Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

71–80 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#71

Wow. Just wow. Troy Hunt does an incredible job of calling out this utterly piss-poor performance from FedEx. Shame it needs somebody with a platform like this to draw attention to it. They should find a way to make them somehow more liable for fraudulent losses. It's gotten to the point now where it sometimes actually is impossible to speak to a human being in customer service - the thick layers of chat bots, delibe…

What concerns me is that this mentality of erecting infuriating barriers will eventually lead to direct in-person stalking of staff.

If anyone has honest anecdotes around this I'd love to hear from you (maybe privately is best if its detailed accounts)

Re: Thanks FedEx, this is why we keep getting phished

#72
post #9

Not that I’m endorsing the use of smart phones, but FedEx does have a mobile application. Why not just use that for notifications regarding deliveries?

Installing an app for every courier firm you might receive a parcel from seems a bit much.

Re: Thanks FedEx, this is why we keep getting phished

#73
post #21
post #4

Earlier quoted context omitted.

In this case the consequence is that the Australian government agency collecting the import tax doesn't get paid. Which means that they don't release the package to FedEx, and that you don't get your package. FedEx needs to do a better job with these notifications. At the very least they need to hire a copywriter.

Our local FedEx once asked me for my details so they could be able to declare my package to the customs and in the SMS message they said that "The sender is paying all declaration fees." I sent them my info and got my package. Then about five months later, I got a bill from FedEx for import fees, tax and service charges. Had to fight with FedEx for some time about it but eventually they agreed to void the bill. At th…

There are more possible realities. You listed the 3 first. There are more options, at least these:

4. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have kept your extra taxes for themselves in the end.

5. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have paid the extra taxes. The government kept them because, hey, they trust Fedex.

6. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have paid the extra taxes. The government kept them but eventually returned them, because some kind of accounting kicked in.

7. You didn't pay the taxes when you bought the stuff. The sender didn't either. Fedex informs the sender and you. Fedex pays out of pocket. The sender pays out of pocket.

Could have happened if you paid:

8. You didn't pay the taxes when you bought the stuff. The sender didn't either. Fedex informs the sender and you. Fedex pays out of pocket. The sender pays out of pocket. You pay out of pocket. Fedex keeps twice the taxes in the end.

9. You didn't pay the taxes when you bought the stuff. The sender didn't either. Fedex informs the sender and you. Fedex pays out of pocket. The sender pays out of pocket. You pay out of pocket. The fed. governemnt keeps triple the taxes.

And many variations I can't think of right now.

Re: Thanks FedEx, this is why we keep getting phished

#74
The biggest banks and brands in India as well as the government organizations do this type of poorly thought communications all day.

The other day an email from the oldest and biggest bank of India landed in my inbox

Truncated Subject line on mobile said "Cash Withdrawls made ..."

My heart skipped a beat because I did no such thing with my account.

Turns out it is a marketing mailer with subject "Cash Withdrawls made Easy!"

Facepalm.

Re: Thanks FedEx, this is why we keep getting phished

#75

I know this comes down to institutional incompetency, but at some point there was a singular human person putting the template content the SMS message in question was generated from into some computer system somewhere and I genuinely wonder what was going on in their head that made them string the words together in this way. You'd have to give it a true, earnest shot to make it worse.

Some say scammers are very smart, and that they deliberately use every trick in the book to tap into our psychological weaknesses and make us act irrationally. But I have the feeling that, 90% of the time, scammers are just told to write an "official-sounding" message – which is the same thing that the hypothetical human who wrote this template was trying to do: that's why the result is so similar. No doubt the use of the word "urgent", or capitalizing the words "Duty" and "Taxes", come from this attempt at making the message sound more formal and official, from someone who is definitely not a skilled writer.

Re: Thanks FedEx, this is why we keep getting phished

#76
post #43
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.

FWIW, I did exactly that a few times where I was 90% certain the e-mail is legit, but it still looked like a phishing attempt. The IT department needs to learn to do better, this is inexcusable, especially in a corporation with otherwise restrictive policies that waste ridiculous amounts of money and effort (think: Windows Defender real-time "protection" on developer machines, with no way to exclude your repos).

Re: Thanks FedEx, this is why we keep getting phished

#77

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

Man, this is just a marketing gimmick. I am always short in USB sticks. So, could have gotten another one.. How about a little bit more of humor?

If you give me your mailing address, I'll arrange it that the bank will mail you one, too.

Just be sure to use the included NOTVIRUS.EXE viewer for best experience.

Re: Thanks FedEx, this is why we keep getting phished

#79
post #24

The Booking.com scams look better than the actual "Self check and pre payments solutions" links send via the Booking hotels. 1 time I was right it is a scam, 2 times it was wrong. Booking.com should make a proper report payment circumvent button and kick out all hotels who do it.

How do those booking.com scams work?

In a case I read (can't remember where), reservation data was somehow leaking (either from booking or from hotels), and scammers were sending messages purporting to be the hotel saying the room was cancelled or mischarged or something like that.

Re: Thanks FedEx, this is why we keep getting phished

#80

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

(translation provided by ChatGPT)

> Terms and Conditions, Price and Service List, Conditions.

> Dear customer,

> our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick.

> With kind regards,

> The Sparkasse Bremen AG

Post reply on HN