logo

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

Posted by stymaar |3 hours ago |46 comments

lemursage 2 hours ago[1 more]

This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package.

I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.

I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).

The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.

kencausey 2 hours ago[2 more]

In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.

walrus01 2 hours ago[5 more]

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...

List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

mixdup 2 hours ago[1 more]

There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either

Cider9986 2 hours ago[2 more]

>Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs

Australia has mandatory identity verification for getting a SIM card.

The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.

KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.

[1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...

Discussion:

https://news.ycombinator.com/item?id=48462308

charlieyu1 32 minutes ago

I spend a lot of time figuring out whether an email from facebookmail.com is legit

jhbadger 2 hours ago[4 more]

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!

chuckadams 2 hours ago

I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.

eventualcomp 2 hours ago

If I had a nickel for every post I saw on HN front page involving companies confusing people on phishing-like patterns today, I would have two nickels. Which is not a lot but still weird that it happened twice.

https://news.ycombinator.com/item?id=49172834

darth_avocado 2 hours ago

Do they build their own software or contract it to the consultants?

agency 2 hours ago

This shit drives me insane. Last year I had my home insurer send me a link in an SMS pointing me to allstate.yem.bo to collect some information. Stop training your users to get phished!!

antonvs 2 hours ago

I wouldn’t assume that email is genuine. “Hi,” and “…the B-point link that I’ve sent”? Dodgy AF.

My first suspicion would be that they’re getting hold of the Fedex invoice data, via a software compromise or an insider.

If it really is real, then wow, FedEx Australia sounds like it’s one guy operating out of a shipping container down at the docks.

antonvs 2 hours ago

> Why are the "D" and the "T" capitalised? Dodgy AF!

You should be more respectful, you’ve clearly received a Message direct from President Trump!

Doohickey-d 2 hours ago

Discussed previously, 2024, 564 comments: https://news.ycombinator.com/item?id=39479001

siftagent 2 hours ago

[flagged]