Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

31–40 of 93 posts

Re: Gone (Almost) Phishin'

#31

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

Also, Microsoft regularly sends me legitimate emails regarding "Microsoft Rewards" that are absolutely indistinguishable from phishing, like "Total Prize Drop is here! Your chance to win 1,000,000 USD cash grand prize or one of three customizable Mercedes-Benz cars!", complete with links to login pages and everything. So like this one, just as mail: https://xcancel.com/bing/status/2034720189003231410

The first time I got those I couldn't believe these were legitimate. Thank you Microsoft for teaching your customers how to fall for scams!

Re: Gone (Almost) Phishin'

#32
post #14
post #6

I told my parents: if they are ever called by anyone, to tell them "now is not a good time, please give me a case number and I'll call back when I do have the time." And then, this is important, look up the number for the customer service hotline online. I feel like this is a simple solution that works 100% of the time.

My dad googled “amex phone number” and called the first result. I spent most of a Saturday cleaning up after the scammers. I told him, next time call the number on the back of your card.

Any chance the first result was an ad? Those are definitely a popular phishing distribution mechanism, so getting your parents an adblocker could help

Re: Gone (Almost) Phishin'

#33
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

hp’s email sender always look malicious and makes me double take

Re: Gone (Almost) Phishin'

#35
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

Microsoft is really bad with this. Login might be live.com or microsoftonline.com or maybe onmicrosoft.com. I went to report a vulnerability to their security portal this week and it redirected me to b2clogin.com.

OneDrive email attachments link to, I kid you not, 1drv.ms, or maybe it was 1drv.com…

Not to mention, they use .ms as if it’s their personal TLD, but obviously anyone can register a .ms domain. It’s like they want people to get phished.

Re: Gone (Almost) Phishin'

#36
Apple let someone in India a place I have never been to, Apple knows I've never been to log into an old Apple account I'd forgotten about and hadn't logged into for 12 years with a password from a leak. All I got was "Your apple account has been linked to a new mac in India".

Disgusting to me that even the most basic of logic for what would be someone stealing an account: has the account been used in years, would this person we have location data for ever be in India setting up a new computer, with a computer type ID we know is compromised to hackintoshes (iMac Pro) wasn't enough of a red flag to send me an email confirmation first.

Luckily the account was so old iCloud barely stored anything back then but still shocking to me.

Re: Gone (Almost) Phishin'

#37
post #16

audit-apple.com is offline now. Is that something ICANN does, and if so, can they fix zombo.com?

ICANN doesn't do that, individual registrars do. ICANN can suspend a registrar's accreditation if they don't act on spam/scam domains brought to their attention, which is something they do at the dizzying frequency of never.
Post reply on HN