Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

51–60 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#52
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener.

The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an employee password!

I think IT incompetence should lead to audit fails or even better delisting from exchanges.

Re: Thanks FedEx, this is why we keep getting phished

#53

Earlier quoted context omitted.

There's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

Re: Thanks FedEx, this is why we keep getting phished

#54
post #2

Suggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender . Edit: " sender " here refers to the sender of the electronic notification .

I almost got in some trouble because of that. A "bank" I wasn't a customer of kept sending me messages about "urgent, answer this form with your personal details or we will lock your account". Seemed quite scammy to me.

Then I later got a physical letter in the mail about the same, and then I called the bank. Apparently I had some account there holding some pension stuff from a previous employer. Shrugs.

Re: Thanks FedEx, this is why we keep getting phished

#55
post #22

Earlier quoted context omitted.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.

These scammers probably aren't targetting specific individuals. They blast these messages out to a bunch of randos, and odds are very high that at least some of those are expecting packages just by chance. The marginal cost of an added message is tiny compared to the reward of one successful scam.

Re: Thanks FedEx, this is why we keep getting phished

#56

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

I do not read this court decision like that at all: the point of contention there seems to be that the customer was just sent a link to a webpage (where the contractual terms can be changed from under him at will by the company, thus this not being durable). The court makes it pretty clear in my (non-lawyer) opinion that attaching a PDF to the email would have been fine.

Re: Thanks FedEx, this is why we keep getting phished

#57

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

i love this comment:

ich arbeite als (externe) CyberCyberCyber Nase in einer Organisation irgendwo in der Sparkassengruppe. Ich kann dir versichern, dass niemand, der auch nur im entferntesten was mit InfoSec in der Bank zu tun hat, von dieser Marketing Idee erfahren hat.

"I work as an (external) CyberCyberCyber nose in an organization somewhere in the Sparkassen-group. I can assure you that no one who is involved even the slightest with infosec at the bank, has heard anything about this marketing idea."

Re: Thanks FedEx, this is why we keep getting phished

#58

Earlier quoted context omitted.

There's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

For some things, you must use paper (or as it turns out, USB).

Why the bank decided to use USB for this purpose, instead of paper, is very strange.

Re: Thanks FedEx, this is why we keep getting phished

#59

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

Haha, nice try!

Re: Thanks FedEx, this is why we keep getting phished

#60

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

Hey at least it's 100% safe from a hacker who has broken SSL/TLS altering the terms and conditions on the wire.
Post reply on HN