Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

31–40 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#31
My best theory is that FedEx outsourced the process of sending these SMS notifications to some external contractor.

Of course, the scammers already have the scam systems in place, so they can win the bid on price :D

I know this sounds ridiculous, but I doubt anything will make better sense than this :P

Re: Thanks FedEx, this is why we keep getting phished

#32
A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received:

- Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them from a domain that I can immediately link to the company. - No alternative way of resolving the issue is provided other than clicking on one of those links (no "go to your account settings", "contact your line manager" or so).

And still, it turns out it was real.

~100k employees company btw

Re: Thanks FedEx, this is why we keep getting phished

#33

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

There's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.

Re: Thanks FedEx, this is why we keep getting phished

#34
Corporates are shockingly incompetent at this sort of stuff.

Seriously just use your main domain for URLs. For me at least that clears up 99% of this.

I dont want to memorise a list of valid mystery domains for each shipper. Is that really too much to ask?

Re: Thanks FedEx, this is why we keep getting phished

#35
When I bought a car once, I received an email a few months later saying I hadn't proven I had obtained insurance on it, and the bank wanted me to visit a domain that wasn't theirs to provide proof.

The email I got looked like a badly-scanned letterhead and was very, very fishy.

After I received a few of them, I finally contacted the bank and it was legit.

I tried telling the office person (not just a clerk at the counter, someone with their own desk) about the situation and they couldn't understand why it was bad.

I soon paid off that loan and got away from that bank.

Re: Thanks FedEx, this is why we keep getting phished

#36
post #30

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

I will simply refuse to believe this is real. As a psychological defense mechanism. What the hell.

Clearly the safer option is sending the terms via CD

https://t3n.de/news/sparkasse-digital-strategie-cds-per-post...

Since no-one has a CD drive in their computer anymore, the security risk is negligible

Re: Thanks FedEx, this is why we keep getting phished

#37
Phishing and workflows like this are handled by the same profile of employees. Low paid, outsourced, hating their job, doing the least possible. That's why they're indistinguishable. Reliable workflows, record profits, high salaries and bonuses for executives - pick two.

Re: Thanks FedEx, this is why we keep getting phished

#38

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

There's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

Re: Thanks FedEx, this is why we keep getting phished

#40
post #34

Corporates are shockingly incompetent at this sort of stuff. Seriously just use your main domain for URLs. For me at least that clears up 99% of this. I dont want to memorise a list of valid mystery domains for each shipper. Is that really too much to ask?

It is.

If they use their main domain, their normal corporate email will get blocked by anti-spam filters.

So everyone uses a different, unrelated domain for bulk mails.

Post reply on HN