From 2024, but funny to read....

What makes this situation so ridiculous is that while we're all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!

top 50 comments

sorted by: hot top controversial new old
[–] 217 points 2 weeks ago (11 children)

Yeah. Recently I was expecting a message from a bank, finally I got a call... from a chatbot claiming it has an important message for me, but first I have to give it my private info to verify myself and there's no way to validate the call is legit first.

When I complained to the bank they just told me I shouldn't worry, they made the call so it's perfectly safe and there's nothing to worry about...

  • source
  • hideshow 11 child comments
  • [–] 136 points 2 weeks ago (7 children)

    I would change banks over that and list that as the reason why.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 87 points 2 weeks ago* (last edited 2 weeks ago) (6 children)

    My banking app has a "is calling?" button, which is pretty neat. The button is highlighted whenever I open the banking app whilst on a phone call, presumably as a subtle anti-scammer warning.

    e: spelling

  • source
  • parent
  • hideshow 6 child comments
  • [–] 43 points 2 weeks ago (1 child)

    My bank has the inverse as well. If i open the app while on a call there's a huge banner across the top stating they are not calling me.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 6 points 2 weeks ago

    The Swedish banks has a shared identification app, and it gives a big alert every time a login is prompted asking if you called out or got called, and doesn't let some actions complete if you say you got called

  • source
  • parent
  • [–] 7 points 2 weeks ago

    Our Dr office does that as well. We have a call about your upcoming appointment, can you provide details to confirm it's you. They don't give appointment time, what office it is, patient name nothing. Even if you trust it legit if you or your partner or kid both have upcoming appointments you have no idea which it's for.

    We just hang up and call to figure out which it was.

  • source
  • parent
  • [–] 89 points 2 weeks ago (6 children)

    Is this for real? I would’ve automatically deleted and reported it as spam lol.

  • source
  • hideshow 6 child comments
  • [–] 39 points 2 weeks ago (2 children)

    You and the "87%" of people who responded to his Tweet or whatever.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 14 points 2 weeks ago* (last edited 2 weeks ago) (2 children)

    Yep. Accidentally imported some parts for my car (thought they were in the states, but no, China), got a random message about duty fees. I initially thought it was a scam, but got another, so I followed the link on a safe device (laptop running Linux). It gave a valid address from the shipping company with details that verified my order, so I had to pay or it wouldn't be delivered. Very annoying, should have been told earlier that I needed to pay duties/tariffs so I could plan accordingly.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • [–] 74 points 2 weeks ago (6 children)

    The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn't going to make any kind of effort towards it. That's on you, not on us!

    Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you're redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing... why wouldn't it just be login.microsoft.com? I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you're dumping your credentials into random looking domains, then downloading and installing software from other random domains.

    They just don't really care as long as there's no legal liability. You're data gets compromised because you didn't notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that's your mistake and no one can sue microsoft for it. As long their negligence doesn't meet the legal definition of negligence, they're not going to put an any kind of effort.

    Anti-phishing training could be so much better... "don't put your credentials into anything other that *.microsoft.com". But since these companies won't make any effort, anti-phishing training amounts to "Just be careful or whatever LOL!"

  • source
  • hideshow 6 child comments
  • [–] 22 points 2 weeks ago

    You’re data

    Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!

    ;-)

    I think you're spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.

    For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says "Don't click links from sources you don't trust" and doesn't teach you what to look for.

    To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.

    The linked article is a fantastic example of the worst legit comms I've seen. Absolutely looks scammy all the way through.

  • source
  • parent
  • [–] 5 points 2 weeks ago

    I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain.

    I’ve had to deal with shit like this personally so I guarantee that was at least one reason. The departments that control the domain treat it like some sort of power trip and make it hard to do the smart thing.

  • source
  • parent
  • load more comments (2 replies)
    [–] 53 points 2 weeks ago (8 children)

    I don't get why all these big companies just cannot be serious about anything they do. They're always disorganized.

  • source
  • hideshow 8 child comments
  • [–] 31 points 2 weeks ago (3 children)

    It's because they're big companies. The bigger they get, the less they can focus on any one thing. More people means more risk of someone being unqualified, and less oversight through more layers of middle management, most of whom are also unqualified.

    Your local business employs fifteen people. One owner, two managers, and 12 staff. Everyone knows everyone and if they're truly bad at their job they can't deflect and skate (unless the owner allows it).

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (2 replies)
  • load more comments (4 replies)
    [–] 43 points 2 weeks ago (4 children)

    Capital One does something similar and it's so fucking annoying. They send text messages that read "Your transaction for some company was DECLINED! Take action now: http://someweirddomain.com/sketchy/uri"

    I used URL Checker to figure out where it ultimately landed and it does go to Capital One.

    I've even complained about this and they said, "Well, you should know these texts only come from us."

  • source
  • hideshow 4 child comments
  • [–] 17 points 2 weeks ago (1 child)

    The solution is: if it looks scammy, get on a different device altogether and use your normal login to the institution to access the issue through the normal channels instead of their "convenient link" through the sketchy service which may well be skimming your data even if they are under contract to your bank.

    Unfortunately, a lot of the institutions' own interfaces suck so badly it's sorely tempting to use the quick link.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 12 points 2 weeks ago

    But as this article points out - that's not always helpful when the company makes it difficult to contact them - or in this case, the Duty and Taxes [sic] aren't a part of the FedEx process but a part of the government, so to FedEx it's a third-party issue and so when they pulled up the shipment, no mention was made of it (that's my theory why that happened).

    Your advice is good - I'm just saying it won't always work. heh. But it is the thing you must do unless you recognize the message source/content and even then, better to just log in separately. heh

  • source
  • parent
  • [–] 27 points 2 weeks ago

    I usually post the article in the comments so it is easier to read, but Troy hunt 's website is already so easy to read its a joy!

  • source
  • [–] 25 points 2 weeks ago* (last edited 2 weeks ago) (2 children)

    A competent government would set up best practice rules, and tools to improve systems. They could even provide some sort of system for consumers to report these issues. Then they could assign companies a cyber security score. Basically, a wall of shame for this stuff, ideally with the option for fines for non-compliance.

    Unfortunately, "competent government" seems to be an oxymoron in most places.

    Edit: to be clear, I provided examples of half-hearted implementations of what I'm talking about from a couple sources, but I'm making no claims about the competency of those governments.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 21 points 2 weeks ago (2 children)

    With how much effort is being put into phishing awareness and training, some people/companies still put zero effort into their communication.

    Duting a lengthy process that involved an attorney, I got an email from a firstnamelastname(at)yahoo(dot)com, with no introduction, no mention of my name, a misspelled address, telling me about an appointment at another address that was... screenshotted from a website and pasted as image. Looks sketchy AF by any measure. Nope, that was a real email from a paralegal.

    Filed a helpdesk ticket at work. Get a Teams message from " (external)", asking me my company machine ID in bad English. Responded with "you are helpdesk, do you not know this?". After a few repeated requests for the ID and not answering any of my questions, I just stopped responding.

  • source
  • hideshow 2 child comments
  • [–] 12 points 2 weeks ago (1 child)

    The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.

    Another manager told users to just bypass the certificate errors on a new web service.

    Multiple times I've had people tell me over teams to do all kinds of weird things to work around security errors.

    It's a weird thing where people in IT think the security rules are for everyone else and not for them. And it's just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company's domain] and the cert is valid and if it's an internal service, use kerberos to validate the user so they don't even enter a password.

    The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what's needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 5 points 2 weeks ago

    Yeah, there were two IT techs at one company who routinely asked for user passwords, in part because some of the software we used require setup in the user account. I'd say no, but I was on a few reply all emails where others provided their password to everyone on the email.

    I forwarded those emails after the IT manager after the company email server got blacklisted by a client for our emails being used as an attack vector to phish.

  • source
  • parent
  • [–] 18 points 2 weeks ago*

    One cool thing that just went live in the last month or so is SMS Sender ID. You need to file a shitton of paperwork before being given the keys to send an SMS to an Australian with a name instead of a phone number.

    https://www.acma.gov.au/sms-sender-id-register

    I personally had to write the code to make this work for a rather large financial institution that uses AWS for bulk SMS. It was a lot of hoops to jump through. If you get one detail wrong, your SMS just has a phone number instead of a name.

    At this point, it should be impossble to deceptively get "Fedex" into an SMS header.

  • source
  • [–] 18 points 2 weeks ago (5 children)

    So many legitimate messages look like phishing schemes nowadays: those class-action ones are probably the worst offenders for me because it would take no effort for someone to create a scam based on that. Banks are another big one. These companies are making it really easy for the scammers to take advantage of people.

  • source
  • hideshow 5 child comments
  • load more comments (5 replies)
    [–] 13 points 2 weeks ago* (last edited 2 weeks ago)

    It really is the golden age of stalkers and scam artists. You wouldn't believe how much I know about the previous owner of my phone number. Their name, where they work, where their kids go to school, their pediatrician, their coworkers names and numbers (still included in text conversations). I started responding to the work texts when I realised they were STILL giving out the number (autofill I guess)

    This needs to be made for real

  • source
  • [–] 8 points 2 weeks ago

    This is definitely not the reason I do it, but it's an added advantage of always getting packages delivered to my AusPost parcel locker. They always arrive in a very consistent format and don't require clicking any links.

  • source
  • [–] 7 points 2 weeks ago

    There's a healthcare organization where I live that basically dominates everything, and every time they contact me it's through a new phone number and new format of call/text and they're super disorganized as well

  • source
  • [–] 6 points 2 weeks ago

    The scammers messages look less dodgy than the real one, if you dont count the obviously suspicious links. Though it doesnt help that the real one also has link that looks suspicious and also like it was made by scammer who isnt very good at what they do.

  • source
  • [–] 5 points 2 weeks ago (12 children)

    I'm in Canada, I purchased something from the US shipped with DHL.

    They did not send a text. They sent a WhatsApp‽

    Plus, they made me pay import fee on the value of the listed items instead of on the price I payed (there was a 40% discount).

  • source
  • hideshow 12 child comments
  • [–] 7 points 2 weeks ago (7 children)

    they made me pay import fee on the value of the listed items instead of on the price I payed (there was a 40% discount).

    All this discount / special deal complexity needs to stop. Now the tax-men are scamming us declaring everything to be taxable at the retail rates when nobody pays the retail rates.

    One price, for everybody, all the time. One tax rate, for everything, all the time.

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (4 replies)
    load more comments
    view more: next ›