5 ms·
>I went to the link which is on mailchimp-sso.com and entered my credentials which - crucially - did not auto-complete from 1Password. I then entered the OTP
by jasode 2y ago
>I went to the link which is on mailchimp-sso.com and entered my credentials which - crucially - did not auto-complete from 1Password. I then entered the OTP
These clever phishing schemes fool even the tech-savvy computer users like Linus Tech Tips, Matthias Wandel, and Troy Hunt. This problem should be "low hanging fruit" for A.I. to identify and help users. E.g. Apple Intelligence on iPhones to scan the emails and text messages for red flags and some something similar in desktop email clients like Mozilla Thunderbird.
Anyways, comparing the WHOIS info for legitimate vs fake:
Domain: mailchimp.com
Registered On: 2001-06-29
Registrar: MarkMonitor Inc.
Country: US
Domain: mailchimp-sso.com
Registered On: 2025-03-24
Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED
Country: AE (United Arab Emirates)
Social-engineering phishing really should be one of the "easier" problems for AI to solve.
[] https://www.whois.com/whois/mailchimp.com https://www.whois.com/whois/mailchimp.com
[] https://www.whois.com/whois/mailchimp-sso.com https://www.whois.com/whois/mailchimp-sso.com
- oefrha 2y agoLet me introduce you to Microsoft: microsoft.com, microsoft.net, office.com, office365.com, windows.com, windows.net, etc. Registrar: MarkMonitor Inc. live.com, onenote.com, msecnd.net, etc. Registrar: CSC Corporate Domains, Inc. sharepoint.com, outlookmobile.com, etc. Registrar: Nom-iq Ltd. dba COM LAUDE https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges https://learn.microsoft.com/en-us/microsoft-365/enterprise/u... Someone should make a Microsoft or phishing domain? game. (To be fair to them, their registrars are at least corporate solutions.)
- meindnoch 2y agoDon't forget these gems: microsoftedgeinsider.com, microsoftinternetsafety.net, microsoftedge.com, and many others: https://github.com/v2ray/domain-list-community/blob/master/data/microsoft https://github.com/v2ray/domain-list-community/blob/master/d...
- 0x000042 2y ago> Someone should make a Microsoft or phishing domain? game. Done: https://domaingame.damgaard.dev/ https://domaingame.damgaard.dev/ :-D
- chedabob 2y agoApple Intelligence will gladly promote an obvious phishing email to the top of your inbox: https://www.reddit.com/r/MacOS/comments/1h5jf7s/apple_intelligence_has_flagged_an_apple/ https://www.reddit.com/r/MacOS/comments/1h5jf7s/apple_intell...
- RandomBacon 2y agoClickacble for everyone who likes old.* better: https://old.reddit.com/r/MacOS/comments/1h5jf7s/apple_intelligence_has_flagged_an_apple/ https://old.reddit.com/r/MacOS/comments/1h5jf7s/apple_intell...
- jasode 2y ago>Apple Intelligence will gladly promote an obvious phishing email to the top of your inbox Sorry for not being clear. I definitely was not recommending for users to depend on Apple Intelligence. I've deliberately turned it off because it doesn't work in comparison to Apple's hype. What I was trying to convey was AI currently doesn't exist to reliably identify text & and email phishing on both iOS and desktop email but this particular fraud problem seems like low-hanging fruit for something like an improved Apple Intelligence to actually solve.