From 2024, but funny to read…

What makes this situation so ridiculous is that while we’re all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!

  • bthest@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    17 minutes ago

    It really is the golden age of stalkers and scam artists. You wouldn’t believe how much I know about the previous owner of my phone number. Their name, where they work, where their kids go to school, their pediatrician, their coworkers names and numbers (still included in text conversations). I started responding to the work texts when I realised they were STILL giving out the number (autofill I guess)

    This needs to be made for real

  • sudoer777@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    ·
    5 hours ago

    There’s a healthcare organization where I live that basically dominates everything, and every time they contact me it’s through a new phone number and new format of call/text and they’re super disorganized as well

  • Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    50
    ·
    19 hours ago

    I don’t get why all these big companies just cannot be serious about anything they do. They’re always disorganized.

    • frongt@lemmy.zip
      link
      fedilink
      English
      arrow-up
      24
      ·
      19 hours ago

      It’s because they’re big companies. The bigger they get, the less they can focus on any one thing. More people means more risk of someone being unqualified, and less oversight through more layers of middle management, most of whom are also unqualified.

      Your local business employs fifteen people. One owner, two managers, and 12 staff. Everyone knows everyone and if they’re truly bad at their job they can’t deflect and skate (unless the owner allows it).

      • trolololol@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        13 hours ago

        Only the owner’s son is allowed to, and his cousin, and his wife’s friend. But everybody knows that and just fix their mistakes. They’re such a sport, is this wholesome? /S

  • SpaceCowboy@lemmy.ca
    link
    fedilink
    English
    arrow-up
    67
    arrow-down
    1
    ·
    24 hours ago

    The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn’t going to make any kind of effort towards it. That’s on you, not on us!

    Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you’re redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing… why wouldn’t it just be login.microsoft.com? I’m guessing within Microsoft, it’s probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you’re dumping your credentials into random looking domains, then downloading and installing software from other random domains.

    They just don’t really care as long as there’s no legal liability. You’re data gets compromised because you didn’t notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that’s your mistake and no one can sue microsoft for it. As long their negligence doesn’t meet the legal definition of negligence, they’re not going to put an any kind of effort.

    Anti-phishing training could be so much better… “don’t put your credentials into anything other that *.microsoft.com”. But since these companies won’t make any effort, anti-phishing training amounts to “Just be careful or whatever LOL!”

    • billwashere@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      I’m guessing within Microsoft, it’s probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain.

      I’ve had to deal with shit like this personally so I guarantee that was at least one reason. The departments that control the domain treat it like some sort of power trip and make it hard to do the smart thing.

    • Evotech@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      Microsoft is just a web of legacy software mixed with modern shit. Its a web of stuff that one human just cannot comprehend. Sp yeah

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      19
      ·
      22 hours ago

      You’re data

      Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!

      ;-)

      I think you’re spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.

      For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says “Don’t click links from sources you don’t trust” and doesn’t teach you what to look for.

      To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.

      The linked article is a fantastic example of the worst legit comms I’ve seen. Absolutely looks scammy all the way through.

  • sanpo@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    200
    ·
    1 day ago

    Yeah. Recently I was expecting a message from a bank, finally I got a call… from a chatbot claiming it has an important message for me, but first I have to give it my private info to verify myself and there’s no way to validate the call is legit first.

    When I complained to the bank they just told me I shouldn’t worry, they made the call so it’s perfectly safe and there’s nothing to worry about…

    • Dultas@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      13 hours ago

      Our Dr office does that as well. We have a call about your upcoming appointment, can you provide details to confirm it’s you. They don’t give appointment time, what office it is, patient name nothing. Even if you trust it legit if you or your partner or kid both have upcoming appointments you have no idea which it’s for.

      We just hang up and call to figure out which it was.

      • tb_@lemmy.world
        link
        fedilink
        English
        arrow-up
        78
        ·
        edit-2
        1 day ago

        My banking app has a “is <bank> calling?” button, which is pretty neat. The button is highlighted whenever I open the banking app whilst on a phone call, presumably as a subtle anti-scammer warning.

        e: spelling

        • Buckshot@programming.dev
          link
          fedilink
          English
          arrow-up
          39
          ·
          1 day ago

          My bank has the inverse as well. If i open the app while on a call there’s a huge banner across the top stating they are not calling me.

          • Natanael@infosec.pub
            link
            fedilink
            English
            arrow-up
            3
            ·
            57 minutes ago

            The Swedish banks has a shared identification app, and it gives a big alert every time a login is prompted asking if you called out or got called, and doesn’t let some actions complete if you say you got called

    • warm@kbin.earth
      link
      fedilink
      arrow-up
      62
      ·
      1 day ago

      Always call back. A legitimate bank will say that its no problem to call them back. Never give any personal details over the phone unless you made the call yourself.

  • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    41
    ·
    1 day ago

    Capital One does something similar and it’s so fucking annoying. They send text messages that read “Your transaction for some company was DECLINED! Take action now: http://someweirddomain.com/sketchy/uri

    I used URL Checker to figure out where it ultimately landed and it does go to Capital One.

    I’ve even complained about this and they said, “Well, you should know these texts only come from us.”

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      16
      ·
      24 hours ago

      The solution is: if it looks scammy, get on a different device altogether and use your normal login to the institution to access the issue through the normal channels instead of their “convenient link” through the sketchy service which may well be skimming your data even if they are under contract to your bank.

      Unfortunately, a lot of the institutions’ own interfaces suck so badly it’s sorely tempting to use the quick link.

      • 🌞 Alexander Daychilde 🌞@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        22 hours ago

        But as this article points out - that’s not always helpful when the company makes it difficult to contact them - or in this case, the Duty and Taxes [sic] aren’t a part of the FedEx process but a part of the government, so to FedEx it’s a third-party issue and so when they pulled up the shipment, no mention was made of it (that’s my theory why that happened).

        Your advice is good - I’m just saying it won’t always work. heh. But it is the thing you must do unless you recognize the message source/content and even then, better to just log in separately. heh

  • spizzat2@lemmy.zip
    link
    fedilink
    English
    arrow-up
    23
    ·
    edit-2
    22 hours ago

    A competent government would set up best practice rules, and tools to improve systems. They could even provide some sort of system for consumers to report these issues. Then they could assign companies a cyber security score. Basically, a wall of shame for this stuff, ideally with the option for fines for non-compliance.

    Unfortunately, “competent government” seems to be an oxymoron in most places.

    Edit: to be clear, I provided examples of half-hearted implementations of what I’m talking about from a couple sources, but I’m making no claims about the competency of those governments.

    • AHemlocksLie@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      14 hours ago

      Oh, they’re competent. It’s just that they’re competent at protecting monied interests, not the people.

    • trolololol@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 hours ago

      Microsoft has enough things to be ashamed of, do you think one govt score and a fine of 100M would change any of that?

    • Addv4@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      edit-2
      1 day ago

      Yep. Accidentally imported some parts for my car (thought they were in the states, but no, China), got a random message about duty fees. I initially thought it was a scam, but got another, so I followed the link on a safe device (laptop running Linux). It gave a valid address from the shipping company with details that verified my order, so I had to pay or it wouldn’t be delivered. Very annoying, should have been told earlier that I needed to pay duties/tariffs so I could plan accordingly.

      • Mika@piefed.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        22 hours ago

        Wait this user story doesn’t say why it’s not a scam - you followed a link instead of calling the company and asking wtf is going on.

        • Addv4@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          21 hours ago

          It’s not a scam, it’s a link from FedEx (or in my case UPS) to pay tariff and duty charges. Believe you me, I triple checked the whole thing and it was legit before I even considered paying for it. If you are shipping an item directly from outside the US, a lot of times those charges are left for you to deal with (resellers on eBay or Amazon for stuff from China would pay for those in advance, which is why it’s not always normal). It’s a bigger thing than it used to be, because it used to be that if the value of an item was less than $800 (I believe, it’s been a min), there wouldn’t be duties on it unless it was a big item or some other unusual circumstances. However, Trump screwed that up with the tariff changes, so extra charges are collected by the shipping company directly. The problem is that I wasn’t warned ahead of time (I thought it was coming from the Philippines so the charges wouldn’t be a thing), and that seems to be increasingly the norm for ordering directly from the manufacturer, given soo many are in China or countries we have decided it is a “good” idea to impose tariffs on (which the customer has to pay).

  • blattrules@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    24 hours ago

    So many legitimate messages look like phishing schemes nowadays: those class-action ones are probably the worst offenders for me because it would take no effort for someone to create a scam based on that. Banks are another big one. These companies are making it really easy for the scammers to take advantage of people.

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      7
      ·
      edit-2
      18 hours ago

      Interestingly enough, I’ve found LLMs are pretty good (for now at least) in helping determine if something is legit or not. I’m using them as a glorified search engine in such a case, but having them not only opine as to whether or not it’s legit but link me to some sort of news or other official site about the thing helps.

      edit: lulz, the anti-AI sentiment is so high that people downvote even the places where it’s actually useful. Whatever, bros, make yourself happy. I hate AI in general, but I don’t let that blind me to the few places it’s actually useful. lol

      • merc@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 hours ago

        So, your suggestion is to feed private, potentially sensitive information to an LLM and then trust its judgment?

        I’m sure that a bank / delivery company / doctor’s office that uses such terrible practices is actually on the ball when it comes to making sure all the links they send only work once and time out after a while, right? So, when a guy in Nigeria is working at his job where he reviews LLM sessions to ensure they’re sycophantic enough, there’s no issue. He can’t click on it or sell the data to criminals or anything, can he?

        • 🌞 Alexander Daychilde 🌞@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          private, potentially sensitive information

          I’m really not sure that I’m giving them anything they don’t already have, but i was speaking of incoming potential spam. Like notifications about class action lawsuits. Generally speaking, if a spammer knows something about me, that means it’s already out there. And if they know enough about me, it’s probably an email I can identify as not spam because they know things that spammers wouldn’t know… so I don’t think I’m really pasting in any truly sensitive information in the first place, but I’ve tried to address the point anyway.

  • Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    21
    ·
    1 day ago

    With how much effort is being put into phishing awareness and training, some people/companies still put zero effort into their communication.

    Duting a lengthy process that involved an attorney, I got an email from a firstnamelastname(at)yahoo(dot)com, with no introduction, no mention of my name, a misspelled address, telling me about an appointment at another address that was… screenshotted from a website and pasted as image. Looks sketchy AF by any measure. Nope, that was a real email from a paralegal.

    Filed a helpdesk ticket at work. Get a Teams message from “<FirstName> <LastName> (external)”, asking me my company machine ID in bad English. Responded with “you are helpdesk, do you not know this?”. After a few repeated requests for the ID and not answering any of my questions, I just stopped responding.

    • SpaceCowboy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      23 hours ago

      The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.

      Another manager told users to just bypass the certificate errors on a new web service.

      Multiple times I’ve had people tell me over teams to do all kinds of weird things to work around security errors.

      It’s a weird thing where people in IT think the security rules are for everyone else and not for them. And it’s just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company’s domain] and the cert is valid and if it’s an internal service, use kerberos to validate the user so they don’t even enter a password.

      The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what’s needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.

      • HobbitFoot @thelemmy.club
        link
        fedilink
        English
        arrow-up
        5
        ·
        20 hours ago

        Yeah, there were two IT techs at one company who routinely asked for user passwords, in part because some of the software we used require setup in the user account. I’d say no, but I was on a few reply all emails where others provided their password to everyone on the email.

        I forwarded those emails after the IT manager after the company email server got blacklisted by a client for our emails being used as an attack vector to phish.

  • sem@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    28
    ·
    1 day ago

    I usually post the article in the comments so it is easier to read, but Troy hunt 's website is already so easy to read its a joy!

  • pHr34kY@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    1 day ago

    One cool thing that just went live in the last month or so is SMS Sender ID. You need to file a shitton of paperwork before being given the keys to send an SMS to an Australian with a name instead of a phone number.

    https://www.acma.gov.au/sms-sender-id-register

    I personally had to write the code to make this work for a rather large financial institution that uses AWS for bulk SMS. It was a lot of hoops to jump through. If you get one detail wrong, your SMS just has a phone number instead of a name.

    At this point, it should be impossble to deceptively get “Fedex” into an SMS header.

  • Zagorath@quokk.au
    link
    fedilink
    English
    arrow-up
    8
    ·
    24 hours ago

    This is definitely not the reason I do it, but it’s an added advantage of always getting packages delivered to my AusPost parcel locker. They always arrive in a very consistent format and don’t require clicking any links.

  • alsimoneau@lemmy.ca
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    24 hours ago

    I’m in Canada, I purchased something from the US shipped with DHL.

    They did not send a text. They sent a WhatsApp‽

    Plus, they made me pay import fee on the value of the listed items instead of on the price I payed (there was a 40% discount).

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      24 hours ago

      they made me pay import fee on the value of the listed items instead of on the price I payed (there was a 40% discount).

      All this discount / special deal complexity needs to stop. Now the tax-men are scamming us declaring everything to be taxable at the retail rates when nobody pays the retail rates.

      One price, for everybody, all the time. One tax rate, for everything, all the time.

      • 🌞 Alexander Daychilde 🌞@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        22 hours ago

        One price, for everybody, all the time. One tax rate, for everything, all the time.

        One Price to rule them all, One Currency to find them,
        One Tax Rate to bring them all, and in the shipping bind them
        In the Land of Canada where the Mooses lie.

          • 🌞 Alexander Daychilde 🌞@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            16 hours ago

            LOL, I know it’s not what you mean at all, but your answer gives me the vibes of “so fuck it, let’s all vote for Sauron”. Even though I know that’s not what you mean at all.

            I guess the ONLY good news is that fascism genreally is stupid. (Which is sad considering how stupid they are and yet still manage to do so much damage. I guess democracy and the general public are that much stupider.)

            • MangoCats@feddit.it
              link
              fedilink
              English
              arrow-up
              2
              ·
              11 hours ago

              fascism genreally is stupid

              Strange thing about sociology / political games: stupid works.

              In the runup to world war II both the UK and USA were studying Fascism as a potential way of “getting more” from their populations to compete better in the coming conflicts…

                • MangoCats@feddit.it
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  2 hours ago

                  I don’t know if this ties in well or not, but many times over the years I have talked with otherwise reasonable people who had already, or were about to, make really stupid decisions, and I called them out as such: “this is a really stupid thing to do” - to which they all responded “are you calling me stupid?” - I never succumbed to the temptation of “well, if the shoe fits…” - truth, and what I said, was: “about this particular decision, yes.” They always had some particular goal in mind which overrode all other considerations in their mind, and they couldn’t step back and see how their goal wasn’t 100% all important overruling all other considerations.

    • smeenz@lemmy.nz
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 hours ago

      Why do so many people seem to think that paid is spelled as payed?

  • reksas@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    The scammers messages look less dodgy than the real one, if you dont count the obviously suspicious links. Though it doesnt help that the real one also has link that looks suspicious and also like it was made by scammer who isnt very good at what they do.