37 ms·
Thanks FedEx, this is why we keep getting phished
- bell-cot 3y agoSuggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender. Edit: "sender" here refers to the sender of the electronic notification.
- brntn 3y agoIn this case the consequence is that the Australian government agency collecting the import tax doesn't get paid. Which means that they don't release the package to FedEx, and that you don't get your package. FedEx needs to do a better job with these notifications. At the very least they need to hire a copywriter.
- Hamuko 3y agoOur local FedEx once asked me for my details so they could be able to declare my package to the customs and in the SMS message they said that "The sender is paying all declaration fees." I sent them my info and got my package. Then about five months later, I got a bill from FedEx for import fees, tax and service charges. Had to fight with FedEx for some time about it but eventually they agreed to void the bill. At this point in time, I have no idea if I paid the taxes when I bought the stuff, if FedEx paid them out of pocket or if the sender paid them out of pocket.
- actionfromafar 3y agoThere are more possible realities. You listed the 3 first. There are more options, at least these: 4. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have kept your extra taxes for themselves in the end. 5. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have paid the extra taxes. The government kept them because, hey, they trust Fedex. 6. You paid the taxes when you bought the stuff. Fedex wants the taxes anyways. They would have paid the extra taxes. The government kept them but eventually returned them, because some kind of accounting kicked in. 7. You didn't pay the taxes when you bought the stuff. The sender didn't either. Fedex informs the sender and you. Fedex pays out of pocket. The sender pays out of pocket. Could have happened if you paid: 8. You didn't pay the taxes when you bought the stuff. The sender didn't either. Fedex informs the sender and you. Fedex pays out of pocket. The sender pays out of pocket. You pay out of pocket. Fedex keeps twice the taxes in the end. 9. You didn't pay the taxes when you bought the stuff. The sender didn't either. Fedex informs the sender and you. Fedex pays out of pocket. The sender pays out of pocket. You pay out of pocket. The fed. governemnt keeps triple the taxes. And many variations I can't think of right now.
- Hamuko 3y agoI mean, either I paid the taxes when I bought the stuff, or I didn't. There's no reality where I "didn't pay the taxes when [I] bought the stuff" and also I "pay out of pocket", since I have not paid anything after placing the order. I guess there's also the possibility that I paid for the taxes but the seller ended up pocketing them, with FedEx footing the bill.
- actionfromafar 3y agoSorry, I was unclear. I mean in the general case - how much does FedEx win or loose from problems like this? If they win, do they exploit it, by design or incompetence?
- dijit 3y agoAny time the law sets things like "reasonable" it's a quagmire. For every utterance of "reasonable" in law you can be sure over $1B of laywer fees have been (or will be) spent.
- bell-cot 3y agoTrue, to a degree. But let's imagine that (1) FedEx felt that profits were more desirable than legal expenses, and (2) FedEx had some power over the sending and contents of the notifications. Might FedEx decide to start following well-regarded standards for writing and sending legit-looking electronic notifications? And iterate from there, as an ongoing strategy?
- Repulsion9513 3y agoI think the answer here is "don't do things that are borderline (un)reasonable"
- calgoo 3y agoCould just shorten it to: “Don’t be a di*”
- tialaramex 3y agoYou can spend as much as lawyer money as you want on arguing whatever nonsense you want, reasonableness is a common standard so sure, people will have spent lots of money pointlessly arguing about it but that's not a problem with reasonableness.
- MichaelZuo 3y agoSometimes the arguers win and set a new precedent... so it definitely creates a new problem with everyone who subsequently encounters the issue.
- tialaramex 3y agoSure, I'm certainly not going to pretend this is perfect, but it seems to be working basically fine and I don't see "reasonableness" - which actually avoids a lot of wrangling - as a problem. Compare Legal Tender against an ordinary Reasonableness test. Legal Tender says that I only have to accept payment of your debt in specific forms (the "Legal Tender") and I can refuse to accept other payment. So maybe our currency is Doodads, the Legal Tender law specifies that the 10 and 50 Doodad Coins shall be Legal Tender, and you owe me 15000 Doodads. You try to pay by card, I refuse. You try to write a cheque, I refuse. You try to pay with 150 of the 100 Doodad Coins, but again I refuse. Eventually I take you to court and... I win?! You did not pay your debt in the required Legal Tender. With Reasonableness the court might buy that it was OK to refuse to accept the card (maybe I don't have a merchant account) and maybe even the cheque too (but already by then I expect a judge to have a lot of questions about how I thought you would pay and I'd better have a really good answer) but the 100 Doodad Coins are clearly money, with Reasonableness as our standard it's obvious that I lose my case, there's no need to write a law saying "Yeah duh, the 100 Doodad Coin is money" because a reasonable person can see that.
- consp 3y ago> then all financial and legal consequences of ignoring it are on the sender. They are, since non compliance will either result in destruction of the package or sending it back (differs a bit per country and type of goods). It's a bit sad there are no easy ways to prepay taxes and it's hit or miss if you get checked. I'm glad the EU figured it out and have almost no weird surprises any more, except from the Uniteds (states and kingdom).
- matsemann 3y agoI almost got in some trouble because of that. A "bank" I wasn't a customer of kept sending me messages about "urgent, answer this form with your personal details or we will lock your account". Seemed quite scammy to me. Then I later got a physical letter in the mail about the same, and then I called the bank. Apparently I had some account there holding some pension stuff from a previous employer. Shrugs.
- j16sdiz 3y agoThe management will overreact by implementing 100-factor authentication, requiring 30 letter password with mandatory Unicode symbols
- bell-cot 3y agoA bunch of extra authentication factors and a password sure sounds like phishing for sensitive PII to me.
- fma 3y agoMaybe its just the hunan brain bad at perception, but I feel like there's some system compromised and info is leaked so scammers know when you are expecting a package because FedEx/USPS spam text increases.
- MattGaiser 3y agoBut in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.
- latexr 3y ago> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.
- the_snooze 3y agoThese scammers probably aren't targetting specific individuals. They blast these messages out to a bunch of randos, and odds are very high that at least some of those are expecting packages just by chance. The marginal cost of an added message is tiny compared to the reward of one successful scam.
- resolutebat 3y agoIn Australia, if you buy something off AliExpress and use the budget shipping option, it will take anywhere from one week to two months to arrive. Shop there a couple of items a year and you're always expecting something. What annoys me is that even the legit SMS notifications contain nothing identifiable about the package or sender, it's always "Your shipment #QWERTYUIOP is arriving by UnrelatedCourier between 1 AM and 11 PM today".
- joseda-hg 3y agoIf you buy stuff with long delivery estimates, you might very well be even with relatively low numbers, Electronics from China, Custom Comissions or things with waitlists Some of those can have over a month between purchase and reception, and might be shipped at arbitrary dates after purchase I'm not that big of an online shopper, but there's certainly people that are
- MattGaiser 3y agoMaybe FedEx sees better results and gets more payments from appearing scammy? Scammers seem to do alright. I know we tech people think this is type of messaging is ridiculous, but I’m constantly pulling less technical friends and family away from crap like this. Half a dozen have asked me about Elon Musk’s crypto trading breakthrough.
- labster 3y agoI doubt FedEx’s customer engagement increased by sending a query string with no domain or protocol. Someone’s asleep at the wheel here.
- tomschwiha 3y agoWell theoretically they force people to Google FedEx which IS a strong signal for google people are interested in the FedEx Brand. Doubt however that's the reason.
- tomashubelbauer 3y agoI know this comes down to institutional incompetency, but at some point there was a singular human person putting the template content the SMS message in question was generated from into some computer system somewhere and I genuinely wonder what was going on in their head that made them string the words together in this way. You'd have to give it a true, earnest shot to make it worse.
- MattGaiser 3y agoYou assume it is a singular person. Could easily be one person writing the message. Another who demanded partial edits in a Jira ticket. But then the data types didn't match up with what the writer requested and then the dev didn't want to deal with it and just shipped it. Or it could be that the message is made with a bunch of disjointed and constructed if statements and only the final output is piped to the customer. I have seen some very terrible log messages like that as nobody is looking at the entire message, just the little bit in the conditional they are editing at that point. As an anecdote, I once worked on code that generated these very detailed error messages about why something went wrong. I discovered most never made it to the customer as someone later down the line reassigned a variable rather than +=. Piles of support tickets could have been avoided.
- sverhagen 3y ago"The words" are probably nested templates so that at the level of input it's hard to really understand what the completed end result looks like. Also, there's many well-intentioned people in tech doing stuff that's just a tiny bit too complex for them to execute by themselves without a buddy or a reviewer. There are also whole teams and departments at big enterprises where someone might not be doing it alone, and they might also not be completely incompetent, making them the star engineer on the team, while everyone else wisely keeps their mouths shut since they surely don't have anything to contribute to the process. All the really good people that worked there, were snatched up by some fancy, greenfield project, on another floor, or got a position on some elite "refactoring team", surely not wasting their time on updating templates.
- MichaelZuo 3y ago
- chb 3y agoNot that I’m endorsing the use of smart phones, but FedEx does have a mobile application. Why not just use that for notifications regarding deliveries?
- consp 3y agoThe FedEx one is meh and does afaik, but some (looking at you dhl) are almost useless as they provide little information (tracking info is hidden sometimes), sometimes do not allow you to add the parcel as it has a tracking code from a foreighn service which you cannot use and you have to figure out the local one, are full of "news" also known as ads and do not allow you to select the dropoff location closest to you (go ups!). Sorry, /rant.
- lobsterthief 3y agoI feel like DHL is the “YOLO” of delivery companies. My stuff always arrives, somehow, despite the entire process seeming archaic.
- genman 3y agoYou mean everyone should install a piece of software from a company that appears to be ignorant about security?
- dotancohen 3y agoAnd buy a very expensive tracking device with frequent security issues? I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.
- risfriend 3y agoAnd where is this?
- e40 3y agoYet another reason why I will try to never use FedEx. UPS is so much better. Banks do similar dumb things. I once vented to a a Wells Fargo security manager about a similar issue. They had no defense at all.
- gregoryl 3y agoAhh yes, the FedEx GST payment system is wonderful! You can find that number in the sms on an official FedEx page somewhere or other - I ended up using that as enough evidence to trust and call. I get the feeling this system as a whole doesn't see much use - from a FedEx perspective, the vast majority of people paying duty will be via some specialised importer, not b2c direct.
- nonrandomstring 3y agoYour security is increasing at risk from organisations and corporations whose own grasp of security is appalling. Because instead of dealing with it they externalise risks and consequences onto the public and customers. Even worse, is where attempts to query that security is actively punished. This is typical now. Listen here (at 42:20) with an example regarding the UK NHS whose incompetence plays directly into the hands of cybercriminals. [0] https://cybershow.uk/episodes.php?id=24 https://cybershow.uk/episodes.php?id=24 (time:42:20)
- corndoge 3y agoSince the link to this podcast is in your profile, you're affiliated with it, right?
- nonrandomstring 3y agoYes
- em-bee 3y agoEven worse, is where attempts to query that security is actively punished. like this case: https://news.ycombinator.com/item?id=37250024 https://news.ycombinator.com/item?id=37250024
- nonrandomstring 3y agoExcellent example em-bee, thanks! I'm writing up a blog post on this subject, so more examples welcome plz.
- gpderetta 3y agoMy UK bank semi-regularly cold-calls me and ask me to authenticate by providing personal information. When I decline they readily tell me instead to call some number available on the bank website. So they not only are incompetent, they actually know it.
- 3y ago
- hubraumhugo 3y agoI found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessant_die_sparkasse_schickt_mir_einen/ https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.
- Kwpolska 3y agoThere's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.
- yau8edq12i 3y agoI've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.
- Repulsion9513 3y agohttps://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A62011CC0049 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
- ar0 3y agoI do not read this court decision like that at all: the point of contention there seems to be that the customer was just sent a link to a webpage (where the contractual terms can be changed from under him at will by the company, thus this not being durable). The court makes it pretty clear in my (non-lawyer) opinion that attaching a PDF to the email would have been fine.
- actionfromafar 3y agoI was prepared to disagree with you, but I now have the same interpretation you have. Durable medium can be email - but the example seems a little fuzzy, for instance a durable medium is definitely when the email is stored on a HDD on a customer device. But is it still durable medium if the email only exists in a webmail? Probably yes, but maybe no. So the conservative approach would be to send paper for some things. (Or in this case, stupidly, USB devices. Banks, don't do that, please.) Ramble Edit: it's unfortunate IMHO that there is no "read only" medium anymore. Not sure what it would look like now when USB-C is taking over the world, and that ship probably sailed, but it would be really cool and useful to have the option of a "data only" USB. Maybe computers could have one USB port marked as "ROM". Or a switch or LED symbol indicating "ROM safe" mode. When using such a ROM port, anything USB inserted there would only look like a DVD reader. A USB drive would get its files "mirrored" into a virtual ISO filesystem. Any other devices, such as keyboards etc would be just ignored and not connected to at all.
- arkitaip 3y ago> What makes this situation so ridiculous is that while we're all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers! Hah!
- urbandw311er 3y agoWow. Just wow. Troy Hunt does an incredible job of calling out this utterly piss-poor performance from FedEx. Shame it needs somebody with a platform like this to draw attention to it. They should find a way to make them somehow more liable for fraudulent losses. It's gotten to the point now where it sometimes actually is impossible to speak to a human being in customer service - the thick layers of chat bots, deliberately gated 'contact us' pages and "why not use our app" nags.. ..if you're savvy enough to know already that only a human can resolve your particular query, getting hold of one can become a time consuming and sometimes traumatic experience. (only slightly tongue-in-cheek, I do actually believe this affects mental health)
- nonrandomstring 3y agoWhat concerns me is that this mentality of erecting infuriating barriers will eventually lead to direct in-person stalking of staff. If anyone has honest anecdotes around this I'd love to hear from you (maybe privately is best if its detailed accounts)
- franze 3y agoThe Booking.com scams look better than the actual "Self check and pre payments solutions" links send via the Booking hotels. 1 time I was right it is a scam, 2 times it was wrong. Booking.com should make a proper report payment circumvent button and kick out all hotels who do it.
- throwaway290 3y agoHow do those booking.com scams work?
- fmobus 3y agoIn a case I read (can't remember where), reservation data was somehow leaking (either from booking or from hotels), and scammers were sending messages purporting to be the hotel saying the room was cancelled or mischarged or something like that.
- zapu 3y agoIt's even worse than that. Scammers are sending messages through booking.com, so you get a message from the hotel, in your booking.com inbox, with a link to a payment site that just makes a payment to the crooks. The root cause is either hotel employees installing session-stealing malware, either accidentally or by being part of the scam.
- franze 3y agohttps://amp.theguardian.com/money/2023/oct/23/bookingcom-customers-targeted-by-scam-confirmation-emails https://amp.theguardian.com/money/2023/oct/23/bookingcom-cus...
- omar_alt 3y agoOne out of ~10 international shipments of records I had in the last year one was from FedEx and they sat on it in their out for delivery warehouse in a nearby town for two months with the usual pass the buck/pillar to post treatment. The extra fees plus customs they put on added up to 40% of the value of the items as well. DHL and UPS arrive within a week and are normally no higher than 25%
- caddemon 3y agoFedEx seems to be the worst option domestically too. Maybe it depends on your location but they're the only service that somehow fails to deliver signature required packages to my mail room. I've also tried to have them contact me directly while I wait at home and I've tried to waive the signature requirement online, but they still just say "delivery attempted" for 3 consecutive days and then hold stuff at their warehouse. Happened to me twice recently. I now try to avoid buying anything expensive that uses FedEx to ship. A funny thing I discovered in this process is that "delivery instructions" are shared for all packages to a given address regardless of the associated name, and never flushed unless you go in and do it manually on their website. I found the name and contact information for the prior tenant of my unit on the FedEx site with no other info besides 1 tracking number to the address (it also let me change the delivery instructions with said info). Potentially they were still calling that person when they tried to deliver initially, though I have other reasons to doubt they actually came to the door that day.
- hnfong 3y agoMy best theory is that FedEx outsourced the process of sending these SMS notifications to some external contractor. Of course, the scammers already have the scam systems in place, so they can win the bid on price :D I know this sounds ridiculous, but I doubt anything will make better sense than this :P
- sebtron 3y agoA few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them from a domain that I can immediately link to the company. - No alternative way of resolving the issue is provided other than clicking on one of those links (no "go to your account settings", "contact your line manager" or so). And still, it turns out it was real. ~100k employees company btw
- Rygian 3y agoDid you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.
- sebtron 3y agoI wanted to, but I could not find it. It turn out I could not see the "report phishing" button because of an Outlook glitch. Thanks Microsoft.
- lrem 3y agoForward the email to your security org?
- alistairSH 3y agoThis. We have a dedicated phish/scam/it-sec channel in Slack for this (in addition to an embedded “report this email” plug-in in Outlook).
- sebtron 3y agoI did end up forwarding the email to another IT service address (one that I knew was legit). They thanked me for the feedback and said they would improve the message.
- Havoc 3y agoCorporates are shockingly incompetent at this sort of stuff. Seriously just use your main domain for URLs. For me at least that clears up 99% of this. I dont want to memorise a list of valid mystery domains for each shipper. Is that really too much to ask?
- jiggawatts 3y agoIt is. If they use their main domain, their normal corporate email will get blocked by anti-spam filters. So everyone uses a different, unrelated domain for bulk mails.
- Sophira 3y agoOkay, but this isn't a bulk email. It's a very specific situation personal to the receiver and will never be sent to anyone else. (Obviously the template will be used for multiple emails, but that's not what defines a bulk email, even though bulk emails can also be defined using a template.)
- thomastjeffery 3y agoSo use a different domain for corporate email. The only reason not to is if you are prioritizing the identifiability of your corporate email over the identifiability of your actual customer-facing operations.
- jiggawatts 3y agoWell, of course. If the CFO gets their mail dropped, they'll fire the IT guy. If a customer is a bit cranky... nothing happens.
- wccrawford 3y agoWhen I bought a car once, I received an email a few months later saying I hadn't proven I had obtained insurance on it, and the bank wanted me to visit a domain that wasn't theirs to provide proof. The email I got looked like a badly-scanned letterhead and was very, very fishy. After I received a few of them, I finally contacted the bank and it was legit. I tried telling the office person (not just a clerk at the counter, someone with their own desk) about the situation and they couldn't understand why it was bad. I soon paid off that loan and got away from that bank.
- dudul 3y agoHappened to me with my mortgage. Got this very weirdly phrased letter about how my homeowner insurance info needed to be updated/confirmed and that I had to go to <random website> to clear it out. I called my insurance broker and yes indeed it was legit. I also tried to explain to them how this letter was a few steps removed from a Nigerian prince scam based on all the red flags, but i don't think it made a big difference.
- judge2020 3y agoThe national insurance providers are often pretty slow or shady when it comes to claims, but I've never had a bad experience with Allstate or State Farm when it comes to their cybersecurity and domain experience. Allstate's frontends (web and app) sometimes feel more clunky but their APIs feel good enough and sites seem to follow good design practices.
- lifestyleguru 3y agoPhishing and workflows like this are handled by the same profile of employees. Low paid, outsourced, hating their job, doing the least possible. That's why they're indistinguishable. Reliable workflows, record profits, high salaries and bonuses for executives - pick two.
- anonymous_sorry 3y agoIn a Blackhat talk several years ago Adam Shostak had a clever term for companies interacting with you in ways that were indistinguishable from scammers. But I can't remember what the memorable term was.
- nonrandomstring 3y agoAnyone found this? Can you remember the episode?
- anonymous_sorry 3y agoFound it here. https://i.blackhat.com/us-18/Wed-August-8/us-18-Shostack-Threat-Modeling-in-2018.pdf https://i.blackhat.com/us-18/Wed-August-8/us-18-Shostack-Thr... He used the term "scamicry": legit communications that mimic scams. For example when a company calls you directly and asks for your security details, but offer you no way to verify who they are first.
- nonrandomstring 3y agoYou star! Thank you anon.
- seb1204 3y agoI have received SMS mostly a day after I ordered something of Amazon. I'm not often ordering something, so sometimes I go weeks without scam SMS.
- hugoromano 3y agoDHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if you refuse to use them. At the end of the day, they don't care if we get phished or scammed; it is all of customs confusion. Next time process your customs form, you will realise how much money you will save, and the form only has less than 8 fields, the Union Customs Code is easy to read.
- JackMcMack 3y agoI've often felt frustrated by the processing fees. Can you elaborate on handling this yourself? Which EU country are you based in?
- AnssiH 3y agoDoes not answer your question, but related: In Finland you can declare DHL/UPS/Fedex packages yourself with customs and pay directly to them, with no fees to carrier (it took a Finnish Competition and Consumer Authority decision in 2017 to get rid of the fees, though). But this is a bit different as it is not a hidden option but standard procedure (though you still get the option of paying the carrier to declare, instead). Declaring inbound packages to Customs by yourself was already the standard here for postal parcels even before Customs internet services, so this was not a completely new way of working.
- hugoromano 3y agoI'm in Portugal. If you put enough pressure, they release for you to process, it is the law.
- dddddaviddddd 3y agoSame in Canada, though, if I understand correctly, you have to visit a customs checkpoint in person to make a declaration: https://goingawesomeplaces.com/how-to-avoid-paying-ups-brokerage-fees-in-canada-self-clearance-instructions/ https://goingawesomeplaces.com/how-to-avoid-paying-ups-broke...
- dghughes 3y agoObviously just call the totally normal support number shown 1 800 111 112 /s
- cbolton 3y agoThis fits nicely with my experience of FedEx. They sent me a bill 7 months after I had received the package. A few days later I get a reminder that doesn't include the necessary information for payment, which seems rather lazy and stupid since an unpaid bill might well have been lost. It refers me to www.fedex.com where I'm told to create an account. I do that only to find it doesn't know anything about my bill. By chance I do find the original bill shortly afterwards. Turns out this bill sent 7 months late had very small text saying "to be paid immediately", the first time I see that on a bill (it's usually 30 days in my country). Of course they sent me a second reminder 10 days after I paid.
- proaralyst 3y agoI've had this, but the first thing I heard was that my customs charge was sent to collections. Cue lots of scary messaging about debt collection, none of which said anything other than this was for a FedEx parcel of some kind
- aerjaser 3y agoThis is common practice for some businesses. If you ever drive on a toll road in Texas (there are a lot of them and more every year) there are no toll booths that allow you to pay then and there but you'll get a bill in the mail 6-12 months later informing you that this is your fifth and final warning and you owe $4 for the toll and $80 in late fees. I guarantee you the people behind this have friends or family in the Texas legislature supporting them.
- tome 3y agoWhy didn't he email the address provided in the SMS, which will obviously go nowhere else other than to FedEx?
- nmstoker 3y agoReminds me of the mess that the LTA are in the UK regarding getting Wimbledon tickets. Over the years they've changed domains several times, had a breach, reset passwords multiple times, and now do part of their login via a random third party site (but to make it worse they push you to sign you up to a second form of account which logs in separately!)
- albert_e 3y agoThe biggest banks and brands in India as well as the government organizations do this type of poorly thought communications all day. The other day an email from the oldest and biggest bank of India landed in my inbox Truncated Subject line on mobile said "Cash Withdrawls made ..." My heart skipped a beat because I did no such thing with my account. Turns out it is a marketing mailer with subject "Cash Withdrawls made Easy!" Facepalm.
- fmobus 3y agoWell, the marketing person who came up with message can pat themselves in the back because you bet the engagement on that one was thru the roof.
- dwighttk 3y agoSo far every time I’ve gotten dodgy AF texts or emails I’ve been able to verify at the real site… crazy that FedEx doesn’t have the info attached to the tracking.
- krisoft 3y ago> crazy that FedEx doesn’t have the info attached to the tracking It is crazy how much the "paying duties at the border" situation feels like an afterthought for all currier companies. It is almost as if it was not really their design they just tackled it on later. I wanted to send a present to my brother in an other country using DHL Express. It was impossible to convince them that I would like to pay duties. Not a thing. Can't be done.
- gpderetta 3y agoThey get a significant markup for providing this "service" to the receiver, so it is not in their interest to help the sender. More charitably the actual duties to be paid might not be known until the package reaches the border at destination.
- krisoft 3y ago> They get a significant markup for providing this "service" to the receiver, so it is not in their interest to help the sender. I understand. It is a service, and I am willing to pay for it. The alternative is that I don't send presents with them. "Happy birthday! Quick pay 20 bucks before you can get your present!" is not really a good experience. > More charitably the actual duties to be paid might not be known until the package reaches the border at destination. I understand that too. That is why they are sending the request for the duties only once the package is at the border. But why can they send the request towards the recipient and not towards the sender?
- naruhodo 3y agoThere really needs to be some kind of cryptographic authentication system for text messages and caller ID that gives the recipient absolute certainty about the identity of the sender. Registering a name in this system should require real-world proof of identity including a business address and the contact information of real people. There should be serious financial penalties for identity fraud. It should be an open standard that can be implemented in open source software. And all the big phone manufacturers should be legally compelled to use it.
- chatmasta 3y agoThis will never work as long as calls and SMS messages are routed over the existing telecom networks. The infrastructure is simply too insecure to enable this kind of scheme. If calls are routed over internet then it becomes more viable but obviously there is still a large coordination problem and misalignment of incentives.
- zokier 3y agoBS. Many countries have successfully implemented SMS sender registration/verification schemes. See for example here for a list: https://support.sms.to/support/solutions/articles/43000562659-international-sms-sender-id-regulations-and-requirements-list-of-countries- https://support.sms.to/support/solutions/articles/4300056265... The details differ per country, but either all non-registered senderids will be blocked, or registered senderids will be allowed only from authorized sources. The degree of mandatoriness varies also, in some places its mandatory for telcos to comply, in other places it is some voluntary cooperative scheme. But despite such details, the problem is clearly not completely intractable.
- zokier 3y agoRelevant as article was about Australia: https://www.acma.gov.au/articles/2024-02/five-telcos-breached-allowing-sms-scams https://www.acma.gov.au/articles/2024-02/five-telcos-breache...
- deleted 3y ago[deleted]
- emilecantin 3y agoCanada Post actually does something good here: you can pay from the tracking page. And they don't add any fees, you just pay the duties and taxes.
- Majromax 3y ago> And they don't add any fees, you just pay the duties and taxes. Are you sure about this? Canada Post's webpage (https://www.canadapost-postescanada.ca/cpc/en/support/articles/customs-requirements/customs-duty-taxes-and-exemptions.page https://www.canadapost-postescanada.ca/cpc/en/support/articl...) says: >> We apply a handling fee of CAN$9.95 per dutiable or taxable mail item.
- emilecantin 3y agoI might misremember the last time I had to pay duties, then. Still, 10$ is much more reasonable than UPS's 70$ plus taxes!
- noirscape 3y agoHere dutch customs doesn't even send you links for this stuff over SMS due to all the spam. They tell you to look up the package tracking number on the PostNL (the national universal delivery company) where you can pay for it. All you get over SMS is a heads-up to check and the ID to enter (you need to combine it with your zipcode).
- sureglymop 3y agoAt my company, they announced that in the upcoming month there would be an internal phishing sensibility campaign. Then, in the same month, they started sending out incredibly dodgy looking emails to "security training" provided by an external website. Of all emails, those looked the most like phishing but they are not. I decided that I refuse to do this training completely because to me it seems crazy how that was coordinated. I would never lose my job over this but it is amusing that I get an "Urgent: security training still outstanding" about once a week which just goes straight into the trash.
- dghlsakjg 3y agoMy company uses an outside vendor for security training that requires us to login using company credentials. The outside security vendors also run phishing security campaigns that they send out from their own domain, and that have "phishing" URLs that point to the same domain we do the training on. I got reported as being phished for following a link that goes to the SAME domain as our required security training. Our security compliance team got my point when I reported every required training reminder as coming from a known phishing domain.
- ilogik 3y agoText message from my mobile carrier: Be careful! Never click on links received in messages from strangers. Learn more at www.....
- axelthegerman 3y agoThe other thing I try to understand but just can't is how Telco providers can be so incompetent in effectively stopping scam texts. First of, texts are not encrypted and they can see ALL communication. On the other hand the US forces me, using Twilio for SMS automation, to sign up "campaigns" with "Sample messages" if maybe all I want to do is building a personal assistant with text commands. My messages will get hit with fees for non compliance, or end up silently blocked without any visibility. Then there are these scammers sending the same or very similar messages to millions of people, pretending to be the same 50 companies (national banks, shipping companies, cell phone carriers) - how about these $bigcorp register their "campaigns" to combat scams and they'll leave me alone (one number sending texts to always the same one or handful of numbers). ... Oh wait I figured it out! Telco don't care, they enjoy inflated traffic numbers in their network and charge for it - why would they stop it
- cfinnberg 3y agoI received once a mail from my bank at the time stating that they have a message for me, but for security reasons I have to read it on their systems. And they provide the following link: https://cbk.pwlnk.io/~hc https://cbk.pwlnk.io/~hc The bank's name is CaixaBank. I was wrong and the message was legit. My first thought was it was a scam :)
- bonton89 3y agoI definitely would have called on that one and tried to avoid the whole link altogether.
- wiradikusuma 3y agoI frequently buy things from Tokopedia, one of the largest e-commerce in Indonesia. At one point, I ordered something, and the next day, someone contacted me through WhatsApp, claiming to be from the courier (with the company logo as a profile picture). They said my package was rerouted, and I had to click a link to fill out some form. Typical scam message, with typo and urgency. I can track the status of my order in the app, and it says it's in transit somewhere. So, their explanation matches. You might think, "Well, that's obviously a scam. They would not contact you through personal WhatsApp!" But sometimes couriers DO contact you to ask for your precise location or notify you, "Hey, I left your package with your neighbor. Here's the photo." I'm just wondering how the scammer got this info that Mr X is expecting Product Y from Shop Z. I almost fell for it (I was in the middle of something and got distracted), and I can only imagine the unlucky victims. It happened 2-3 times during that period and then gone. Did someone find out and fix it? How did they find out? Because I'm guessing there are lots of hands involved in the delivery pipeline.
- pflenker 3y agoOne time working at a bigger company I received an email that was a very, very obvious, poorly made phishing attempt - in fact, so poorly done that I wondered if I could break the login form somehow. So I submitted bogus data to see what happened - Turns out it was part of some kind of "test" of the company to raise awareness for phishing, and I failed the test since I submitted the form.
- pch00 3y agoReminds me of the "householdresponse.com" domain quite a few people in the UK have been exposed to at one time or another... https://www.bleepingcomputer.com/news/security/uk-gov-keeps-repeating-its-voter-registration-website-is-not-a-scam/ https://www.bleepingcomputer.com/news/security/uk-gov-keeps-...
- gaogao 3y agoIn illustration of the prevalence of the phish, I got a dodgy SMS from a sketchy email address that "The USPS package has arrived at the warehouse and cannot be delivered due to incomplete address information." while I was reading the article on my phone.
- red_admiral 3y agoThe number of "Please click this Microsoft Sway link for an important update" emails that I get these days ... sigh. So far they've all been legit (although rarely important), but if I ever go over to the dark side, that's what my first phishing campaign will look like.
- MarkusWandel 3y agoThis is a real problem with so much stuff outsourced to external cloud providers. Used to be, if it was from the company intranet, no problem. Now every survey, every training thing, every new flavour of the month is from external mystery domains and then it wants your corporate credentials to log in. At my company they keep us sharp by running "fake phishing" campaigns to kind of gamify recognizing phishing emails. But this shouldn't be necessary for legitimate corporate stuff.
- al_borland 3y agoIs it common for people to have to pay previously unknown charges to get their packages delivered? I don’t frequently make international orders, but have a few times, and have never seen this. Everything has always been charged up front.
- Kye 3y agohttps://en.wikipedia.org/wiki/Cash_on_delivery https://en.wikipedia.org/wiki/Cash_on_delivery There are also import duties in some places like the US that can be a surprise if you don't know where the seller is or how they're shipping: https://en.wikipedia.org/wiki/Customs_duties_in_the_United_States https://en.wikipedia.org/wiki/Customs_duties_in_the_United_S... I forget the name, but the USPS has a special service shippers at companies like Aliexpress often use to avoid stuff like this when shipping to the US.
- Symbiote 3y agoThe EU and UK have systems to allow the tax to be paid when purchasing, for large companies that support it like Ali Express. These are fairly new. Countries also have their own limits below which they don't bother with the taxes. There was so much abuse of this in the EU+UK the limit is now zero. The only time it should be surprising is when the foreign website isn't paying the taxes, and it also isn't clear it's a foreign site. Generally on cheap crap from China.
- crazygringo 3y agoAbsolutely. That's very often how customs works. As a general rule, the sender is responsible for postage, while the recipient is responsible for customs, and the package only gets released to them once they pay it. But many times there are no customs fees, so there's no issue -- it depends entirely on the pair of sending and receiving country and the category and amount of merchandise. That may have been your experience. Generally speaking, customs can't be charged upfront with your order. Perhaps there are exceptions with certain delivery services in certain countries which have managed to modernize some of it, but I haven't come across that yet.
- prakashn27 3y agoAt this point I use sms only for 2 factor authentication WhatsApp for connecting with friends and family Email for rest of the stuff.
- jwally 3y agoI got an sms from "Nikki Haley" the other week asking me to join some political rally. This has SUCH potential for abuse. A) spreading misinformation. Not hard to confuse people that their polling location is closed but the inconvenient one across town is still open B) fake fundraising. Blast out an sms from "citizens for action" who need money to support ${popular cause/candidate}
- PaulHoule 3y agoI just got a letter from the insurance agent that I thought was going to say "THIS IS NOT A BILL" but it was a cancellation notice for my homeowner's policy. The letter was designed to be as difficult to read as possible, about 97% of the space was form letter elements that weren't relevant, in the middle of page 2 there was an area covered with large black underlines that had the reason for the cancellation typed lightly in it. It is probably time to look for a new insurance provider but I was thinking of calling back the insurance agent and telling her I was planning to run for state senate on a platform of reforming the insurance laws and legislating that you can get 20 years in prison for sending a letter that says "THIS IS NOT A BILL" and that insurance paperwork has to be written in English excerpting any words that are shared with Latin or French. (Which I'm sure the French would approve of)
- habosa 3y agoFedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the same. 2. When I moved out of that building I wanted to add my new address to delivery manager … but I couldn’t. The site errored every time. The reason? Some forums revealed the correct hypothesis that if you have special characters in your password then some parts of the site are permanently broken for you. Including the change password flow. So I had to have my wife make a new account with a worse password. Truly amateur stuff for an otherwise very impressive company.
- eropple 3y agoUPS is up there, too. I still get text messages about an old address on an account I can't log into for...reasons. (Special characters sound plausible! And of course the password reset flow doesn't work.) Wonder if they share a vendor.
- judge2020 3y agoUPS is better in my experience with them always requiring a code sent to me via USPS to verify access to UPS My Choice, except for when I signed up with a new construction address - It also seems to only show me packages with my last name on it, packages with just a company name did not show up.
- ryandrake 3y agoI can’t believe it’s 2024 and we are still seeing bugs with handling “special” characters. Unicode has been here for how long? Robust string handling is supported in every language. There is no such thing as a special character. My name should be able to contain Chinese characters. My password should be able to contain emojis. What is this Stone Age shit still running on companies’ backends?
- 3y ago
- hibikir 3y agoSt Louis county just did some of this for their property declaration system. It used to set right there in the website: An ugly set of forms, but perfectly functional. Apparently they ordered a rewrite to yet another contractor, and now you get a link to.. stlouismosmartfile.tylerhost.net. Following the link, from the county's own website, warns of a third party link! The link prompts the user to register... and the validation email, unsurprisingly, is sent to spam, and then flagged as risky by gmail! Enough red flags, you'd think it's an old soviet military parade, but no... when you call the county, they say that yes, this isn't them getting hacked (again), but the way things are supposed to be. This is something everyone that owns any property and is a resident of the county must fill out: About half a million accounts will be created in two weeks. Making sure that all of this comes from the county's domain? Too difficult for them. And all for a website on the other side that doesn't look much better than the old one.
- sf_rob 3y agoI contacted Wells Fargo to complain that their use of 3rd party surveys from non WellsFargo.com domains attenuates customers to entering banking information to 3rd parties. They had one incompetent employee contact me to assure me that the communication was legitimate (not the complaint), then escalated to another employee who understood the complaint and promised to escalate… 6 months later I get an email assuring me that the communication was legitimate and closing the ticket.
- ActionHank 3y agoThank goodness it was legitimate.
- vijaypatil 3y agoDo I see a YC pitch idea right here - a platform that gets such comms right and secure would be a right a Solution to develop. It seems major companies can’t get it right or don’t want to get it right.
- Triphibian 3y agoThere are banks in the US that send sketchy looking text message like this when you get transferred funds. They literally ask that you follow a texted url and enter your bank information.
- Rudism 3y agoA while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security number, at which point alarms started going off in my head and I started sweating about even giving the last four digits to a stranger who had called me out of the blue. I told him I wouldn't do that, and was there a number on the bank's website I could call in order to get back to him, in order to verify that he actually worked for the bank. The guy started acting really annoyed, and said he didn't think there was any number on the bank's website that could reach him, and that if I didn't give him my full social security number he would be forced to reject the loan application. I told him I didn't feel comfortable giving that information to someone who had phoned me, and if there was no way for me to call him back through an official bank phone number then the call was over. He hung up angrily. Turns out he actually was from the bank and he did cancel the loan application.
- Breza 3y agoReminds me of the repeated calls my parents received to refinance their mortgage under some government program. It took them months to realize it was legit.
- bastawhiz 3y agoI'd have read him the riot act on the phone. My bank has big warning banners on virtually every page of the site warning me to be careful of scammers. Someone calling me on the phone and asking for my TIN? Yeah, I don't think so.
- krisoft 3y ago> I'd have read him the riot act on the phone. No point. If he is a scammer he has a thick skin. If he is working for the bank this is either a training or a policy issue. Just refuse politely and report to the bank. (preferably to some security channel if there is one.)
- jwie 3y agoThe fact that there's no formal difference between tax payments and scam payments should be tickling the part of your brain; this means something.
- pbackx 3y agoI think this will be full of similar experiences: Some time ago my wife's cards suddenly got all kinds of charges, clearly not ours. So we call the bank and while they put the blame on us, among other things they said the bank never ever would contact us by SMS and we may have clicked on dodgy links in one of those messages. Eventually they decide we should replace all our cards. 5 minutes later we get an SMS asking us to call an unknown number to set our PIN code for the new card. It contained at least 5 warning signs as in the author's article. We call them back asking them what that SMS is about and the only explanation is "That is the good kind of SMS, you can trust it" (Eventually we did get all stolen money back, but it took a while. We never got a plausible explanation of what may have happened and what we could do to prevent it in the future)
- deleted 3y ago[deleted]
- EchoReflection 3y agothe only other options I can think of (in the USA) are USPS and a company that I haven't seen in so long that I wondered if they were still in business, DHL. DHL's website is still up and running, but I guess they aren't doing great if I never see their delivery trucks anymore. Maybe they have a stronger presence in areas away from where I live...
- hn_throwaway_99 3y agoWow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's only going to become more true with AI. Relying on those distinguishing characteristics in the first case is an absolute fatal flaw. Instead (and, in fairness, Troy Hunt did do this) you should never depend on an outbound link or phone number in a message you received. You should log in to whatever service you think sent it based on looking up the address or phone number yourself. This "hang up, look up, call back" advice should be an absolute mantra. I think responsible organizations should just start by saying they will never put links or phone numbers in text/emails/calls, and their notification messages should say something like "Log in to your dashboard to see details."
- avarun 3y agoI don't think Troy Hunt is recommending what you're suggesting at all? The very beginning of the post starts with: > but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs). It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.
- hn_throwaway_99 3y agoTwo things: 1. The entire article is about a (surprisingly) legit FedEx SMS looking totally spammy. My point is that we should take "looking totally scammy" completely out of our vocabulary, and pointing out similarities or differences in scam vs real notifications only furthers the notion that they're distinguishable in the first place. Again, to emphasize, I still think this overall was a great article highlighting the ineptitude of FedEx sending such egregiously bad notifications in the first place 2. Hunt says exactly this in the article "But if I were to take a guess, they've merely blocked the tip of the iceberg. This is why in addition to technical controls, we reply [sic] on human controls which means helping people identify the patterns of a scam: requests for money, a sense of urgency, grammar and casing that's a bit off, add [sic] looking URLs." My point is we should stop "helping people identify patterns of a scam". We should instead just teach people to treat all incoming notifications as suspect and to never follow a link/phone number from an incoming message.
- csours 3y agoThere ought to be a law, I tell you
- tonymet 3y agoThis reinforces the need for "mutual trust security" that I've been calling for now for years. All of the significant authentication schemes are built to validate the customer, and none validate the vendor. When your bank or mobile provider gives you a call : how do you know it's them? They start asking you for personal data right away, but you have no idea who you are sharing information with. We need "mutual authentication" including better identity, trust, challenge-response and more. Customers should be able to validate who they are talking to before even sharing their own credentials.
- Bjartr 3y agoThat exists, but isn't super widespread. Some places will have you choose something (image, phrase, etc.) that they will display to you when logging in. If you don't recognize the thing shown when you go to login, don't trust it.
- tonymet 3y agoYou're right but it's for web and hardly used. Phone, text and email are much bigger threats. email has some incomplete protections including DKIM and others. Phone and text only have caller-id which is easily spoofed and vendors don't even manage their contact points . we need a platform that consumers can easily understand and use.
- zokier 3y agoEV certs were intended for that. They should always contain info of the company who they were issued to. They were mostly a trainwreck, and now almost completely abandoned.
- ianburrell 3y agoFor voice calls, and maybe SMS, there could be mechanism to do bidirectional authentication with words. The problem is that would have to switch to app to generate the words and validate the response. For user, password or passkey would work. For company, the SSL cert on domain might work. Otherwise, would need to download certificates. For SMS and voice calls, it would help if they could implement call authentication so can trust the number. Phones should show the user if the number is validated. It would also be good to add trusted CallerID names; Google does with some numbers.
- d1str0 3y agoI clicked the link to read this article because last week I received a paper letter from FedEx I initially thought was scammy. It asked me to pay duty/taxes for my $799 Prusa 3D print order that arrived just last week. So now I know Troy Hunt also bought a Mk4 assemble-yourself kit from Prusa. Enjoy, Troy! Mine took 8 hours to build and it works like a charm! Fantastic little machine.
- aggieNick02 3y agoMy favorite FedEx facepalm was when they kept trying and failing to deliver a package to themselves... They have an option to have your package held at a FedEx store. It's great for when the package requires signature and you're not able to wait at home all day for it. Recently I used it. Unbeknownst to me, the FedEx store changed its physical location while the package was in transit, to a different strip mall across the highway. So for several days in a row, I was notified that FedEx attempted to deliver, but that the business was closed. Every call to customer service yielded understanding and sympathetic employees who had no idea how to fix the issue. After about 5 days, something clicked, and my package showed up at the new FedEx location.
- dawnerd 3y agoCan we add pharmacies calling and asking to verify your ssn and dob? It’s trained a lot of older people to trust whoever is calling.
- kylecordes 3y agoThe bar to relative excellence in our industry is so very low.
- 0xbadcafebee 3y agoCompare this to USPS, which is so secure that I can't get back into the account I created to manage deliveries for my home address, and there is absolutely no recourse. (no customer or technical support, going into a USPS office does nothing, etc) I still receive e-mails at my old e-mail address about deliveries coming to my home, but I can not turn them off, change the e-mail address, etc.
- lnxg33k1 3y agoCouriers are part of the reason I haven’t bought anything for years
- riggsdk 3y agoI've somewhat convinced myself that someone in the postal service is leaking information about pending parcels to scammers (or the scammers have access to some servers). Whenever I'm expecting a package the number of phishing attempts in my email skyrockets. Period of no packages - a lot less attempts. Waiting for a new package? Phishing emails ramp up again.
- flerchin 3y agoAnd Amazon emailing me about my package due to arrive today. Clicking the link is right there and very convenient to find out which one. They won't tell me which package because then gmail will be able to know what I'm buying (which I'm fine with). These emails are the _exact same form_ that a phishing email would take.
- chankstein38 3y agoFedEx is trash but this kind of handling of these kinds of communications is so common it's disgusting. I say it all of the time too. "No wonder people get scammed." We get security trainings at work or get things like "_company_ will NEVER ask for your password" then they immediately violate their own rules. It's absurd.
- me_jumper 3y agoI bought insurance online. Some days later I got a super dodgy email telling me I should sign up for an online portal. The link was a mess and linked to a different insurance provider. I called my provider. Turns out the actual insurance is handled by a sub-provider that works for a different (major) insurance... WTF
- datavirtue 3y agoI just read an article detailing how thousands of Americans fall for scams run by Mexican cartel proposing to buy their timeshare from them. Americans buying Mexican timeshares is a big thing apparently. One guy kept getting pulled into the scams eventually paying them (and losing) $1.8MM. Others had lost tens or hundreds of thousands to the same type of scam. Every time someone supposedly bought their timeshare there would be a bank fee or tax they would have to wire money for. The guy who lost $1.8MM wired money 90+ times. These are lawyers and doctors, educated people getting ripped off.
- tempestn 3y agoWas just dealing with similar nonsense from BMO Harris bank yesterday. I got this text (numbers changed): "FreeMsg: BMO Fraud Ctr: 18774352371 Case 19684358 Did you attempt $4.00 at NYTIMES with card x1234? Reply YES or NO" The 1234 did match the last 4 digits of my card - not the first four, a common trick - but the rest of the message is, as Troy says, Dodgy AF. They then followed up with a similar email, prompting me to click on a link that began like this: https://ecs01-us.ficoccs-prod.net/2088/en-US/tran_Not_Authorized https://ecs01-us.ficoccs-prod.net/2088/en-US/tran_Not_Author... That's certainly not a BMO domain. Wtf, bank? So, called them and confirmed the messages were legit, unlike that charge. And as an aside, this is far from the first time I've had a card compromised while never using it at a physical vendor, and only a handful of large online ones. Once I actually started getting fraud transactions on a card I had never used. I'm guessing access to credit card info is far too broadly available within the bank.
- malfist 3y agoThe first four are not secrets. The first two digits identify the card issuer, and the next two are the card type. That's how those credit card numbers can show you your card issuer's logo after you type the first two characters.
- lights0123 3y agoRight—they're saying it would be easy for a scammer to "prove legitimacy" by showing those first four, given that they're public.
- eiiot 3y agoI got an email from BMO the other day that I had changed my password. I immediately tried to log in (with my current password) and it worked fine. Never got any other communication from them about it, or even a fraud alert after I supposedly "changed" the password. I moved to Schwab a while ago, so I'm not sure what I would've done to change the password. Schwab is much better, by the way. BMO is a joke. I never thought I would say this, but I miss Bank of the West.
- meeech 3y agoThis is funny to see today because I had exact same experience, but with UPS. Call came in, marked as Probable Spam. Robot voice on the line, claiming to be from UPS. Duties and taxes. I am expecting a package, so I went to the website and it was legit. Though it won't change, because to do it right would cost them $$$. Whereas doing it wrong costs them less, and it then becomes a me problem.
- nerdjon 3y agoThe URL part of this particular drives me insane, and it's not particularly Fedex's fault. But When every online retailer seems determined to keep me in their website (or a branded third party website) when I click a tracking number. "Track Package" sure, keep me on the website. But if you present me with a tracking number that you are making a link yourself, just send me to the shipper company. Bonus points when they then make it really hard to find the actual link I want on that random website they send me too. I already bought from you and will soon have your product in my hands, do I really need to be kept on a branded site that offers no extra value? Emails seem to be the worst for this. I feel like these companies are setting up people to be phished, when the idea that you can only track Fedex on Fedex.com is no longer true.
- asveikau 3y agoSome of these package themed spams are amusing. I got some spam texts from a +44 number (UK) claiming to be USPS. Similarly I got a call from a +1 416 number (Toronto area) telling me they were US Customs and Border Control.
- TheDudeMan 3y ago"while we're all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!" Brilliant. Troy is the best.
- dimask 3y agoLast year we received an email with title > ACTION REQUIRED - New certificate authority for slack-edge.com Capitalised letters telling you MUST do sth (check; plus "as soon as possible" in the body). Bad/incosistent email layout (check). Unknown urls (slack-edge.com, slackhq.com) that resemble the services's standard url slack.com (check). A bunch of links obfuscated behind "slackhq" redirects, check. Even a link that reads "slack.com" and points to that slackhq redirect thing. The majority thought it was scam, of course. I only suspected it may not have been scam because a scammer would have done a better job explaining what one had to actually do (and in the end there was nothing we needed to do anyway).
- skjoldr 3y agoReading these comments makes me thankful for the existence of Nova Poshta in Ukraine. Two years of open war, and they still consistently deliver packages overnight across roughly a third of the country, and are doing their best transporting international shipments to and from Europe. Very focused on keeping things moving and avoiding losing any parcels.
- UberFly 3y agoThey must have extra motivation to excel and help the local effort in what ever way they can. Too many entities elsewhere see their duty to others, their country and company as a burden.
- Ignacio3z 3y ago[dead]
- nerdyadventurer 3y agoDoes anyone know how to block SMS from marketers without numbers (ex: XYZ instead of 123) on Android?
- mixdup 3y agoThis reminds me of the IRS phone scams. The IRS does not have an actual voice actor record their phone messages or phone tree, they just use a text-to-speech system that is commercially available So, the scammers just use the same system so the phone messages you get from them sound like the same voice you hear if you actually call the IRS For just a little extra money they could pay someone to exclusively record IRS messages and the voice would never be the same as the scammers (at least, until someone replicates the real voice with AI but that's an issue for another day)
- southernplaces7 3y agoReally though, What would you expect from a a company that managed to lose Tom Hanks for nearly 5 years? Even after that, he had to rescue himself first and they still screwed up his "welcome back" buffet meal.
- sara44444444 3y agoSpecial thanks to spyrecovery36 @ gmail com for exposing my cheating husband. Right with me I got a lot of evidences and proofs that shows that my husband is a f** boy and as well a cheater ranging from his text messages, call logs, WhatsApp messages, deleted messages and many more, All thanks to Support @: spyrecovery36 @ gmail com , if not for him I will never know what has been going on for a long time. Contact him now and thank me later. Stay safe.
- sara44444444 3y ago[flagged]