Earlier quoted context omitted.
How do those booking.com scams work?
In a case I read (can't remember where), reservation data was somehow leaking (either from booking or from hotels), and scammers were sending messages purporting to be the hotel saying the room was cancelled or mischarged or something like that.
Thanks FedEx, this is why we keep getting phished
91–100 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#92There really needs to be some kind of cryptographic authentication system for text messages and caller ID that gives the recipient absolute certainty about the identity of the sender. Registering a name in this system should require real-world proof of identity including a business address and the contact information of real people. There should be serious financial penalties for identity fraud. It should be an open…
If calls are routed over internet then it becomes more viable but obviously there is still a large coordination problem and misalignment of incentives.
Re: Thanks FedEx, this is why we keep getting phished
#93I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.
(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG
Re: Thanks FedEx, this is why we keep getting phished
#94Earlier quoted context omitted.
I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
> Durable media should enable the consumer to store the information for as long as it is necessary for him to protect his interests stemming from his relationship with the trader. Such media should include in particular paper, USB sticks, CD-ROMs, DVDs, memory cards or the hard disks of computers as well as e-mails.
USB sticks are on the list, but so is paper and e-mail. This USB stick could have been an e-mail.
Re: Thanks FedEx, this is why we keep getting phished
#95A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.
email is well and truly dead.
Re: Thanks FedEx, this is why we keep getting phished
#96A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Obviously it doesn’t excuse the practice, but I can see why people use alternative domains to get things done. The above anecdote was also purely within the company; I’m sure that if you add in a partner/managed service, it only amplifies the complexity.
Re: Thanks FedEx, this is why we keep getting phished
#97A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
It's good we have 26 letters, that comfortably leaves you a margin of 6 combinations :-)
Re: Thanks FedEx, this is why we keep getting phished
#98Suggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender . Edit: " sender " here refers to the sender of the electronic notification .
Re: Thanks FedEx, this is why we keep getting phished
#99Earlier quoted context omitted.
(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG
[flagged]
Re: Thanks FedEx, this is why we keep getting phished
#100In a Blackhat talk several years ago Adam Shostak had a clever term for companies interacting with you in ways that were indistinguishable from scammers. But I can't remember what the memorable term was.