Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

131–140 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#131
I received once a mail from my bank at the time stating that they have a message for me, but for security reasons I have to read it on their systems. And they provide the following link: https://cbk.pwlnk.io/~hc

The bank's name is CaixaBank. I was wrong and the message was legit. My first thought was it was a scam :)

Re: Thanks FedEx, this is why we keep getting phished

#132
post #3

Maybe its just the hunan brain bad at perception, but I feel like there's some system compromised and info is leaked so scammers know when you are expecting a package because FedEx/USPS spam text increases.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package?

Some people still prefer to buy most things directly in physical stores. For me, would be easier to list the few times when I am expecting a package. And even then, I'm expecting the package, not some random message about it; it usually arrives without any notification at all (and the tracking on the site is usually delayed).

Re: Thanks FedEx, this is why we keep getting phished

#133
post #80

Earlier quoted context omitted.

(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG

[flagged]

do you get google points for using google translate or something I'm not aware of?

Re: Thanks FedEx, this is why we keep getting phished

#134
I frequently buy things from Tokopedia, one of the largest e-commerce in Indonesia.

At one point, I ordered something, and the next day, someone contacted me through WhatsApp, claiming to be from the courier (with the company logo as a profile picture). They said my package was rerouted, and I had to click a link to fill out some form. Typical scam message, with typo and urgency. I can track the status of my order in the app, and it says it's in transit somewhere. So, their explanation matches.

You might think, "Well, that's obviously a scam. They would not contact you through personal WhatsApp!" But sometimes couriers DO contact you to ask for your precise location or notify you, "Hey, I left your package with your neighbor. Here's the photo."

I'm just wondering how the scammer got this info that Mr X is expecting Product Y from Shop Z. I almost fell for it (I was in the middle of something and got distracted), and I can only imagine the unlucky victims.

It happened 2-3 times during that period and then gone. Did someone find out and fix it? How did they find out? Because I'm guessing there are lots of hands involved in the delivery pipeline.

Re: Thanks FedEx, this is why we keep getting phished

#135

DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if yo…

Same in Canada, though, if I understand correctly, you have to visit a customs checkpoint in person to make a declaration: https://goingawesomeplaces.com/how-to-avoid-paying-ups-broke...

Re: Thanks FedEx, this is why we keep getting phished

#136
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

Re: Thanks FedEx, this is why we keep getting phished

#137
post #116

Earlier quoted context omitted.

There are more possible realities. You listed the 3 first. There are more options, at least these: 4. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have kept your extra taxes for themselves in the end. 5. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have paid the extra taxes. The government kept them because, hey, they trust Fedex. 6…

I mean, either I paid the taxes when I bought the stuff, or I didn't. There's no reality where I "didn't pay the taxes when [I] bought the stuff" and also I "pay out of pocket", since I have not paid anything after placing the order. I guess there's also the possibility that I paid for the taxes but the seller ended up pocketing them, with FedEx footing the bill.

Sorry, I was unclear.

I mean in the general case - how much does FedEx win or loose from problems like this?

If they win, do they exploit it, by design or incompetence?

Re: Thanks FedEx, this is why we keep getting phished

#138

Earlier quoted context omitted.

I was prepared to disagree with you, but I now have the same interpretation you have. Durable medium can be email - but the example seems a little fuzzy, for instance a durable medium is definitely when the email is stored on a HDD on a customer device. But is it still durable medium if the email only exists in a webmail? Probably yes, but maybe no. So the conservative approach would be to send paper for some things.…

That doesn't fix the issue though. The issue is a killer USB or a virus on the disk. Being able to only read an infected file still allows it to be read. Also, this is only a software solution as the USB protocol would require bidirectional transmission.

It doesn't fix the issue vs paper.

But it would bring us back to being as safe as a CD or diskette was.

I was thinking a special chip, talking bidirectionally both ways, pretending to be a PC host to the USB drive, and pretending to a DVD-ROM to the actual PC.

Re: Thanks FedEx, this is why we keep getting phished

#139

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

It leads to less security as it is more likely that the new password will just be an old one with an incremented number at the end.

Re: Thanks FedEx, this is why we keep getting phished

#140

One out of ~10 international shipments of records I had in the last year one was from FedEx and they sat on it in their out for delivery warehouse in a nearby town for two months with the usual pass the buck/pillar to post treatment. The extra fees plus customs they put on added up to 40% of the value of the items as well. DHL and UPS arrive within a week and are normally no higher than 25%

FedEx seems to be the worst option domestically too. Maybe it depends on your location but they're the only service that somehow fails to deliver signature required packages to my mail room. I've also tried to have them contact me directly while I wait at home and I've tried to waive the signature requirement online, but they still just say "delivery attempted" for 3 consecutive days and then hold stuff at their warehouse. Happened to me twice recently. I now try to avoid buying anything expensive that uses FedEx to ship.

A funny thing I discovered in this process is that "delivery instructions" are shared for all packages to a given address regardless of the associated name, and never flushed unless you go in and do it manually on their website. I found the name and contact information for the prior tenant of my unit on the FedEx site with no other info besides 1 tracking number to the address (it also let me change the delivery instructions with said info). Potentially they were still calling that person when they tried to deliver initially, though I have other reasons to doubt they actually came to the door that day.

Post reply on HN