Live data from Hacker News

Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

akamai.com

1–10 of 75 posts

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#2
I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about it one day" shrug, and banks and other institutions continue to send legitimate messages that look like phishing.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#3

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

[deleted]

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#4

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about it one day" shrug

This is my problem with almost every "report spam/fraud/etc" flow. It's always a digital shrug, and then nothing happens.

Only one site I know of ever had it right: Instagram, up to about 2021. When you reported an account or post, you would actually be notified when they took action, which would usually take about a week and be something like "the account was removed". It was so satisfying to see a spam account get taken down after a report. But, they removed that in favor of the "hey thanks for the report we've tossed it right in the trash lol" user flow that every other site uses. Unfortunate.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#5

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> banks and other institutions continue to send legitimate messages that look like phishing.

The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#6
Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall.

https://economynext.com/sri-lanka-to-study-infobip-centraliz...

Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#7

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

Is detecting phishing all that straightforward? As banks, travel agents, and even governments, are all terrible at avoiding the signalling of phishing.

Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for.

https://www.equifaxsecurity2017.com/

This looks like phishing. But it is legitimate.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#8

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

Is detecting phishing all that straightforward? As banks, travel agents, and even governments, are all terrible at avoiding the signalling of phishing. Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for. https://www.equifaxsecurity2017.com/ This looks like phishing. But it is legitimate.

Vattenfall (a big Swedish energy company) had the same for a while. Their marketing created a website where you could log in as a user, on a completely different domain.

Most have been fixed but my current pet peeve is receiving email newsletters from these companies with tracking links. I get it, you're trying to measure something. But they're genuinly sending you links like sx4pv.mjt.lu/lnk/EEEAAAA-3434-asdfasdfasdf

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#10

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

Is detecting phishing all that straightforward? As banks, travel agents, and even governments, are all terrible at avoiding the signalling of phishing. Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for. https://www.equifaxsecurity2017.com/ This looks like phishing. But it is legitimate.

Indeed. They haven't learned their lesson.

AT&T finally copped to enormous breach this month. In their notification to individuals (sorry, sign up for identity protection, etc), they made sure to let you know official email always comes from: att@message.att-mail.com

...an email address and subdomain that have never contacted me before on a sketchy sounding domain that doesn't match the service (hosted at https://att.com). The email links to experianidworks.com which asks for email, address, and SSN upon clicking the CTA.

Post reply on HN