Earlier quoted context omitted.
Are you married? Putting two people in the mix does create some "fog of war" about expected package deliveries. I'm not falling for these scams, but I'm also quite ignorant about most of the planned package traffic to my house.
That's a good point I guess - I am married. But the first thing that I'll do if the email is not immediately suspicious is ask my spouse if they are expecting anything and why the message came to me and not them. Maybe I'm not the target market for these operators.
USPS jumps to first place as most imitated brand in phishing attacks
51–60 of 74 posts
Re: USPS jumps to first place as most imitated brand in phishing attacks
#52Is this because Americans are easier to dupe or that there are so many online Americans it pays off to target them the most? All the other brands are used in multiple countries whereas USPS is only for the US.
It's because US cell phone networks refuse to implement basic authentication, and because USA population has the most excess money to steal.
Like other countries.
> and because USA population has the most excess money to steal.
No, it doesn't. Many other countries have a lot more wealth in their general population. There are many people in the US with higher salaries than other places however don't think they have the most excess money to steal.
I think everyone is missing a major factoid. Microsoft is second, it'll be used in every language in almost every country. Yet, it's piped to the post by a large amount by a US only target. People do things for a reason especially when it comes to money. The US market is clearly the most profitable. But my question remains is that because there are so many or that they're dumb?
Re: USPS jumps to first place as most imitated brand in phishing attacks
#53Just heard from a client last week who had their credit card compromised and while waiting for their new card to arrive via mail, had more of their cards compromised by a USPS phishing text. The scam was basically a text that said "there was a problem mailing your new credit card" which lead to a USPS cloned website that asked for $0.30 to resolve the issue. My client tried two credit cards (each "failed") before fin…
I'm continually astounded how many people will be asked for a credit card through no direct action of their own (e.g. an unsolicited text not part of a conversation they initiated) and will just do it. And multiple times! Edit to be clear: I don't think these people are dumb, and I'm sure there is some scenario in which I could fall victim to a similar claim. This is more a comment on people generally as opposed to "…
Re: USPS jumps to first place as most imitated brand in phishing attacks
#54Earlier quoted context omitted.
maybe you should instead fuck your legislators so they can make that practice illegal (getting adverts per mail without consent). Where I live it's opt out, so not ideal either but at least I don't have to put up with the trash after adding a sticker to my post box.
Why not both? USPS is most prolific and polluting spam purveyor in the world.
Re: USPS jumps to first place as most imitated brand in phishing attacks
#55Yup, I've gotten a couple of the USPS texts per month for the last few months now. The USPS will never text you, I asked. They only do things by mail :]
Re: USPS jumps to first place as most imitated brand in phishing attacks
#56Fuck the USPS for allowing advertisers to bulk send junk mail to everyone for a couple dollars. It’s a daily chore to take out the mailbox trash before it’s so full they start returning important letters back to sender for not being able to fit it in.
https://consumer.ftc.gov/articles/how-stop-junk-mail says it's free to stop getting mail for dead people. I was executor for my mom and aunt in 2017 and still get mail for them both. Turns out it's now $1 to stop that. https://www.ims-dm.com/cgi/ddnc.php Screw you Hillsdale College.
Re: USPS jumps to first place as most imitated brand in phishing attacks
#57Earlier quoted context omitted.
I write "return to sender" on the envelope and drop it into a post box. It doesn't cost anything.
> I write "return to sender" on the envelope and drop it into a post box. It doesn't cost anything This technically only works for first-class mail. Bulk mail doesn’t have return services.
Re: USPS jumps to first place as most imitated brand in phishing attacks
#58Earlier quoted context omitted.
Why not both? USPS is most prolific and polluting spam purveyor in the world.
because you don't shoot the messenger... I don't think it should be the task of the mail delivery service to decide what you should receive
https://www.usps.com/business/every-door-direct-mail.htm
I’ve tried every opt-out I can find and it still doesn’t stop.
Re: USPS jumps to first place as most imitated brand in phishing attacks
#59Earlier quoted context omitted.
Spam delivered over SMS and the security (perceived or real) of SMS-based 2FA are entirely different subjects, though. But to kibitz on the second: a validated phone account remains by far the easiest 2FA mechanism to deploy and rely on, and 2FA remains by far more secure than simple password authentication. Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The w…
> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all. It was your interpretation that I advise people to not use any 2FA at all. I won't honor the request to not dump on SMS, as I am perfectly happy to dump on an "extremely valuable technology" on technical dem…
No, to be clear, it's the obvious interpretation of a non-expert user, which is why your advice is so dangerous. They don't have a yubikey, don't understand how the apps work, and are faced with a decision to either enable SMS 2FA or not. And you're telling them not to, so they won't. And we'll all suffer.
Again, work the other side of the problem if this is important to you. Make the other solutions better and educate people about them. Don't tell them not to use something that might very well save their bank account.
Re: USPS jumps to first place as most imitated brand in phishing attacks
#60Earlier quoted context omitted.
maybe you should instead fuck your legislators so they can make that practice illegal (getting adverts per mail without consent). Where I live it's opt out, so not ideal either but at least I don't have to put up with the trash after adding a sticker to my post box.
Why not both? USPS is most prolific and polluting spam purveyor in the world.