3 ms·
From the article: the email was spoofed to appear to be from the building company.
by sjroot 8y ago
From the article: the email was spoofed to appear to be from the building company.
- bt3 8y agoYou can see in the screenshot (scan of the email) it was a low-tech spoof. They simply bought the same domain with a different TLD (.com vs .us) There were many red flags that weren't caught, this being one of them.
- sjroot 8y agoYeah, there is a lot of UX work that could be done to address this. For example, a "HTTPS green lock" equivalent for ongoing email conversations.