Live data from Hacker News

Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

akamai.com

11–20 of 75 posts

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#11
post #5

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.

Do business with business that have local offices. That way anytime something needs verification or seems off, go into the businesses building.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#12
post #6

Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.

I dont get sms but amount of spam in gmail inbox about Swiss post (I live here but not native) is staggering.

Luckily they still look so lame its trivial to spot them, and gmail is doing a fine service filtering them right into spam.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#13

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

Is detecting phishing all that straightforward? As banks, travel agents, and even governments, are all terrible at avoiding the signalling of phishing. Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for. https://www.equifaxsecurity2017.com/ This looks like phishing. But it is legitimate.

Even tech companies do this wrong. Github had it's upcoming/beta features on githubnext.com and even sent out auth related e-mails from there. I wanted to test their new features but when I got the email I lost my faith in them and opted not to.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#14
post #5

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.

I ranted about something similar when it came how the US Internal Revenue Service was implementing authentication for their free-filing service.

They're training taxpayers to put in large amounts of extremely sensitive personal information into a third-party domain called "id.me". Even if you trust the private company, I think it's insane they didn't at least whitelabel the process through a *.irs.gov domain!

(For those curious, the .me TLD is run by the country of Montenegro. Control over DNS has some security implications for phishing and man in the middle attacks.)

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#15
post #6

Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.

About 7-8 years ago in France you’d get regular phone calls from actual humans running the same scam about a DHL or whatever packaging requiring duties to be paid. Plus the same SMS scams.

Americans are lucky in they usually don’t have to buy from abroad and when they do, rarely is tax/duty payment required from the recipient (unlike many other parts of the world).

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#16
post #5

Earlier quoted context omitted.

> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.

Do business with business that have local offices. That way anytime something needs verification or seems off, go into the businesses building.

When a Canadian gov agency calls, a good reverse verification method is to test their French.

« Êtes-vous une pamplemousse? »

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#17
post #6

Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.

In 2019, when I landed in Hamburg, I got a scam SMS before the "Welcome to germany"-SMS. IOW, the scammers managed to consume the "new arrival" event somehow, and send out their own scam. Tells a lot about how much the telcos actually care / are a part of these scams.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#18

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

Is detecting phishing all that straightforward? As banks, travel agents, and even governments, are all terrible at avoiding the signalling of phishing. Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for. https://www.equifaxsecurity2017.com/ This looks like phishing. But it is legitimate.

It is not straightforward, and it is complicated by a number of factors. The first would be bad "brand hygiene": If a company has dozens of legitimate domains across different TLDs, different providers and different geographical locations then it's already more complicated than just one canonical .com domain. If teams within the company are permitted to spin up their own domains (e.g. marketing campaigns, branch offices) then it gets 10x worse. Lastly if a legitimate brand frequently changes its appearance, it will be harder to pin down the true brand identity.

But even if you follow all of these best practices there are still powerful attack vectors. A threat actor could host their phishing page on an unrelated (compromised) domain with good domain reputation, in that case you wouldn't even know about that site until the first email or SMS hits your customers. Or the threat actor could use one of the many file-hosting or website services to create their site and host it on a shared third-party domain with perfect domain reputation (e.g. amazonaws.com).

And then there's incentive: It's no the companies that suffer financial losses, it is their customers. If you were talking about their employees being phished that would be a different story. Same thing for Google Safe Browsing: Their incentive is to protect against most of the obvious phishing, without any false positives, ever. If they are slow to detect something they won't suffer any losses. If they generate a False Positive their Chrome browser might suffer significant reputational damage if a popular legitimate domain is blocked.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#19

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about it one day" shrug This is my problem with almost every "report spam/fraud/etc" flow. It's always a digital shrug, and then nothing happens. Only one site I know of ever had it right: Instagram, up to about 2021. When you reported an account or post, you would actually be notified…

Generally, I find the effectiveness of feedback is inversely proportional to the ease of submitting it.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#20
I get no spam, until I send something...then it's an avalanch for a few weeks then they dry up until next time I need DHL (or, indeed, any other carrier - €40 to send a registered letter, DHL priced themselves out of my budget).
Post reply on HN