Live data from Hacker News

How are cyber criminals rolling in 2025?

vin01.github.io

51–60 of 97 posts

Re: How are cyber criminals rolling in 2025?

#51

I am surprised no one mentioned using LLMs to spell and grammar check their emails and vibe-code bank landing-pages to continue a more polished version of scamming elderly people out of their life savings.

The misspellings/shitty grammar are on purpose.

I have heard that theory from some cybersecurity experts online but have never seen it substantiated in any way (by interviewing some scammers, for example) and frankly don't believe it.

The misspellings and grammatical errors (used to?) continue on the fake sites that are created to steal credentials, and the excuses for most of the reasoning regarding emails do not hold there.

Re: How are cyber criminals rolling in 2025?

#52
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

I've been seeing similar scams via PayPal. The scammers apparently add the target email address as a forwarding address on a compromised or created-for-purpose email account. And that bouncer email address is signed up for PayPal. So the scam email is actually from PayPal, bounced through some other inbox. The To name and address is of the bouncer email address PayPal sent it to.

One version involves sending money to someone with the PayPal account (so the target might think it was sent from their own account) with a "note" to the transaction recipient, which the target sees, which says PayPal has detected unusual activity and please call this phone number to request a refund.

Another involves a "Your ITEM NAME order is on its way" email where the item being ordered is called something like, "Some Company, Inc: Don't recognize the seller? Call us at SOME PHONE NUMBER".

A third is like the second, except it's a "You paid CURRENCY to SELLER" email. This one has the PayPal user's name at the top, so not as convincing perhaps.

Re: How are cyber criminals rolling in 2025?

#53
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

So, I craft a search where the search query is “call 1 800 scam”, then I buy a google ad with key word of “ticketmaster help”, the ad links to real ticketmaster with my query, and google shows that ad to someone having trouble and hey presto they call my scam line at 4 quid a minute from their mobile? Yuck all round. I mean ticketmaster is just a sin eater for greedy popstars but yuck ..

On top of that, you receive private information about people from Google, because if someone calls your number, then you know that they were on ticketmaster. Replace ticketmaster by e.g. a swingers club, and now Google's ad businessmodel is in real trouble because it leaks sensitive information.

Re: How are cyber criminals rolling in 2025?

#54

Earlier quoted context omitted.

But why does google allow unverified owners of a domain to buy ads for it? Surely only ticketmaster or agencies approved by ticket master should be allowed to do this?

Because most of the ads are created by external ad agencies, and the people involved are not competent enough to do any verification. Source: I've also thought this was ridiculous and asked someone working on the adsense team. Apparently tried enforcing some domain verification mechanism in an experiment, but most companies and agencies struggled to get the verification done and of course the $ metrics on this launch…

Maybe a partial solution here would be to offer some kind of "domain locking" option?

Allow sites that are heavy targets of this kind of scam - like ticketmaster - to add a "AdSense: locked" line to their robots.txt (or similar) - if that line is present then advertisers have to go through an additional domain verification step in order to place an ad.

Re: How are cyber criminals rolling in 2025?

#55
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

FWIW I sent this to a friend on the dev team at Ticketmaster and they escalated it.

Re: How are cyber criminals rolling in 2025?

#56

Earlier quoted context omitted.

> At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses. Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. Well that's fine; my school did the same thing and other than feeling wasteful there was no- > All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture. Oh. Yeah, open ports by default is... an…

When you're living in the residences and there's a DC++ server running, it's pretty sweet. Ours had a whole 1.5TB of stuff on it!

Was this RIT by any chance?

Re: How are cyber criminals rolling in 2025?

#58
post #32

Earlier quoted context omitted.

But why does google allow unverified owners of a domain to buy ads for it? Surely only ticketmaster or agencies approved by ticket master should be allowed to do this?

Not necessarily, if you have an affiliate program or something like that you could buy ads for, say, eBay using your affiliate link in the hopes of you generating more profit than the ads cost.

There are also still plenty of businesses with a Facebook page as their homepage

Re: How are cyber criminals rolling in 2025?

#59
post #55
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

FWIW I sent this to a friend on the dev team at Ticketmaster and they escalated it.

Its cool you at least attempted to do something with a bit of social connection at such a heavily targeted website.

Having personal issues with Ticketmaster's pricing methods (causing many to probably never want to do anything that might help) is a different issue than the website being used as a source for redirecting calls to fake call centers.

Since they escalated maybe something will get done. Ticketmaster would have a motivation, if large numbers fall prey to diverted call center scams it only makes their reputation flounder even worse.

(...obvious joke here would be if the scammers actually offer better support, they're just trying to steal call center business)

Re: How are cyber criminals rolling in 2025?

#60
post #54

Earlier quoted context omitted.

Because most of the ads are created by external ad agencies, and the people involved are not competent enough to do any verification. Source: I've also thought this was ridiculous and asked someone working on the adsense team. Apparently tried enforcing some domain verification mechanism in an experiment, but most companies and agencies struggled to get the verification done and of course the $ metrics on this launch…

Maybe a partial solution here would be to offer some kind of "domain locking" option? Allow sites that are heavy targets of this kind of scam - like ticketmaster - to add a "AdSense: locked" line to their robots.txt (or similar) - if that line is present then advertisers have to go through an additional domain verification step in order to place an ad.

I like this idea. I would love to hear from Google why they would not do this. Anyone know why Google / Facebook et al would not want to do this?
Post reply on HN