Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

111–120 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#111
post #27

Earlier quoted context omitted.

You mean everyone should install a piece of software from a company that appears to be ignorant about security?

And buy a very expensive tracking device with frequent security issues? I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.

And where is this?

Re: Thanks FedEx, this is why we keep getting phished

#112
post #89
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

Our government uses equivalent of www.mydatabox.cz (real one is mojedatovaschranka.cz).

Literally a domain that looks like from teaching material for phishing, no databox.gov.cz or something like that.

The domain is for an official legal documentation communication with government and has same legal weight as letter that was person delivered and recipient was checked against ID.

Re: Thanks FedEx, this is why we keep getting phished

#113

When I bought a car once, I received an email a few months later saying I hadn't proven I had obtained insurance on it, and the bank wanted me to visit a domain that wasn't theirs to provide proof. The email I got looked like a badly-scanned letterhead and was very, very fishy. After I received a few of them, I finally contacted the bank and it was legit . I tried telling the office person (not just a clerk at the co…

Happened to me with my mortgage. Got this very weirdly phrased letter about how my homeowner insurance info needed to be updated/confirmed and that I had to go to to clear it out.

I called my insurance broker and yes indeed it was legit. I also tried to explain to them how this letter was a few steps removed from a Nigerian prince scam based on all the red flags, but i don't think it made a big difference.

Re: Thanks FedEx, this is why we keep getting phished

#114
post #80

Earlier quoted context omitted.

(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG

[flagged]

I've seen ChatGPT translate English to German miles ahead of what Google translate does.

Like an English satirical poem to perfect German. Changing the literal translation to keep the meaning and sarcasm of the poem.

Re: Thanks FedEx, this is why we keep getting phished

#115

DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if yo…

I've often felt frustrated by the processing fees. Can you elaborate on handling this yourself? Which EU country are you based in?

Re: Thanks FedEx, this is why we keep getting phished

#116
post #21

Earlier quoted context omitted.

Our local FedEx once asked me for my details so they could be able to declare my package to the customs and in the SMS message they said that "The sender is paying all declaration fees." I sent them my info and got my package. Then about five months later, I got a bill from FedEx for import fees, tax and service charges. Had to fight with FedEx for some time about it but eventually they agreed to void the bill. At th…

There are more possible realities. You listed the 3 first. There are more options, at least these: 4. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have kept your extra taxes for themselves in the end. 5. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have paid the extra taxes. The government kept them because, hey, they trust Fedex. 6…

I mean, either I paid the taxes when I bought the stuff, or I didn't. There's no reality where I "didn't pay the taxes when [I] bought the stuff" and also I "pay out of pocket", since I have not paid anything after placing the order. I guess there's also the possibility that I paid for the taxes but the seller ended up pocketing them, with FedEx footing the bill.

Re: Thanks FedEx, this is why we keep getting phished

#117

Earlier quoted context omitted.

What makes bank a relevant or suitable service provider to store my "important files"? To store any files whatsoever other than those they're obliged to deliver to me?! "upload your testament, passport, and id documents here, you can trust us we are A BANK".

It's the electronic version of a safe deposit box

I can understand that marketing message making sense and appealing to.. some people; I am surprised to see it on HN though.

This is like buying vegetable & olive oils from BP or Shell because they're oil experts looking for new income streams as we shift away from petroleum.

Re: Thanks FedEx, this is why we keep getting phished

#118
post #89
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

I’m supposed to pay my semi-annual property taxes (on the order of ~thousands of USD) on a site that ends in .org instead of .gov, and nobody apparently sees anything weird or wrong with it.

Re: Thanks FedEx, this is why we keep getting phished

#119
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

> I think IT incompetence should lead to audit fails or even better delisting from exchanges.

Fear of policy is why you get things like "force us to change our passwords every 6 months and block the last twenty". Getting a central arbiter of IT competence is a hard problem.

Re: Thanks FedEx, this is why we keep getting phished

#120
Here dutch customs doesn't even send you links for this stuff over SMS due to all the spam.

They tell you to look up the package tracking number on the PostNL (the national universal delivery company) where you can pay for it. All you get over SMS is a heads-up to check and the ID to enter (you need to combine it with your zipcode).

Post reply on HN