Thanks FedEx, This Is Why We Keep Getting Phished (2024)
1–10 of 86 posts
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#2Do they build their own software or contract it to the consultants?
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#3Discussed previously, 2024, 564 comments: https://news.ycombinator.com/item?id=39479001
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#4I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...
List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#5I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#6In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#7There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#8[flagged]
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#9This shit drives me insane. Last year I had my home insurer send me a link in an SMS pointing me to allstate.yem.bo to collect some information. Stop training your users to get phished!!
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#10In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
Whois has been replaced by RDAP.