(IPv6 is currently safe... for now...)
Scammers are abusing an internal Microsoft account to send spam links
181–190 of 196 posts
Re: Scammers are abusing an internal Microsoft account to send spam links
#182A while back I had a reservation with a hotel on Booking and I received a phish attempt that came directly via the Booking site domain email and also DMs but "sent" by the hotel. When I looked into it at the time, it seemed less like an issue of hotels specifically having their accounts infiltrated and more like some kind of message/email endpoint on Booking's end was being abused in a similar manner. I'm not sure th…
I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_
Re: Scammers are abusing an internal Microsoft account to send spam links
#183Earlier quoted context omitted.
I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_
Hotels should start giving 5-star reviews to their guests I suggest!
Re: Scammers are abusing an internal Microsoft account to send spam links
#184Re: Scammers are abusing an internal Microsoft account to send spam links
#185Earlier quoted context omitted.
Unfortunately in the US, maybe elsewhere, pharmacies and medical offices have trained the elderly it’s okay to verify their dob when they call. Costco does that when they call and it drives me nuts.
US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.
Just for a discount?
Re: Scammers are abusing an internal Microsoft account to send spam links
#186Earlier quoted context omitted.
This is very much my experience. I generally say at some point before terminating the call "you should not train your customers to give out account access credentials to strangers" and the caller usually has no clue what I mean. Does no one in the security teams have theory of mind? This will be the way I bring up the issue with the regulator if I do. I can think of many ways round this issue that would be much safer…
The caller is a minimal wagie following a script, you can't get mad at them. The chucklefuck that wrote the script that you can get mad at won't pick up your calls. That's how responsibility works.
Re: Scammers are abusing an internal Microsoft account to send spam links
#187Earlier quoted context omitted.
US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.
Why would anyone stick with an insurer that clearly doesn’t give a darn about them? Just for a discount?
Re: Scammers are abusing an internal Microsoft account to send spam links
#188I mean, it happened to the FBI... https://krebsonsecurity.com/2021/11/hoax-email-blast-abused-...
>The FBI is aware of a software misconfiguration That's not a misconfiguration, that's incompetence. How do these people get hired?
Re: Scammers are abusing an internal Microsoft account to send spam links
#189Earlier quoted context omitted.
US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.
Why would anyone stick with an insurer that clearly doesn’t give a darn about them? Just for a discount?
Also, if 'Just for a discount' isn't a reason to use them, do you have $3,000 lying around to wire me? If you do, I'll happily switch to a much more expensive insurer that meets my other criteria, and might or might not send me marketing materials disguised as fishing SMS. (I'll let you know if they do.)
---
Insurers aren't banks or ISPs or gas stations. They don't provide a fungible service that is nearly identical from one to the other. You can't 'just switch'. They are both heavily obfuscated, and heavily differentialized, because the healthcare 'market' is obfuscated and heavily balkanized.
And all of them are utter shit, but in different ways, and if you are lucky, you won't discover the ways in which yours is shit.
---
[1] How this isn't a statutory capital crime for anyone with the rank of director and higher, I have no idea. But the fact that the people orchestrating this are permitted in civil society does lead me to believe that maybe we don't live in a just world.
Re: Scammers are abusing an internal Microsoft account to send spam links
#190Earlier quoted context omitted.
Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.
Oh man that brings back memories! "Hello, I'm calling from Blockchain, I would like to talk about your investment portfolio" it weirded me out they would pretend to be from the underlying technology instead of an exchange or something. I kept thinking I should pretend to be the CEO of TCP/IP or something when they called.