257 pointsby stymaar8 hours ago21 comments
  • lemursage7 hours ago
    This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package.

    I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.

    I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).

    The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.

    • handedness5 hours ago
      I've gotten the same from FedEx several times over the years. It never gets less weird.
  • Terr_5 hours ago
    I wonder how we could describe this so that aging non-technical executives understand.

    "It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."

  • kencausey7 hours ago
    In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
    • varun_ch5 hours ago
      not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam.

      But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing...

      I understand the idea that they want an official TLD that doesn't necessarily have their trademark in it, so you know it's a link to a Google service but potentially user content, but why have c.gle links to official/urgent messaging??

      (at least they don't use 1drv.com in emails like Microsoft.. seriously...)

      • Terr_5 hours ago
        I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.
        • ButlerianJihad16 minutes ago
          You know what? If someone shows me a shortcode on my feature phone, or on someone else's device, or it's printed on a leaf of paper, or if I'm in a library using library computers, a shortened URL like that is way easier to type in.

          However you slice it, even after we conquer character limits and font rendering and storage space for every electronic device, human beings will still be using "the analog hole" to copy code like that.

        • xethos4 hours ago
          I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see
          • martheena minute ago
            Wait, multiple messages get concatenated to MMS? In early 2010s I remember in my country it's still concatenated as regular text (so if one part is somehow missing or comes in very late, some phones will only show the surviving parts as one, others dump each parts separately), I guess they remove that functionality? Back then each part cost roughly one cent and plenty of phones in use still don't support MMS, then people just jump into WhatsApp entirely when Nokia support it in their feature phone.
          • kevin_thibedeauan hour ago
            MMS costs more on the backend.
    • inigyou7 hours ago
      Whois has been replaced by RDAP.
      • ButlerianJihad13 minutes ago
        https://en.wikipedia.org/wiki/Registration_Data_Access_Proto...

        Even if you retrieve registration information about a domain, that will not necessarily help a consumer figure out if it is legitimate, or who owns it. There will be a lot of redactions and shell companies and generic information.

        The target market for WHOIS and RDAP has always been administrators and registrants and others on their level. Obviously--RDAP is a JSON format, not plain text anymore!

        As a consumer, if you're trying OSINT, try not to spread that around, because it is another opportunity for deception, confusion, and cargo culting. What you want is good malware protection, according to your actual risk profile. If your browser protection is worthwhile then it will stop attacks from domains like that.

        If you are particularly worried about strange domains, many 3rd-party DNS services can block those. NextDNS had a checkbox for "block newly-registered domains" as well as filtering any sus gTLD or ccTLD type ones.

      • kencausey6 hours ago
        As far as I am able to find Google does not provide an RDAP server for gle either.
      • b1127 hours ago
        There are whois servers, and the whois command, so no, it has not.

        I agree that this is the goal.

        • inigyou6 hours ago
          Clearly there is not a whois server here
          • jdiff6 hours ago
            According to a new uncle to your comment, not whois or RDAP.
  • jhbadger7 hours ago
    It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!
    • LgWoodenBadger5 hours ago
      Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate.

      Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).

      • voakbasda5 hours ago
        FWIW, they put a header in the message that you can spot from a thousand miles away. That is how they get past the filters.

        I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely.

        It’s compliance theater. No real security is gained, but it checks all the boxes.

    • starky7 hours ago
      We have a training thing at work that sends out phishing emails and you are supposed to report them using a handy button in the email app. If they are training emails you get a good job website that pops up. I greatly enjoy reporting every single genuine email that reads anything like a potential phishing email as there is someone in IT that reviews them and probably gets annoyed at the various groups sending sketchy emails for official business.
    • AlotOfReading6 hours ago
      I'm forced to have a relationship with a bank that sends out iPad giveaway emails, where your chance of winning is contingent on filling out a survey with personal information. These occasionally go out on the same day as their periodic "how to recognize scams" newsletter.
    • ern6 hours ago
      A significant number of phishing attempts would be thwarted if email apps had the option to expand the links next to URLs on platforms without mouseover, like mobile.
  • walrus017 hours ago
    I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...

    List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

    • ddtaylor7 hours ago
      I'm not convinced that would help.

      The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

      Its just attempting to work around incompetence, which always just shows up again somewhere else.

      • walrus016 hours ago
        > The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

        I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the linked example) and decides to DIY it rather than going through the full process to do it with their own domain.

        Reminds me a bit of large businesses where some sales or CRM-related department goes out and starts buying email-blasting/email-list features from some mailchimp-type company and only later on realizes they need to talk to whoever controls the domain to get approval for proper outbound DKIM in the DNS records, etc.

        • SoftTalker5 hours ago
          Or more likely IMO, FedEx HQ said "you can't use our domain to collect foreign tax payments" and so it got outsourced to a service in Australia. And a lot of these "collect payments as a service" sites just look and feel like something that was developed in 1995 and never updated. I run into them everywhere, from local governments to medical and legal offices, small utility companies, etc. I have no idea how they pass PCI audits.
      • reaperducer6 hours ago
        The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

        Just today I saw an e-mail from "onmicrosoft.com" that was completely legit.

        I wonder how many domains MS is running these days. It seems like each department and project gets its own.

        • walrus016 hours ago
          At least they're not sending from contoso.com ?
        • Macha3 hours ago
          Note that XYZ.onmicrosoft.com is the domain you get when you sign up for hosted office 365 without a domain of your own
        • Yokolos5 hours ago
          Every time I see a new Microsoft domain I've never seen before, I have to double check that it's actually legit. Every time I realize anew why people still fall for phishing attempts, because all these legit domains look like phishing attempts.
    • cosmic_cheese7 hours ago
      The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.
      • nubinetwork6 hours ago
        It didn't change anything though, if you have the money you can just buy more.
        • tialaramex6 hours ago
          Also this was never a real problem. "All the good names are taken" is true if you insist that every name which isn't taken is a bad name but otherwise obviously false.

          The same exact "Somebody already had the good ideas, it's not my fault I'm just too late" whining can be seen centuries ago. People who live in a world with no electricity, absolutely convinced that every product which will ever be wanted already exists. Morons.

          Way back in time I wrote an HN post where I just spotaneously came up with plausible 2LD names off the dome and every single one was available. I won't bother repeating the exercise because it was evident that everybody who could understand this was unsurprised while the people who'd previously believed all the good names were gone just dismissed these as bad names because after all, if they were good names they'd be taken already, duh.

    • inigyou7 hours ago
      This was a calculated project by ICANN to 1. bring lots more money to ICANN and 2. prevent decentralisation of the DNS root away from the control of the USA.
    • userbinator4 hours ago
      I definitely don't trust those when they show up in search results, and even when they sometimes appear here in articles voted to the front page, I tend to ignore them.

      Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose

      Many-legit-sounding-hyphenated-words-domain is actually another red flag for me, as that was indeed what they did before the proliferation of TLDs.

    • emmelaich3 hours ago
      My theory is that it devalues the domain name thus increasing the value of search sites.

      BTW, it'd be nice if browsers automatically show the CNs of the "Issued-To:" and the "Issued-By" in the security certificate.

    • dqv7 hours ago
      For the past 2 years I've gotten backscatter from a phishing campaign that uses a domain I own in the from address. Every single domain they try to get the victims to click on is a .com

      The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.

      As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.

    • pibaker5 hours ago
      Not helped by legitimate websites often redirecting you through weird multi tiered domains especially during log in, or legitimate businesses using link shorteners instead of their full domains, or more and more businesses themselves hopping on new TLDs, like the recent cloudflare wallet release.
  • Walf3 hours ago
    It really doesn't help that after the acquisition of TNT couriers, some bright spark decided to call the Australian arm of FedEx "FedEx Express". That's right, "Federal Express Express".

    It's moronic that these big companies can't get their shit together and provide nice links like this:

    https://fedex.au/duty/abc123

    which could have an explainer landing page before prompting you to visit the grotesque original link.

    • selimthegrim2 hours ago
      it's that way stateside too
      • lotsofpulpan hour ago
        What is even more moronic than Federal Express Express is Fedex Express (worked by well paid employees) is a completely different product than Fedex Ground (worked by the lowest paid independent contractors).
  • getpokedagain2 hours ago
    Twenty or so years ago I ordered wheels and tires from tire rack dot com and as I was in college had them delivered to my parents house. The FedEx driver proceeded to roll them down the driveway and into my parents siding scraping up my new wheels and causing about 20k in damage to the siding.

    They seem to have improved so much in that time.

    (╯°□°)╯︵ ┻━┻

  • mixdup7 hours ago
    There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either
    • grishka6 hours ago
      With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.
      • xethos4 hours ago
        This actually depends on who has better SEO. Some scam numbers place higher than the help pages for actual businesses. Receiving physical bills and calling the number on the back of your credit or debit card are good suggestions.

        Or, as another poster suggested, competent governments and corporations will use their actual domain name for official communication.

      • mixdup6 hours ago
        I know that, does my grandmother? In the heat of the moment, will she remember that I told her 2 years ago when they call her?
        • XorNot6 hours ago
          We've desperately needed secure identity verification for business callers for years, so we can start the decades long process of changing people's instincts about it.

          There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database.

          It should just be a standard part of business registration processes.

          • 4 hours ago
            undefined
          • Terr_4 hours ago
            But for which country, state, province, or city?

            Put in the hierarchical angle, and we're kind of back at domain names.

      • smallerize6 hours ago
        So I call back and get dropped at the top of the phone tree. Now how do I address the original problem?
      • lstodd6 hours ago
        With calls, drop any non-prearranged calls, period.

        Over a few years I burned that approach into my parents. It was tough, but worth it.

        • grishka3 hours ago
          That's a good approach, and I do this too actually, but some people's job or occupation requires them to take calls from unknown numbers. And some people still use landlines without caller ID.
        • fortran775 hours ago
          My mom used to know what to do, but with dementia, she lost that ability. We now have a call block on her landline, so only a small whitelist can get through.
  • Cider99866 hours ago
    >Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs

    Australia has mandatory identity verification for getting a SIM card.

    The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.

    KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.

    [1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...

    Discussion:

    https://news.ycombinator.com/item?id=48462308

    • ern6 hours ago
      The phishing in Australia came from uncontrolled SMS gateways which allowed for sender impersonation, not physical phones with SIM cards. They've recently partly closed the loophole by requiring providers to register sender names.
    • J-Kuhn6 hours ago
      Alternative Phone Line? You want the bootstrapping problem?
  • anon70004 hours ago
    I keep getting this message and it might be legit, but I have no idea:

    > BlueShieldCA: ANON, you have an important benefits message in your health feed. blueshieldca.customerfeed.com/a/abcd12345 Txt help/stop Msg&DataRatesApply

    If I login to BSCA, their messaging section shows nothing. But some threads on the internet make “customerfeed” seem like a real service.

  • chuckadams7 hours ago
    I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.
  • eventualcomp7 hours ago
    If I had a nickel for every post I saw on HN front page involving companies confusing people on phishing-like patterns today, I would have two nickels. Which is not a lot but still weird that it happened twice.

    https://news.ycombinator.com/item?id=49172834

    • tanseydavid5 hours ago
      Consider yourself lucky. This happens very frequently these days.
  • monksy5 hours ago
    Chase actively will tell you they'll call you back and then they'll try to verify who you are. That's their fraud department at play.

    Despite trying to tell people not to trust unknown callers.

  • charlieyu15 hours ago
    I spend a lot of time figuring out whether an email from facebookmail.com is legit
  • agency7 hours ago
    This shit drives me insane. Last year I had my home insurer send me a link in an SMS pointing me to allstate.yem.bo to collect some information. Stop training your users to get phished!!
  • darth_avocado7 hours ago
    Do they build their own software or contract it to the consultants?
  • fortran775 hours ago
    When I lived in Sunnyvale, CA, I got text that said "Renew your alarm license online at my-alarm-license-renew.info"

    You do need a residential alarm license in Sunnyvale, but I was sure this was a scam. I called the city. It was the real address, and they were mystified as to why I'd call them. (I sent in a check to avoid the $1.50 processing fee, but that was before 50% of checks get stolen in the mail.)

  • antonvs6 hours ago
    I wouldn’t assume that email is genuine. “Hi,” and “…the B-point link that I’ve sent”? Dodgy AF.

    My first suspicion would be that they’re getting hold of the Fedex invoice data, via a software compromise or an insider.

    If it really is real, then wow, FedEx Australia sounds like it’s one guy operating out of a shipping container down at the docks.

  • antonvs7 hours ago
    > Why are the "D" and the "T" capitalised? Dodgy AF!

    You should be more respectful, you’ve clearly received a Message direct from President Trump!

    • Terr_4 hours ago
      That would actually make it an order of magnitude dodgier-AF. Dodgiest-AF?

      I'd rather be scammed by people who can at least theoretically go to jail for their crimes.

      • 4 hours ago
        undefined
  • Doohickey-d7 hours ago
    Discussed previously, 2024, 564 comments: https://news.ycombinator.com/item?id=39479001
  • siftagent7 hours ago
    [flagged]