Live data from Hacker News

SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

fredbenenson.com

131–140 of 152 posts

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#131

Earlier quoted context omitted.

As explained in the article, the scammers are using compromised Sendgrid domains to send the phishing emails. This means the emails are going to pass SPF/DKIM. Those domains are apparently owned by legitimate businesses which are actual Sendgrid customers. The phishers just compromised their account and API credentials

SendGrid's platform doesn't need to be the sender of these emails at all. It's just classic phishing, the emails can pass SPF, DKIM and DMARC as all of these rely on DNS resource records to be created on the RFC5321.MailFrom and/or RFC5322.From domain. Which is under control of the spammer. It's not pretending to be from sendgrid.com, if it was then these measures would help.

Correct, I think the confusion might arise because of the self replicating nature of this attack when the target domain is an MTA.

I can't pinpoint it exactly, but it might be a combination of the replication cycle of the attack being recursive and very short if the target is an MTA. But it may also be because the fact that sendgrid clients are sendgrid clients is public information.

Kind of how like meta companies are overrepresented in their medium, in a stock exchange banks are overrerpresented, lots of websites about building websites, lots of road ads are about placing road ads.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#132

relatedly, my wife received polititexts destined to her conservative father. The latest was actually genius IMO, in that it stated "Dear STEVEN, due to inactivity, your registration will be changed to DEMOCRAT in 20 minutes unless you navigate to this link." It, I assume, redirected to some support page to donate to the US conservative party or its affiliates. The social engineering is getting more effective

I don't know if the fact that it fully slipped into the absurd or the fact that it probably still worked on people is sadder. I do love the idea of voter registration oscillating back and fourth at 20 minutes intervals forever. Would make voting in the primaries way more exciting as the voter base kept flipping.

> I don't know if the fact that it fully slipped into the absurd or the fact that it probably still worked on people is sadder.

The thing is that that one plays on propaganda that people have already been conditioned to accept.

Very probably this person's father believes that the Democrats (a) control the state-operated voter registration system, and (b) manipulate it to their advantage. He believes that because he's been sent that message through a vast number of channels for many years. He would think it was absolutely in character for his registered party to be changed, and would probably think that would somehow affect how his vote was actually counted.

It's no more absurd than the idea that busloads of illegal aliens are showing up to vote "somewhere". Or whatever other idiotic lies they've been telling forever.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#133
The OP didn’t explain or showed the unsubscribe button compromise trick. Anyone here can shed some light on it?

I always had the habit of clicking on the unsubscribe button whenever I see an unwanted email. And I’d like to know what would happen if I click on malicious unsubscribe link.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#134

First thought... Why would ICE need donations? I then realized how unrecognizable scams have become to me now. Older people are going to be in a worse position.

You can donate to reduce the national debt, so it's not that far out of the realm of possibility that federal agencies would solicit donations, too. https://www.pay.gov/public/form/start/23779454

Donating to reduce the government debt is such a wildly dumb thing to exist. The US is currency sovereign! It has no risk of default on any debt denominated in USD!

The only reason a site like this exists is for politicians to distract from the fact that the budget of a nation with currency sovereignty does not actually have to raise revenues with taxes in order to spend money on services (and thus, be an excuse to cut services).

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#135
This speculative nonsense adds nothing:

> We know that state actors have invested heavily in understanding and exploiting these divisions. Russian active measures campaigns have been documented doing exactly this kind of work: identifying wedge issues and creating content designed to inflame both sides. North Korea has demonstrated similar sophistication in their social engineering operations by targeting academics and foreign policy experts

What about "read Twitter in between bouts of using one susceptible user's API key to spam other users for their API keys" _really_ requires the sophistication of a state-level actor? Statements like this aren't journalism, they're exactly the same kind of manipulation being used by the phishers.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#136
post #134

Earlier quoted context omitted.

You can donate to reduce the national debt, so it's not that far out of the realm of possibility that federal agencies would solicit donations, too. https://www.pay.gov/public/form/start/23779454

Donating to reduce the government debt is such a wildly dumb thing to exist. The US is currency sovereign! It has no risk of default on any debt denominated in USD! The only reason a site like this exists is for politicians to distract from the fact that the budget of a nation with currency sovereignty does not actually have to raise revenues with taxes in order to spend money on services (and thus, be an excuse to c…

Yeah donating for the debt is equivalent to literally burning money. The us’s biggest debt buyer is the US fed reserve. Bonds offered to foreign buyers absorbs loose worldwide cash. The supply of dollars is always less than demand because petroleum must be traded in dollars. And demand exceeds supply because IMF loans are denominated in dollars, plus interest, meaning that demand perpetually keeps going up because the interest keeps rising, simply because the clock ticks.

So what is the point of the debt? To convince govt should not be too big nor suck up to many of the worldwide human capital resources.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#137

Earlier quoted context omitted.

As explained in the article, the scammers are using compromised Sendgrid domains to send the phishing emails. This means the emails are going to pass SPF/DKIM. Those domains are apparently owned by legitimate businesses which are actual Sendgrid customers. The phishers just compromised their account and API credentials

SendGrid's platform doesn't need to be the sender of these emails at all. It's just classic phishing, the emails can pass SPF, DKIM and DMARC as all of these rely on DNS resource records to be created on the RFC5321.MailFrom and/or RFC5322.From domain. Which is under control of the spammer. It's not pretending to be from sendgrid.com, if it was then these measures would help.

Yes, as the article says, they seem to be using Sendgrid to phish Sendgrid customers because the UX is "xyz.com delivered by sendgrid.com", hoping that this is seen as legitimacy by the recipient.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#138
I’m more troubled by the fact these emails are hitting my sendgrid only email address.

Is this related to the breach that SendGrid said didn’t happen? I set my account up in 2021 for reasons I don’t recall and it’s since been deleted/deactivated by them.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#139
post #134

Earlier quoted context omitted.

You can donate to reduce the national debt, so it's not that far out of the realm of possibility that federal agencies would solicit donations, too. https://www.pay.gov/public/form/start/23779454

Donating to reduce the government debt is such a wildly dumb thing to exist. The US is currency sovereign! It has no risk of default on any debt denominated in USD! The only reason a site like this exists is for politicians to distract from the fact that the budget of a nation with currency sovereignty does not actually have to raise revenues with taxes in order to spend money on services (and thus, be an excuse to c…

> The only reason a site like this exists is for politicians to distract from the fact that the budget of a nation with currency sovereignty does not actually have to raise revenues with taxes in order to spend money on services (and thus, be an excuse to cut services).

This is not a mainstream view. This _is_ a view of MMT, which is rejected by the majority of current economists, and this context is probably important to people seeing this when it’s just presented as a well known fact

> In a 2019 survey of top U.S. economists not a single respondent agreed with the basic aspects of MMT

https://en.wikipedia.org/wiki/Modern_Monetary_Theory

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#140

Earlier quoted context omitted.

SendGrid's platform doesn't need to be the sender of these emails at all. It's just classic phishing, the emails can pass SPF, DKIM and DMARC as all of these rely on DNS resource records to be created on the RFC5321.MailFrom and/or RFC5322.From domain. Which is under control of the spammer. It's not pretending to be from sendgrid.com, if it was then these measures would help.

Yes, as the article says, they seem to be using Sendgrid to phish Sendgrid customers because the UX is "xyz.com delivered by sendgrid.com", hoping that this is seen as legitimacy by the recipient.

None of the examples in the article exhibit the 'via' UX. They were all sent with an aligned RFC5321.MailFrom and RFC5322.From (i.e. domain name used in both of those values is the same), those not matching is the most common reason to have the 'via' displayed [0]. They do have display names which pretend to be SendGrid.

0: https://support.google.com/mail/answer/1311182#zippy=%2Ci-ca...

Post reply on HN