Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

101–110 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#101
post #80

Earlier quoted context omitted.

(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG

[flagged]

Sheesh! Do you need a hug? Anyway, with chat GPT you can simply give it the image from the reddit post and get the OCRd and translated text. It's one step, it's fast, it's accurate enough. Why not use it?

Re: Thanks FedEx, this is why we keep getting phished

#103
post #81

Your security is increasing at risk from organisations and corporations whose own grasp of security is appalling. Because instead of dealing with it they externalise risks and consequences onto the public and customers. Even worse, is where attempts to query that security is actively punished . This is typical now. Listen here (at 42:20) with an example regarding the UK NHS whose incompetence plays directly into the…

Even worse, is where attempts to query that security is actively punished. like this case: https://news.ycombinator.com/item?id=37250024

Excellent example em-bee, thanks! I'm writing up a blog post on this subject, so more examples welcome plz.

Re: Thanks FedEx, this is why we keep getting phished

#104
post #34

Corporates are shockingly incompetent at this sort of stuff. Seriously just use your main domain for URLs. For me at least that clears up 99% of this. I dont want to memorise a list of valid mystery domains for each shipper. Is that really too much to ask?

It is. If they use their main domain, their normal corporate email will get blocked by anti-spam filters. So everyone uses a different, unrelated domain for bulk mails.

Okay, but this isn't a bulk email. It's a very specific situation personal to the receiver and will never be sent to anyone else. (Obviously the template will be used for multiple emails, but that's not what defines a bulk email, even though bulk emails can also be defined using a template.)

Re: Thanks FedEx, this is why we keep getting phished

#105
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training.

There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office365/gsuite mail flow permit-list controls, as an admin, to ensure that the phish test arrives correctly in peoples' inboxes.

Re: Thanks FedEx, this is why we keep getting phished

#107
post #46
post #43

Earlier quoted context omitted.

Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.

I wanted to, but I could not find it. It turn out I could not see the "report phishing" button because of an Outlook glitch. Thanks Microsoft.

Forward the email to your security org?

Re: Thanks FedEx, this is why we keep getting phished

#108
post #62

Earlier quoted context omitted.

My bank offers that and I use it to store backups of important files.

What makes bank a relevant or suitable service provider to store my "important files"? To store any files whatsoever other than those they're obliged to deliver to me?! "upload your testament, passport, and id documents here, you can trust us we are A BANK".

It's the electronic version of a safe deposit box

Re: Thanks FedEx, this is why we keep getting phished

#109
post #80

Earlier quoted context omitted.

(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG

[flagged]

It's often better at picking up context

Re: Thanks FedEx, this is why we keep getting phished

#110
post #27

Earlier quoted context omitted.

You mean everyone should install a piece of software from a company that appears to be ignorant about security?

And buy a very expensive tracking device with frequent security issues? I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.

interesting. Where is that? I would like to know more
Post reply on HN