Live data from Hacker News

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

troyhunt.com

41–50 of 86 posts

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#41

This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package. I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it…

I've gotten the same from FedEx several times over the years. It never gets less weird.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#42

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it w…

Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate.

Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#43

Earlier quoted context omitted.

It didn't change anything though, if you have the money you can just buy more.

Also this was never a real problem. "All the good names are taken" is true if you insist that every name which isn't taken is a bad name but otherwise obviously false. The same exact "Somebody already had the good ideas, it's not my fault I'm just too late" whining can be seen centuries ago. People who live in a world with no electricity, absolutely convinced that every product which will ever be wanted already exist…

There are plenty of Chinese domains that are just numbers. If they can build entire businesses off of that, so can anybody. There's of course a ton of risk around scammers winning SEO and adwords competitions.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#44

Earlier quoted context omitted.

I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else.

> The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the link…

Or more likely IMO, FedEx HQ said "you can't use our domain to collect foreign tax payments" and so it got outsourced to a service in Australia. And a lot of these "collect payments as a service" sites just look and feel like something that was developed in 1995 and never updated. I run into them everywhere, from local governments to medical and legal offices, small utility companies, etc. I have no idea how they pass PCI audits.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#45

In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.

not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam.

But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing...

I understand the idea that they want an official TLD that doesn't necessarily have their trademark in it, so you know it's a link to a Google service but potentially user content, but why have c.gle links to official/urgent messaging??

(at least they don't use 1drv.com in emails like Microsoft.. seriously...)

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#46

Earlier quoted context omitted.

I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else.

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Just today I saw an e-mail from "onmicrosoft.com" that was completely legit. I wonder how many domains MS is running these days. It seems like each department and project gets its own.

Every time I see a new Microsoft domain I've never seen before, I have to double check that it's actually legit. Every time I realize anew why people still fall for phishing attempts, because all these legit domains look like phishing attempts.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#47

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it w…

Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate. Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need…

FWIW, they put a header in the message that you can spot from a thousand miles away. That is how they get past the filters.

I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely.

It’s compliance theater. No real security is gained, but it checks all the boxes.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#48
post #4

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

Not helped by legitimate websites often redirecting you through weird multi tiered domains especially during log in, or legitimate businesses using link shorteners instead of their full domains, or more and more businesses themselves hopping on new TLDs, like the recent cloudflare wallet release.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#50
I wonder how we could describe this so that aging non-technical executives understand.

"It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."

Post reply on HN