Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.
About 7-8 years ago in France you’d get regular phone calls from actual humans running the same scam about a DHL or whatever packaging requiring duties to be paid. Plus the same SMS scams. Americans are lucky in they usually don’t have to buy from abroad and when they do, rarely is tax/duty payment required from the recipient (unlike many other parts of the world).
Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
21–30 of 75 posts
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#22Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#23Earlier quoted context omitted.
> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.
Do business with business that have local offices. That way anytime something needs verification or seems off, go into the businesses building.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#24Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#25USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#26The core challenge of phishing attacks is that USPS is not, in fact, the primary victim of these attacks.
The victims are distributed citizens who fall for the scam. USPS doesn't have very many levers available to them to address the attacks (besides a warning on their site, which they have), but also doesn't 'feel' the impact so would have a hard time justifying substantial investment in addressing it.
Ultimately the solution needs to come from regulatory regimes that target fraud, particularly SMS message spam.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#27USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
I wonder if the .com TLD is part of the GOP campaign to kill the USPS
Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#28USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#29I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…
Is detecting phishing all that straightforward? As banks, travel agents, and even governments, are all terrible at avoiding the signalling of phishing. Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for. https://www.equifaxsecurity2017.com/ This looks like phishing. But it is legitimate.
This is a huge issue and it seems like we've just given up on it. There used to be EV SSL certs, but they are essentially dead now. There's BIMI for email, but support is mixed, and only partly addresses the issue.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#30Earlier quoted context omitted.
About 7-8 years ago in France you’d get regular phone calls from actual humans running the same scam about a DHL or whatever packaging requiring duties to be paid. Plus the same SMS scams. Americans are lucky in they usually don’t have to buy from abroad and when they do, rarely is tax/duty payment required from the recipient (unlike many other parts of the world).
In Germany we get those phishing SMS too, but I think the US is probably worse off, as they get way more phishing calls (which I think are more effective) as scammers in Nigeria or India usually don't speak German or French...