Thanks FedEx, This Is Why We Keep Getting Phished (2024)

(troyhunt.com)

146 points | by stymaar 1 hour ago

14 comments

  • lemursage 42 minutes ago
    This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package.

    I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.

    I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).

    The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.

  • kencausey 58 minutes ago
    In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
    • inigyou 47 minutes ago
      Whois has been replaced by RDAP.
      • kencausey 2 minutes ago
        As far as I am able to find Google does not provide an RDAP server for gle either.
      • b112 30 minutes ago
        There are whois servers, and the whois command, so no, it has not.

        I agree that this is the goal.

        • inigyou 15 minutes ago
          Clearly there is not a whois server here
  • walrus01 1 hour ago
    I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...

    List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

    • ddtaylor 34 minutes ago
      I'm not convinced that would help.

      The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

      Its just attempting to work around incompetence, which always just shows up again somewhere else.

      • walrus01 2 minutes ago
        > The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

        I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the linked example) and decides to DIY it rather than going through the full process to do it with their own domain.

        Reminds me a bit of large businesses where some sales or CRM-related department goes out and starts buying email-blasting/email-list features from some mailchimp-type company and only later on realizes they need to talk to whoever controls the domain to get approval for proper outbound DKIM in the DNS records, etc.

    • dqv 32 minutes ago
      For the past 2 years I've gotten backscatter from a phishing campaign that uses a domain I own in the from address. Every single domain they try to get the victims to click on is a .com

      The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.

      As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.

    • cosmic_cheese 47 minutes ago
      The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.
    • inigyou 46 minutes ago
      This was a calculated project by ICANN to 1. bring lots more money to ICANN and 2. prevent decentralisation of the DNS root away from the control of the USA.
  • Cider9986 26 minutes ago
    >Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs

    Australia has mandatory identity verification for getting a SIM card.

    The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.

    KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.

    [1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...

    Discussion:

    https://news.ycombinator.com/item?id=48462308

    • ern 7 minutes ago
      The phishing in Australia came from uncontrolled SMS gateways which allowed for sender impersonation, not physical phones with SIM cards. They've recently partly closed the loophole by requiring providers to register sender names.
    • J-Kuhn 5 minutes ago
      Alternative Phone Line? You want the bootstrapping problem?
  • mixdup 55 minutes ago
    There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either
    • grishka 24 minutes ago
      With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.
      • mixdup 13 minutes ago
        I know that, does my grandmother? In the heat of the moment, will she remember that I told her 2 years ago when they call her?
        • XorNot 2 minutes ago
          We've desperately needed secure identity verification for business callers for years, so we can start the decades long process of changing people's instincts about it.

          There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database.

          It should just be a standard part of business registration processes.

  • jhbadger 45 minutes ago
    It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!
    • starky 36 minutes ago
      We have a training thing at work that sends out phishing emails and you are supposed to report them using a handy button in the email app. If they are training emails you get a good job website that pops up. I greatly enjoy reporting every single genuine email that reads anything like a potential phishing email as there is someone in IT that reviews them and probably gets annoyed at the various groups sending sketchy emails for official business.
  • eventualcomp 37 minutes ago
    If I had a nickel for every post I saw on HN front page involving companies confusing people on phishing-like patterns today, I would have two nickels. Which is not a lot but still weird that it happened twice.

    https://news.ycombinator.com/item?id=49172834

  • chuckadams 1 hour ago
    I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.
  • antonvs 17 minutes ago
    I wouldn’t assume that email is genuine. “Hi,” and “…the B-point link that I’ve sent”? Dodgy AF.

    My first suspicion would be that they’re getting hold of the Fedex invoice data, via a software compromise or an insider.

    If it really is real, then wow, FedEx Australia sounds like it’s one guy operating out of a shipping container down at the docks.

  • darth_avocado 1 hour ago
    Do they build their own software or contract it to the consultants?
  • agency 52 minutes ago
    This shit drives me insane. Last year I had my home insurer send me a link in an SMS pointing me to allstate.yem.bo to collect some information. Stop training your users to get phished!!
  • antonvs 31 minutes ago
    > Why are the "D" and the "T" capitalised? Dodgy AF!

    You should be more respectful, you’ve clearly received a Message direct from President Trump!

  • Doohickey-d 1 hour ago
    Discussed previously, 2024, 564 comments: https://news.ycombinator.com/item?id=39479001
  • siftagent 54 minutes ago
    [flagged]