From 2024, but funny to read…

What makes this situation so ridiculous is that while we’re all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!

  • Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    22
    ·
    3 hours ago

    I don’t get why all these big companies just cannot be serious about anything they do. They’re always disorganized.

    • frongt@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 hours ago

      It’s because they’re big companies. The bigger they get, the less they can focus on any one thing. More people means more risk of someone being unqualified, and less oversight through more layers of middle management, most of whom are also unqualified.

      Your local business employs fifteen people. One owner, two managers, and 12 staff. Everyone knows everyone and if they’re truly bad at their job they can’t deflect and skate (unless the owner allows it).

  • SpaceCowboy@lemmy.ca
    link
    fedilink
    English
    arrow-up
    47
    arrow-down
    1
    ·
    7 hours ago

    The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn’t going to make any kind of effort towards it. That’s on you, not on us!

    Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you’re redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing… why wouldn’t it just be login.microsoft.com? I’m guessing within Microsoft, it’s probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you’re dumping your credentials into random looking domains, then downloading and installing software from other random domains.

    They just don’t really care as long as there’s no legal liability. You’re data gets compromised because you didn’t notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that’s your mistake and no one can sue microsoft for it. As long their negligence doesn’t meet the legal definition of negligence, they’re not going to put an any kind of effort.

    Anti-phishing training could be so much better… “don’t put your credentials into anything other that *.microsoft.com”. But since these companies won’t make any effort, anti-phishing training amounts to “Just be careful or whatever LOL!”

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      ·
      6 hours ago

      You’re data

      Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!

      ;-)

      I think you’re spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.

      For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says “Don’t click links from sources you don’t trust” and doesn’t teach you what to look for.

      To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.

      The linked article is a fantastic example of the worst legit comms I’ve seen. Absolutely looks scammy all the way through.

  • spizzat2@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    ·
    edit-2
    6 hours ago

    A competent government would set up best practice rules, and tools to improve systems. They could even provide some sort of system for consumers to report these issues. Then they could assign companies a cyber security score. Basically, a wall of shame for this stuff, ideally with the option for fines for non-compliance.

    Unfortunately, “competent government” seems to be an oxymoron in most places.

    Edit: to be clear, I provided examples of half-hearted implementations of what I’m talking about from a couple sources, but I’m making no claims about the competency of those governments.

  • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    28
    ·
    8 hours ago

    Capital One does something similar and it’s so fucking annoying. They send text messages that read “Your transaction for some company was DECLINED! Take action now: http://someweirddomain.com/sketchy/uri

    I used URL Checker to figure out where it ultimately landed and it does go to Capital One.

    I’ve even complained about this and they said, “Well, you should know these texts only come from us.”

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      13
      ·
      7 hours ago

      The solution is: if it looks scammy, get on a different device altogether and use your normal login to the institution to access the issue through the normal channels instead of their “convenient link” through the sketchy service which may well be skimming your data even if they are under contract to your bank.

      Unfortunately, a lot of the institutions’ own interfaces suck so badly it’s sorely tempting to use the quick link.

      • 🌞 Alexander Daychilde 🌞@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        6 hours ago

        But as this article points out - that’s not always helpful when the company makes it difficult to contact them - or in this case, the Duty and Taxes [sic] aren’t a part of the FedEx process but a part of the government, so to FedEx it’s a third-party issue and so when they pulled up the shipment, no mention was made of it (that’s my theory why that happened).

        Your advice is good - I’m just saying it won’t always work. heh. But it is the thing you must do unless you recognize the message source/content and even then, better to just log in separately. heh

  • blattrules@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    8 hours ago

    So many legitimate messages look like phishing schemes nowadays: those class-action ones are probably the worst offenders for me because it would take no effort for someone to create a scam based on that. Banks are another big one. These companies are making it really easy for the scammers to take advantage of people.

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      4
      ·
      edit-2
      2 hours ago

      Interestingly enough, I’ve found LLMs are pretty good (for now at least) in helping determine if something is legit or not. I’m using them as a glorified search engine in such a case, but having them not only opine as to whether or not it’s legit but link me to some sort of news or other official site about the thing helps.

      edit: lulz, the anti-AI sentiment is so high that people downvote even the places where it’s actually useful. Whatever, bros, make yourself happy. I hate AI in general, but I don’t let that blind me to the few places it’s actually useful. lol

  • sanpo@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    160
    ·
    12 hours ago

    Yeah. Recently I was expecting a message from a bank, finally I got a call… from a chatbot claiming it has an important message for me, but first I have to give it my private info to verify myself and there’s no way to validate the call is legit first.

    When I complained to the bank they just told me I shouldn’t worry, they made the call so it’s perfectly safe and there’s nothing to worry about…

    • warm@kbin.earth
      link
      fedilink
      arrow-up
      49
      ·
      9 hours ago

      Always call back. A legitimate bank will say that its no problem to call them back. Never give any personal details over the phone unless you made the call yourself.

      • tb_@lemmy.world
        link
        fedilink
        English
        arrow-up
        56
        ·
        edit-2
        9 hours ago

        My banking app has a “is <bank> calling?” button, which is pretty neat. The button is highlighted whenever I open the banking app whilst on a phone call, presumably as a subtle anti-scammer warning.

        e: spelling

  • Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    18
    ·
    9 hours ago

    With how much effort is being put into phishing awareness and training, some people/companies still put zero effort into their communication.

    Duting a lengthy process that involved an attorney, I got an email from a firstnamelastname(at)yahoo(dot)com, with no introduction, no mention of my name, a misspelled address, telling me about an appointment at another address that was… screenshotted from a website and pasted as image. Looks sketchy AF by any measure. Nope, that was a real email from a paralegal.

    Filed a helpdesk ticket at work. Get a Teams message from “<FirstName> <LastName> (external)”, asking me my company machine ID in bad English. Responded with “you are helpdesk, do you not know this?”. After a few repeated requests for the ID and not answering any of my questions, I just stopped responding.

    • SpaceCowboy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      7 hours ago

      The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.

      Another manager told users to just bypass the certificate errors on a new web service.

      Multiple times I’ve had people tell me over teams to do all kinds of weird things to work around security errors.

      It’s a weird thing where people in IT think the security rules are for everyone else and not for them. And it’s just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company’s domain] and the cert is valid and if it’s an internal service, use kerberos to validate the user so they don’t even enter a password.

      The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what’s needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.

      • HobbitFoot
        link
        fedilink
        English
        arrow-up
        5
        ·
        3 hours ago

        Yeah, there were two IT techs at one company who routinely asked for user passwords, in part because some of the software we used require setup in the user account. I’d say no, but I was on a few reply all emails where others provided their password to everyone on the email.

        I forwarded those emails after the IT manager after the company email server got blacklisted by a client for our emails being used as an attack vector to phish.

  • sem@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    28
    ·
    10 hours ago

    I usually post the article in the comments so it is easier to read, but Troy hunt 's website is already so easy to read its a joy!

  • Zagorath@quokk.au
    link
    fedilink
    English
    arrow-up
    6
    ·
    8 hours ago

    This is definitely not the reason I do it, but it’s an added advantage of always getting packages delivered to my AusPost parcel locker. They always arrive in a very consistent format and don’t require clicking any links.

    • Addv4@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      8 hours ago

      Yep. Accidentally imported some parts for my car (thought they were in the states, but no, China), got a random message about duty fees. I initially thought it was a scam, but got another, so I followed the link on a safe device (laptop running Linux). It gave a valid address from the shipping company with details that verified my order, so I had to pay or it wouldn’t be delivered. Very annoying, should have been told earlier that I needed to pay duties/tariffs so I could plan accordingly.

      • Mika@piefed.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 hours ago

        Wait this user story doesn’t say why it’s not a scam - you followed a link instead of calling the company and asking wtf is going on.

        • Addv4@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 hours ago

          It’s not a scam, it’s a link from FedEx (or in my case UPS) to pay tariff and duty charges. Believe you me, I triple checked the whole thing and it was legit before I even considered paying for it. If you are shipping an item directly from outside the US, a lot of times those charges are left for you to deal with (resellers on eBay or Amazon for stuff from China would pay for those in advance, which is why it’s not always normal). It’s a bigger thing than it used to be, because it used to be that if the value of an item was less than $800 (I believe, it’s been a min), there wouldn’t be duties on it unless it was a big item or some other unusual circumstances. However, Trump screwed that up with the tariff changes, so extra charges are collected by the shipping company directly. The problem is that I wasn’t warned ahead of time (I thought it was coming from the Philippines so the charges wouldn’t be a thing), and that seems to be increasingly the norm for ordering directly from the manufacturer, given soo many are in China or countries we have decided it is a “good” idea to impose tariffs on (which the customer has to pay).

  • alsimoneau@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    7 hours ago

    I’m in Canada, I purchased something from the US shipped with DHL.

    They did not send a text. They sent a WhatsApp‽

    Plus, they made me pay import fee on the value of the listed items instead of on the price I payed (there was a 40% discount).

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      7 hours ago

      they made me pay import fee on the value of the listed items instead of on the price I payed (there was a 40% discount).

      All this discount / special deal complexity needs to stop. Now the tax-men are scamming us declaring everything to be taxable at the retail rates when nobody pays the retail rates.

      One price, for everybody, all the time. One tax rate, for everything, all the time.

      • 🌞 Alexander Daychilde 🌞@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        6 hours ago

        One price, for everybody, all the time. One tax rate, for everything, all the time.

        One Price to rule them all, One Currency to find them,
        One Tax Rate to bring them all, and in the shipping bind them
        In the Land of Canada where the Mooses lie.

  • pHr34kY@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    10 hours ago

    One cool thing that just went live in the last month or so is SMS Sender ID. You need to file a shitton of paperwork before being given the keys to send an SMS to an Australian with a name instead of a phone number.

    https://www.acma.gov.au/sms-sender-id-register

    I personally had to write the code to make this work for a rather large financial institution that uses AWS for bulk SMS. It was a lot of hoops to jump through. If you get one detail wrong, your SMS just has a phone number instead of a name.

    At this point, it should be impossble to deceptively get “Fedex” into an SMS header.

  • reksas@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    4
    ·
    8 hours ago

    The scammers messages look less dodgy than the real one, if you dont count the obviously suspicious links. Though it doesnt help that the real one also has link that looks suspicious and also like it was made by scammer who isnt very good at what they do.

  • Kazel@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    30
    ·
    10 hours ago

    hurr durr sus message here and there but surprise he is expecting a package. that sus af email is exactly that kind of email i would expect in that situation, including broken links and everything. not worth a read

    Pro tip: Scammers want your money, their links will work ;)

    • Funkt4st1c@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      2
      ·
      9 hours ago

      Whoosh.

      Its a legit communication from Fedex. Bpoint.com.au is a legitimate website to pay dues. The point of this entire article is that the legitimate communication from FedEx looks sketchy as fuck even when you are expecting it and FedEx says its real. It is a call to action for FedEx to improve their communication

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      6 hours ago

      Pro tip: You’re gonna get scammed if you ever receive a scam message that appears to be related to something you happen to be expecting. I’m sure you’ll feel all superior to the rest of us until that happens, but it will happen to you.

      And meanwhile, you’re so fucking smart it galls me to have to point this out to you, but what about your grandmother getting an SMS like that? Not everyone is as brilliant as you.

      And the point is that it would be relatively easy for companies to avoid looking so “sus”.

      So instead of feeling smug that you think you can keep yourself safe, perhaps thinking of others might be a good place to start.

      You’re just as bad as the fascists who have zero empathy for anything until it affects them personally.