

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.by chuckadams
- When I lived in Sunnyvale, CA, I got text that said "Renew your alarm license online at my-alarm-license-renew.info"
You do need a residential alarm license in Sunnyvale, but I was sure this was a scam. I called the city. It was the real address, and they were mystified as to why I'd call them. (I sent in a check to avoid the $1.50 processing fee, but that was before 50% of checks get stolen in the mail.)
by fortran77 - Twenty or so years ago I ordered wheels and tires from tire rack dot com and as I was in college had them delivered to my parents house. The FedEx driver proceeded to roll them down the driveway and into my parents siding scraping up my new wheels and causing about 20k in damage to the siding.
They seem to have improved so much in that time.
(╯°□°)╯︵ ┻━┻
- I keep getting this message and it might be legit, but I have no idea:
> BlueShieldCA: ANON, you have an important benefits message in your health feed. blueshieldca.customerfeed.com/a/abcd12345 Txt help/stop Msg&DataRatesApply
If I login to BSCA, their messaging section shows nothing. But some threads on the internet make “customerfeed” seem like a real service.
by anon7000 - It really doesn't help that after the acquisition of TNT couriers, some bright spark decided to call the Australian arm of FedEx "FedEx Express". That's right, "Federal Express Express".
It's moronic that these big companies can't get their shit together and provide nice links like this:
which could have an explainer landing page before prompting you to visit the grotesque original link.
by Walf - it's that way stateside tooby selimthegrim
- >Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs
Australia has mandatory identity verification for getting a SIM card.
The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.
KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.
[1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...
Discussion:
by Cider9986 - Alternative Phone Line? You want the bootstrapping problem?by J-Kuhn
- The phishing in Australia came from uncontrolled SMS gateways which allowed for sender impersonation, not physical phones with SIM cards. They've recently partly closed the loophole by requiring providers to register sender names.by ern
- There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, eitherby mixdup
- With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.by grishka
- I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...
List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt
by walrus01 - My theory is that it devalues the domain name thus increasing the value of search sites.
BTW, it'd be nice if browsers automatically show the CNs of the "Issued-To:" and the "Issued-By" in the security certificate.
by emmelaich - I definitely don't trust those when they show up in search results, and even when they sometimes appear here in articles voted to the front page, I tend to ignore them.
Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose
Many-legit-sounding-hyphenated-words-domain is actually another red flag for me, as that was indeed what they did before the proliferation of TLDs.
by userbinator - For the past 2 years I've gotten backscatter from a phishing campaign that uses a domain I own in the from address. Every single domain they try to get the victims to click on is a .com
The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.
As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.
by dqv - Not helped by legitimate websites often redirecting you through weird multi tiered domains especially during log in, or legitimate businesses using link shorteners instead of their full domains, or more and more businesses themselves hopping on new TLDs, like the recent cloudflare wallet release.by pibaker
- The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.
- This was a calculated project by ICANN to 1. bring lots more money to ICANN and 2. prevent decentralisation of the DNS root away from the control of the USA.by inigyou
- I'm not convinced that would help.
The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.
Its just attempting to work around incompetence, which always just shows up again somewhere else.
by ddtaylor - In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.by kencausey
- Whois has been replaced by RDAP.by inigyou
- not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam.
But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing...
I understand the idea that they want an official TLD that doesn't necessarily have their trademark in it, so you know it's a link to a Google service but potentially user content, but why have c.gle links to official/urgent messaging??
(at least they don't use 1drv.com in emails like Microsoft.. seriously...)
by varun_ch - It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!by jhbadger
- Every official permissions block and exemption request popup our company's enterprise ops manages appears indistinguishable from malware. It's almost impressive.by glaslong
- I'm forced to have a relationship with a bank that sends out iPad giveaway emails, where your chance of winning is contingent on filling out a survey with personal information. These occasionally go out on the same day as their periodic "how to recognize scams" newsletter.
- A significant number of phishing attempts would be thwarted if email apps had the option to expand the links next to URLs on platforms without mouseover, like mobile.by ern
- We have a training thing at work that sends out phishing emails and you are supposed to report them using a handy button in the email app. If they are training emails you get a good job website that pops up. I greatly enjoy reporting every single genuine email that reads anything like a potential phishing email as there is someone in IT that reviews them and probably gets annoyed at the various groups sending sketchy emails for official business.by starky
- Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate.
Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need to check).
- I wonder how we could describe this so that aging non-technical executives understand.
"It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."
by Terr_ - I would simplify the message a bunch, things like capitalization and even the currency issue, detract from the core issue.
"There are technologies and protocols from the early 2000s that need to be followed to ensure that a a message comes from your company, they are not being followed so messages requesting payment are indistinguishable from impersonators.
The protocols are called DNS and HTTPS, the cost to implement for the country in question would be in the 5 digits range, the benefits would be massively detracting scammers from targetting your company to impersonate and thus harm your brand."
I don't think metaphors help, non technical people, especially executives, can handle minimal technical details.
by TZubiri