SMS phishers harvested phone numbers, shipment data from UPS tracking tool
krebsonsecurity.com
krebsonsecurity.com
Google is the domain registrar. (reported)
Hotlinked to ups.com images, logos and css... Opportunity for some fun here UPS! (reported)
Uses hCaptcha on the landing page. (reported)
Nginx server with Plesk, and a plesk login page, no obvious stuff like ssh exposed, all latest versions, I'm not much of sec hacker so I didn't get very far. Started sending malformed and large requests to the credit card processing endpoint to see if I could break it, slowed it down a little, but then the captcha got blocked.
Of all of those hCaptcha was the first to respond and act, they've already banned the site's account within 5mins of my email... and this renders the site useless, so here's for hCaptcha! fighting fraud while the behemoths are slow and complicit... I know it's whackamole but it was a little bit of fun.
I have been able to send scammers 500MB+ POST requests just by making the password field password=888888888888888888888888888888 (etc til its 100s of MB of data).
Use a tool like OWASP ZAP or Burp Suite and you can easily slam a scammers website full of 500mb+ requests that will quickly fill up their log files and cheap VPS harddrive and eventually the website will get an hdd full msg or just go offline til they fix it.
Cheap and easy way to take their website offline to prevent more people from getting scammed.
So, crafting API calls to intentionally bring down a system most definitely can be a criminal offence.
Now if you're objection was to the use of felony as opposed to misdemeanor, then ignore whatever I said above.
The DoJ is unlikely to prosecute a vigilante of scammers, but they have prosecuted others (eg. Aaron Swartz) who were doing a debatably morally upright actions while violating the letter of the law.
What exactly would the scammer/hacker say to the police/their lawyer? "Could you please help? I'm trying to scam innocent people out of their money, but some greyhat has filled up my server's logs with junk!"
I wonder if this is the reason Google is getting rid of it's domain registration service? I imagine this is quite a pain to deal with
Unfortunately I’ve also observed a lot of Canadian phishing links will geo-redirect, so reporting them can sometimes go nowhere unless the checker uses the right vpn.
https://letsencrypt.org/2015/10/29/phishing-and-malware.html
“We shouldn’t be the police, let some layer above or below us be the police, just anyone but us!”
What they don’t really say is that an abuse team costs money to run.
When self-regulation doesn’t work, you risk ending up with legally-imposed regulation. I’m sure that will really delight them.
I would encourage anyone who sues large companies for a living to consider putting together a class action suit. I have received dozens of these high quality phishing attacks ever since that original Apple purchase. Doubtless many people have fallen for the attack and provided banking information to the attacker since that time.
I put in my address but did not verify that I lived here in any way.
When I loaded my account settings in the “delivery instructions” it said “garage code 12345”. So that’s how I learned the garage code to my own building.
These delivery companies are shockingly loose with customer data, not surprised by this story.
The thing I couldn’t stop ignoring is that it was perfectly timed the day before I was expecting a UPS delivery. It could have been coincidental but I doubt it.
Their domain name is sketchy AF though.
Quite probably the first mass phishing scam I’ve fallen for in nearly 20 years. Kinda horrifying to think how many non-tech people have gotten caught up by this.
"Fake Login Page" site generating scripts are pretty close to slightly customized versions of "Save Page As..." (plus some find/replace logic to fix domains, JavaScript, etc). They have been around for at least 2 decades. The big logistics companies (USPS, UPS, FedEx, DHL) almost certainly all have FLP generator scripts that are optimized for each one of them by now.
I worked at a social media company and our developers were constantly watching the FLPs that targeted our users. We both built countermeasures so they stopped working and helped mitigate the damage to accounts that we knew were scammed by the FLP sites.
Now I'm more interested to know how this data leaked ...
Seriously, their security team must be nonexistant.
Kinda like I remember a bit Canadian telecom talking big about their big “fraud squad”, but that’s primarily protecting fraud against the company, not its customers.
The reference number for a shipment can be literally any number the shipper chooses. So if they use a sequential number such as an invoice number or order number, it would be relatively easy for scammers to deduce what the reference number might be for a particular company (such as Lego).
Just to add a bit of fuel to this theory, if you go to the “Track by Reference Number” section on UPS Canada’s website today it has a message at the top stating:
Upcoming Changes: Limiting the display of reference number tracking details for improved security.
UPS is changing how the reference number tracking results are displayed to provide additional protection:
Tracking details will be mostly masked with only basic reference number tracking details available.
Senders that have saved the shipment’s account number as a payment method in their profile, or in their company profile, will see the full tracking details.
The domain is/was uspexlocrts.info and at the time, a whois lookup showed that it had been registered just a few hours before I received the SMS on my phone. There was a subsequent modification about a month later.
The whois information is largely redacted, with only the state/province and country field showing up as Beijing, CN.
I ended up submitting all the information via the (authentic) usps customer inquiry interface and basically asked them to deal with it however they saw fit.
A few days later, when I tried visiting the page again, I noticed that the site had been added to Chrome as a potential phishing site (attempting to visit the site first shows the all-red Chrome warning page instead).
Finally, on the 15th of March, I received a response from the USPS:
-- Dear <Customer>,
Thank you for contacting the USPS® Internet Customer Care Center.
"Smishing", a form of phishing, is an unsolicited SMS (text) message. Victims will typically receive a deceptive text message that is intended to lure the recipient into providing their personal or financial information. These scams often attempt to impersonate a government agency, bank, or other company to lend legitimacy to their claims. Common lures include “your account has been suspended,” “there is suspicious activity on your account”, "there is a problem with your shipping address" and “there is a package waiting for you at the Post Office.” To report USPS-related smishing: Please visit the United States Postal Inspection Service ® smishing page at https://www.uspis.gov/news/scam-article/smishing/ for additional information and reporting steps.
If you have any additional questions or concerns, please contact us again.
Thank you for emailing your Postal Service™,
USPS Internet Customer Care Center
I'm sure with enough time & patience you could enumerate the hell out of them or use data from previous leaks to get your hands on the good stuff. It's all about rate limiting, but that can also be defeated pretty easily.
https://www.trackingmore.com/tracking-status-detail-en-238.h...
Talk about burying the lead! This is a deliberate and downright sleazy attempt to downplay the breach.
whaling
smishing
pharming
vishing
spear phishing
clone phishing
snowshoeing
Every year we get new ones, and I'm convinced it's so that companies can sell a new phishing training to corporations every year.
https://www.theregister.com/2022/03/30/ubiquiti_brian_krebs/
I've personally had them grossly misrepresent a technical writeup I'd posted online, and then completely ignore attempts to correct them.[1] I've heard similar accounts from other people who work in information security.
I don't even read their articles anymore. They're the IT equivalent of the National Enquirer, if you ask me.
[1] I'd written up a discovery about how (back in the early 2010s) Motorola phones sent and received sensitive data insecurely, including data related to any configured Exchange ActiveSync account. The Register claimed (in the headline as well as the article!) that the issue was related to Exchange, i.e. that Microsoft was partly responsible, when the issue was entirely limited to communication between the phones and Motorola's internet-facing APIs. Literally every other publication got it right, but The Register, a supposed tech news site, took it as a chance to dunk on Microsoft and wouldn't correct their claims.
Krebs doesn't always get it right, but he tries. Trust-but-verify.