Live data from Hacker News

Crates.io phishing attempt

fasterthanli.me

31–40 of 83 posts

Re: Crates.io phishing attempt

#31

I got an official email from Paypal last week saying that I had a charge for $900 at Kraken, and to call some number if it's suspicious. What's great about the attack is that it's sent from paypal.com and signed by paypal. And the email contains a legit link to paypal, not some phishing site. But the phone number is the attack. The attack: 1. Register a paypal business account 2. Add the victim's email address (or on…

Let's say someone falls for this.

What happens next, when they become the business account secondary user?

Re: Crates.io phishing attempt

#32

I got an official email from Paypal last week saying that I had a charge for $900 at Kraken, and to call some number if it's suspicious. What's great about the attack is that it's sent from paypal.com and signed by paypal. And the email contains a legit link to paypal, not some phishing site. But the phone number is the attack. The attack: 1. Register a paypal business account 2. Add the victim's email address (or on…

This kind of incompetence should result in PayPal loosing its banking permits in the EU. This is unacceptable and there is no way for an average person to identify the fraud and that is PayPal's fault.

There should be no way to send custom text from Paypal to a stranger. They don't even parse out phone numbers!

Re: Crates.io phishing attempt

#33

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

Definitely. I get scammers calling me from a caller id that claims to be my bank asking about suspicious charges, and they know my name and have my account info, but they ask for my full credit card number to "verify" it. Yet, they give different suspicious charges every time you ask.

The worst part is that when I call the bank to see if its legit, they are much less pleasant to deal with than the scammers...

Re: Crates.io phishing attempt

#34

I got an official email from Paypal last week saying that I had a charge for $900 at Kraken, and to call some number if it's suspicious. What's great about the attack is that it's sent from paypal.com and signed by paypal. And the email contains a legit link to paypal, not some phishing site. But the phone number is the attack. The attack: 1. Register a paypal business account 2. Add the victim's email address (or on…

Let's say someone falls for this. What happens next, when they become the business account secondary user?

I added to my comment, but when you call the number, you talk to the attacker and they ask you questions about you and your account. Maybe they try to buy crypto with it or they prime you to go to some attack website and use your paypal account to buy something.

Re: Crates.io phishing attempt

#35

I got an official email from Paypal last week saying that I had a charge for $900 at Kraken, and to call some number if it's suspicious. What's great about the attack is that it's sent from paypal.com and signed by paypal. And the email contains a legit link to paypal, not some phishing site. But the phone number is the attack. The attack: 1. Register a paypal business account 2. Add the victim's email address (or on…

Let's say someone falls for this. What happens next, when they become the business account secondary user?

[deleted]

Re: Crates.io phishing attempt

#36

I got an official email from Paypal last week saying that I had a charge for $900 at Kraken, and to call some number if it's suspicious. What's great about the attack is that it's sent from paypal.com and signed by paypal. And the email contains a legit link to paypal, not some phishing site. But the phone number is the attack. The attack: 1. Register a paypal business account 2. Add the victim's email address (or on…

This kind of incompetence should result in PayPal loosing its banking permits in the EU. This is unacceptable and there is no way for an average person to identify the fraud and that is PayPal's fault. There should be no way to send custom text from Paypal to a stranger. They don't even parse out phone numbers!

[deleted]

Re: Crates.io phishing attempt

#37

Earlier quoted context omitted.

When you grab a domain which is plausibly very similar to the legit domain the organization you work with is using, you can forge emails that will make your email client show all sorts of “verification passed” badges next to them. You can further appeal to developers’ geeky hearts by not making language mistakes and actually using verbiage present in real emails as sent by them. You can exploit recent supply chain at…

> Don’t worry, when they actually target you, you’ll be caught. When they target me, which happens, it doesn't work because of WebAuthn. Buy a Security Key. If you think you might lose it, buy at least two more. For critical sites like GitHub (which was targeted here) set up your Security Keys and get into the habit of relying on them. It's the same philosophy as Rust itself, machines are really good at diligently pe…

"Your WebAuthn key enrollment period has expired. Please log in to re-enroll a new key."

Something similar to this was in the recent npmjs thing.

Re: Crates.io phishing attempt

#38

I got an official email from Paypal last week saying that I had a charge for $900 at Kraken, and to call some number if it's suspicious. What's great about the attack is that it's sent from paypal.com and signed by paypal. And the email contains a legit link to paypal, not some phishing site. But the phone number is the attack. The attack: 1. Register a paypal business account 2. Add the victim's email address (or on…

Wow, thats pretty bad. Reminds me of the old Paypal Invoice scams where scammers would upload the paypal logo as the invoice logo (which appears top left) and essentially “bill” the user. The scammer the adds inside the invoice note a paragraph explaining “Your money is being held due to currency exchange issues”, which gives basic reason to the “monetary deduction”. It got me as a kid, was quite slick for the time. Thought these scam-methods would be at least flagged these days before going out.

Re: Crates.io phishing attempt

#39
post #33

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

Definitely. I get scammers calling me from a caller id that claims to be my bank asking about suspicious charges, and they know my name and have my account info, but they ask for my full credit card number to "verify" it. Yet, they give different suspicious charges every time you ask. The worst part is that when I call the bank to see if its legit, they are much less pleasant to deal with than the scammers...

> The worst part is that when I call the bank to see if its legit, they are much less pleasant to deal with than the scammers...

+1

This is so true. I just never realized that is why I'm always tempted to not bother doing the right thing.

Re: Crates.io phishing attempt

#40
This is funny. The site https://github.rustfoundation.dev now only contains a single image that is the buff doge vs cheems meme.

Chad Rust Devs

vs.

Virgin NPM Devs Falling For Phishing

Amusing. You have to ignore SSL to get the image since the site has HSTS enabled.

A coincidence is that today I got a "two factor code from Coinbase. If you did not request this, call this number". Ho ho ho. Yes, I will call your number, Coinbase.

Post reply on HN