Live data from Hacker News

USPS jumps to first place as most imitated brand in phishing attacks

guard.io

41–50 of 74 posts

Re: USPS jumps to first place as most imitated brand in phishing attacks

#41

Is this because Americans are easier to dupe or that there are so many online Americans it pays off to target them the most? All the other brands are used in multiple countries whereas USPS is only for the US.

US destination SMS is very cheap; less than 1 cent in bulk, same with phone calls to US numbers. English gets you access to most if the population. The population is large, and most of them have ready access to payment methods that works globally.

That makes the US a good target, regardless of success rates, as long as they're not extremely low.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#42
post #17
post #11

Earlier quoted context omitted.

I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point, but you're saying networks did a good job protecting against SMS spam and this is the reason why people trust it?

Spam delivered over SMS and the security (perceived or real) of SMS-based 2FA are entirely different subjects, though. But to kibitz on the second: a validated phone account remains by far the easiest 2FA mechanism to deploy and rely on, and 2FA remains by far more secure than simple password authentication. Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The w…

It's an attractive nuisance. And the SMS request that's actually part of the problem can be misunderstood by users (whose model is understandably less technical) as a validation that this is authentic.

"Ooh I'm not sure about these texts from Big Bank, maybe I should call them instead... Oh it did the 2FA code text, I guess it's legitimate"

Re: USPS jumps to first place as most imitated brand in phishing attacks

#44
post #15

Earlier quoted context omitted.

You know you can fill out one form and 90% of it will stop?

What’s the form? Never heard of it before

Five U. S. dollars:

https://www.dmachoice.org

I've done it, and in a matter of weeks the junk just disappears for the most part. Lasts ten years, and I think we're about due for a re-up at our house, as the junk is leaking back in.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#45
It's a very common scam in my neck of the woods as well. I'm constantly receiving emails with text like "your package is held up at customs, please pay $2.50 to release it".

Are enough people buying online AND losing track of their orders that they will just blindly take the bait? I fail to see how this vector is more lucrative than the "your computer is infected" route.

Anecdotally for me, roughly once every ~10-20 orders does the attack coincide with an order that I'm waiting for. But then I know where the order is coming from, I know which courier is handling my package, and the store 9/10 times have an online tracker and the shop itself will alert me if there are any delivery shenanigans going on.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#46
post #45

It's a very common scam in my neck of the woods as well. I'm constantly receiving emails with text like "your package is held up at customs, please pay $2.50 to release it". Are enough people buying online AND losing track of their orders that they will just blindly take the bait? I fail to see how this vector is more lucrative than the "your computer is infected" route. Anecdotally for me, roughly once every ~10-20…

Are you married? Putting two people in the mix does create some "fog of war" about expected package deliveries.

I'm not falling for these scams, but I'm also quite ignorant about most of the planned package traffic to my house.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#47
post #45

It's a very common scam in my neck of the woods as well. I'm constantly receiving emails with text like "your package is held up at customs, please pay $2.50 to release it". Are enough people buying online AND losing track of their orders that they will just blindly take the bait? I fail to see how this vector is more lucrative than the "your computer is infected" route. Anecdotally for me, roughly once every ~10-20…

The difference is that if you text a random person it's likely that they recently ordered something online.

the timing of the text makes it more believable.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#48
post #45

It's a very common scam in my neck of the woods as well. I'm constantly receiving emails with text like "your package is held up at customs, please pay $2.50 to release it". Are enough people buying online AND losing track of their orders that they will just blindly take the bait? I fail to see how this vector is more lucrative than the "your computer is infected" route. Anecdotally for me, roughly once every ~10-20…

Are you married? Putting two people in the mix does create some "fog of war" about expected package deliveries. I'm not falling for these scams, but I'm also quite ignorant about most of the planned package traffic to my house.

That's a good point I guess - I am married. But the first thing that I'll do if the email is not immediately suspicious is ask my spouse if they are expecting anything and why the message came to me and not them.

Maybe I'm not the target market for these operators.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#49
post #29

Earlier quoted context omitted.

maybe you should instead fuck your legislators so they can make that practice illegal (getting adverts per mail without consent). Where I live it's opt out, so not ideal either but at least I don't have to put up with the trash after adding a sticker to my post box.

Why not both? USPS is most prolific and polluting spam purveyor in the world.

Yeah one of the biggest (if not the biggest) sources of paper that I throw away is junk mail. I throw away bags of it every month, 98% of it unopened. The environmental impact of the paper, the printing, the fuel burned to deliver it, must dwarf the impact of the single-use plastic bags I get at the supermarket.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#50
post #11

The networks did such a good job for so long keeping spam out that people almost inherently trust sms, I've had to help multiple people with fallout from these types of texts.

I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point, but you're saying networks did a good job protecting against SMS spam and this is the reason why people trust it?

Its a learned trust, most people don't realize that their phone service provider blocks something like 90% of all messages they receive, they made a conscious decision to not show the users their spam folders, so we don't see what's not getting through like you can when you check your email.
Post reply on HN