I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.
I will simply refuse to believe this is real. As a psychological defense mechanism. What the hell.
Thanks FedEx, this is why we keep getting phished
371–380 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#372Earlier quoted context omitted.
Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.
I’m supposed to pay my semi-annual property taxes (on the order of ~thousands of USD) on a site that ends in .org instead of .gov, and nobody apparently sees anything weird or wrong with it.
Still can't believe it
Best hope the government of Macedonia remains friendly I guess
Re: Thanks FedEx, this is why we keep getting phished
#373Earlier quoted context omitted.
Do you have any examples? I'm largely out of the Microsoft ecosystem these days, aside from the occasional Xbox usage.
Office.com redirects you to login.microsoftonline.com which isn't horribly bad, but is starting to get there. Now you have microsoft365.com and friends, too. At least when things were login.microsoft.com you could apply the "last part is definitive" now that heuristic is pretty useless. And if you watch the actual DNS requests during a login, whew. CDNs make it even worse, here's a few VALID requests from my DNS cach…
Re: Thanks FedEx, this is why we keep getting phished
#374Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…
This is more restriction than necessary, and unkind to users who may be technically unsophisticated, distracted, sick that day, or just kinda dumb. Include a link, make it a part of the core domain, short, and prominent: https://example.com/contact . If the user isn't logged in, lead with a login flow explaining "If you received a message from us, login for details", and include a contact form, phone number, and if t…
Couldn't disagree more. By sending outbound links in notifications we're only perpetuating the idea that it's OK to click those in the first place. It's hardly any more difficult to just open your browser yourself. I also don't like the idea that we're not willing to accept the absolute mildest of inconveniences, when on the flip side we have loads of stories of people's lives being completely ruined when their life savings are stolen by scammers. It'd be like telling people not to lock their doors because that adds 5 seconds to the time it takes to enter your house.
Re: Thanks FedEx, this is why we keep getting phished
#375A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
Re: Thanks FedEx, this is why we keep getting phished
#376Earlier quoted context omitted.
I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"
I have an Outlook rule to redirect these to junk.
At the moment in my current corporate email address this the number one source of spam, just all the internal phishing testing emails. It feels like the attempted cure is worse than the disease and I hate getting so much useless trash.
Re: Thanks FedEx, this is why we keep getting phished
#377Earlier quoted context omitted.
I had video of them pulling into the driveway and leaving without getting out of the vehicle and saying "no one was home." I'm also in the video.
That sounds like internal verification uses GPS. So in most cases it's going to be the customer's word against the astonishingly lazy driver's evidence.
Re: Thanks FedEx, this is why we keep getting phished
#378Earlier quoted context omitted.
UPS is up there, too. I still get text messages about an old address on an account I can't log into for...reasons. (Special characters sound plausible! And of course the password reset flow doesn't work.) Wonder if they share a vendor.
I can’t believe it’s 2024 and we are still seeing bugs with handling “special” characters. Unicode has been here for how long? Robust string handling is supported in every language. There is no such thing as a special character. My name should be able to contain Chinese characters. My password should be able to contain emojis. What is this Stone Age shit still running on companies’ backends?
Re: Thanks FedEx, this is why we keep getting phished
#379Earlier quoted context omitted.
I don't think Troy Hunt is recommending what you're suggesting at all? The very beginning of the post starts with: > but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs). It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.
Two things: 1. The entire article is about a (surprisingly) legit FedEx SMS looking totally spammy. My point is that we should take "looking totally scammy" completely out of our vocabulary, and pointing out similarities or differences in scam vs real notifications only furthers the notion that they're distinguishable in the first place. Again, to emphasize, I still think this overall was a great article highlighting…
I think this is the core point Troy Hunt is trying to show, but I don't think Troy Hunt makes it explicit enough that this org chart/processes problem is the real problem and the thing FedEx should most fix because you can't rely on incoming notifications to not look scammy, real notifications are indistinguishable from fake ones even if the real ones weren't doing so horribly to begin with. Troy Hunt often makes that point better in other posts (see the old, long series on "Extended Validation" certificates for an example) and maybe just assumed that message was clear rather than harping on it and then resummarizing it in bold text and blinking lights this post.
Re: Thanks FedEx, this is why we keep getting phished
#380Every time someone supposedly bought their timeshare there would be a bank fee or tax they would have to wire money for. The guy who lost $1.8MM wired money 90+ times.
These are lawyers and doctors, educated people getting ripped off.