking numbers: Integrating with known fake tracking services (like BlueCare Express or Packtrack) to identify invalid or manipulated tracking information. This could involve cross-referencing tracking numbers with carrier APIs and flagging discrepancies in status or origin.
- Stricter enforcement on trademarked goods: Implementing proactive scanning for new listings from unfamiliar sellers that feature well-known brands, especially if those sellers exhibit other characteristics of abusive dropshipping.
- Customer Education: While not a direct defensive measure, educating customers about the risks associated with third-party sellers exhibiting suspicious patterns (e.g., unusually diverse product categories, inflated prices for common goods, lack of tracking information, or foreign return addresses) can empower them to make more informed purchasing decisions and report suspicious activity.
By adopting these proactive and collaborative defensive strategies, e-commerce platforms can move beyond reactive manual reporting to build a more secure and trustworthy online retail environment, protecting customers, legitimate sellers, and their own reputations.
Key Takeaways
- Abusive dropshipping is a distinct and sophisticated form of seller-initiated e-commerce fraud, operating covertly without formal agreements, unlike legitimate dropshipping or gray-market selling, and has been largely unaddressed by prior research.
- Abusers exploit price discrepancies for "gap items", leveraging international shipping for profit, and actively avoid trademarked goods through underground collaboration, shared "allow lists" of non-risky brands, and forging authorization documents to evade detection.
- Deceptive fulfillment practices are central to the abuse, including withholding or faking tracking numbers (using services like BlueCare Express or Packtrack) to obscure foreign origins and avoid account suspension, leading to neglected orders and reputational damage for original sellers.
- Specialized software, both benign (e.g., Helium 10, AMZScout) and malicious (e.g., Software-Mal), is heavily utilized to automate item sourcing, filter for profitability, evade trademark checks (querying services like Bulk-SEO-Tools and Trademarkia), and minimize competition.
- Five observable characteristics provide a robust framework for automated detection: listing a variety of item categories, having few listings per brand, sourcing from many non-trademarked brands, operating from a different country than the target market, and preferring lower-priced items to minimize risk.
- The abuse inflicts significant harm across the e-commerce ecosystem, leading to inflated prices, poor service, and uncertain deliveries for customers, reputational damage for original sellers due to unauthorized listings, and erosion of trust and traffic for e-commerce platforms.
About the Speaker(s)
Arjun Arunasalam is a dedicated researcher in the field of cybersecurity, with a particular focus on understanding and mitigating emerging threats within digital ecosystems. As the presenter of "The Dark Side of E-Commerce: Dropshipping Abuse as a Business Model" at the NDSS Symposium, Arunasalam showcased his expertise in dissecting complex, real-world fraudulent operations. His work represents the first comprehensive study into abusive dropshipping, highlighting his commitment to exploring under-researched areas of seller-initiated e-commerce fraud. Through meticulous methodology, including extensive web crawls, forum analysis, software investigation, and expert interviews, Arunasalam and his team have provided foundational insights into the operational lifecycle, tools, and harmful strategies employed by abusive dropshippers. His ethical approach to research, including anonymization and proactive sharing of findings with ten e-commerce platforms and the Federal Trade Commission, underscores his commitment to translating academic discoveries into tangible real-world impact and fostering a more secure online environment.
All talks from Network and Distributed System Security (NDSS) Symposium 2024