Live data from Hacker News

USPS jumps to first place as most imitated brand in phishing attacks

guard.io

11–20 of 74 posts

Re: USPS jumps to first place as most imitated brand in phishing attacks

#11

The networks did such a good job for so long keeping spam out that people almost inherently trust sms, I've had to help multiple people with fallout from these types of texts.

I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point, but you're saying networks did a good job protecting against SMS spam and this is the reason why people trust it?

Re: USPS jumps to first place as most imitated brand in phishing attacks

#12
I heard about this scam a couple months ago, but finally got a text myself last week. I didn't click the link for obvious reasons, but looking only at the text itself, it was hard to tell if they were mimicking USPS or UPS. The domain they were using was just some random string like "USPUSU" or something like that.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#14

Just heard from a client last week who had their credit card compromised and while waiting for their new card to arrive via mail, had more of their cards compromised by a USPS phishing text. The scam was basically a text that said "there was a problem mailing your new credit card" which lead to a USPS cloned website that asked for $0.30 to resolve the issue. My client tried two credit cards (each "failed") before fin…

I'm continually astounded how many people will be asked for a credit card through no direct action of their own (e.g. an unsolicited text not part of a conversation they initiated) and will just do it. And multiple times!

Edit to be clear: I don't think these people are dumb, and I'm sure there is some scenario in which I could fall victim to a similar claim. This is more a comment on people generally as opposed to "those people."

Re: USPS jumps to first place as most imitated brand in phishing attacks

#15

Fuck the USPS for allowing advertisers to bulk send junk mail to everyone for a couple dollars. It’s a daily chore to take out the mailbox trash before it’s so full they start returning important letters back to sender for not being able to fit it in.

You know you can fill out one form and 90% of it will stop?

Re: USPS jumps to first place as most imitated brand in phishing attacks

#16

Fuck the USPS for allowing advertisers to bulk send junk mail to everyone for a couple dollars. It’s a daily chore to take out the mailbox trash before it’s so full they start returning important letters back to sender for not being able to fit it in.

maybe you should instead fuck your legislators so they can make that practice illegal (getting adverts per mail without consent). Where I live it's opt out, so not ideal either but at least I don't have to put up with the trash after adding a sticker to my post box.

You clearly haven't seen my legislators.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#17
post #11

The networks did such a good job for so long keeping spam out that people almost inherently trust sms, I've had to help multiple people with fallout from these types of texts.

I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point, but you're saying networks did a good job protecting against SMS spam and this is the reason why people trust it?

Spam delivered over SMS and the security (perceived or real) of SMS-based 2FA are entirely different subjects, though.

But to kibitz on the second: a validated phone account remains by far the easiest 2FA mechanism to deploy and rely on, and 2FA remains by far more secure than simple password authentication. Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#18
I get at least 5 of these a day between SMSes, iMessages from compromised iCloud accounts, and emails. And it does suck, because I do a lot of shipping and receiving for my business, and I DO get emails from the USPS for owing various amounts of overage on my outgoing shipments. When my scale weighed something as 4oz, but theirs as 5oz, that is the next level up in shipping cost (at least for Ground Advantage and Priority Large Envelope).

Re: USPS jumps to first place as most imitated brand in phishing attacks

#19

Yup, I've gotten a couple of the USPS texts per month for the last few months now. The USPS will never text you, I asked. They only do things by mail :]

> The USPS will never text you, I asked. They only do things by mail :]

Rather the USPS will never text you unprompted. There are a number of services (like package tracking) where the USPS will text you.

PS: Sorry for the pedantry

Post reply on HN