Fintech Giant Fiserv Used Unclaimed Domain
krebsonsecurity.com
krebsonsecurity.com
I see this sort of thing ALL the time - documentation referring to completely made up domains like "newcustomer.com", and it soon makes its way into software becoming real world DNS lookups for these placeholder domains. Nobody ever goes back and changes them and there's no monitoring or awareness that it's an issue.
Please take a moment to read BCP 32 - https://tools.ietf.org/html/bcp32 if you do not know about example.com or the .invalid TLD.
https://www.nasdaq.com/market-activity/stocks/fisv
edit:
Update, 12:44 p.m. ET: The lead paragraph has been updated to reflect Fiserv’s 2020 revenues, which were nearly $15 billion.
It appears Netspend was interacting with their own customer in the context of one of it's own processes. They weren't doing so as a TPV working on behalf of the banking institution that the customer would be using Netspend to transfer money from/to.
-Example- Netspend: Thanks for signing up for Netspend. We need to verifying your real. Please go to netspend.com/validate and provide y.
If Netspend was asking or directing the customer to provide information on, or interact with the banking institutions own properties then yes, I can see how you'd be correct.
-Example- Netspend: You've indicated you use Example Bank. In order for us to link to your EB account please go to example.com/myaccount and do x, y, and z.
https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...
Hmm, stock is close to an all-time high:
They never had the domain.