Not it’s not. billing-jan-2020.info looks suspicious as hell. Recognizing domain names from url is very 101 Internet security.
Not it’s not. billing-jan-2020.info looks suspicious as hell. Recognizing domain names from url is very 101 Internet security.
Here's some examples I've collected of people clicking on links in suspicious texts:
https://twitter.com/edent/status/1193147685370552322 https://twitter.com/edent/status/780317797855395841
I could see this weird domain name being slightly confusing and looking like a full URL in a browser that normally hides the path part.
It would be much easier if browsers just cut the crap and displayed the full URL (including the protocol) consistently. It's just one thing everyone can learn and then apply across all platforms & browsers.
There is nothing being exploited here like a display bug in the URL bar, TLS vulnerability, etc - it is completely obvious that you are not connecting to EE.co.uk and instead to some weird domain.
There's only so much we can do to fix stupid and natural selection (or in this case financial selection) can take care of the rest. Banks refunding every instance of fraud (even when the user is obviously at fault and failed for an obvious scam) don't help either as it means people still don't understand the importance of being vigilant and actually taking the time to learn some basics in order not to fall for these very obvious scams.
I would guess that if this scam was performed over snail mail it would have vastly higher success rates than SMS spam.
Granted, domains are "backwards", and browsers could be made to match known banking sites against every URL to warn of scams. But at the point where people are clicking scammy bit.ly links too, the domain part doesn't seem to be so key anymore.
In HTML (emails) you can make the url look like the real thing onscreen. Should GMail alert when anchor text is a different link than it actually links to? (Maybe it already does?)