Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

1–10 of 187 posts

Re: I was seven words away from being spear-phished

#2
I don't understand the point of using compromised Cambridge accounts for this. All they wanted people to do was to just click on a link. They could have easily registered some legitimate sounding domain name and linked to that instead. It wouldn't be unusual at all for an academic organisation to have a separate site.

Re: I was seven words away from being spear-phished

#3

I don't understand the point of using compromised Cambridge accounts for this. All they wanted people to do was to just click on a link. They could have easily registered some legitimate sounding domain name and linked to that instead. It wouldn't be unusual at all for an academic organisation to have a separate site.

A compromised Cambridge url gives a lot of credence to their claim though, especially with the paranoid coinbase developer they were targeting.

Re: I was seven words away from being spear-phished

#4

I don't understand the point of using compromised Cambridge accounts for this. All they wanted people to do was to just click on a link. They could have easily registered some legitimate sounding domain name and linked to that instead. It wouldn't be unusual at all for an academic organisation to have a separate site.

It is a prestigious domain - with a high recognition factor. And, as part of that, it will almost never be blocked by URL / DNS filters.

In this case, it clearly worked. The user saw cam.ac.uk and trusted it.

Re: I was seven words away from being spear-phished

#5
post #3

I don't understand the point of using compromised Cambridge accounts for this. All they wanted people to do was to just click on a link. They could have easily registered some legitimate sounding domain name and linked to that instead. It wouldn't be unusual at all for an academic organisation to have a separate site.

A compromised Cambridge url gives a lot of credence to their claim though, especially with the paranoid coinbase developer they were targeting.

It also means the e-mail is significantly more likely to make it past a spam filter, even an aggressive one. There was very little in that e-mail any reasonable spam filter could possibly have flagged, unless they're going to start doing API calls to grammarly. But if they check spelling and grammar, filters will start flagging a lot more than spam.

Re: I was seven words away from being spear-phished

#7
post #5
post #3

Earlier quoted context omitted.

A compromised Cambridge url gives a lot of credence to their claim though, especially with the paranoid coinbase developer they were targeting.

It also means the e-mail is significantly more likely to make it past a spam filter, even an aggressive one. There was very little in that e-mail any reasonable spam filter could possibly have flagged, unless they're going to start doing API calls to grammarly. But if they check spelling and grammar, filters will start flagging a lot more than spam.

.ac.uk emails get spam filtered pretty harshly.
Post reply on HN