Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
akamai.com
akamai.com
Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
[1] https://web.archive.org/web/20000229182038/http://www.usps.g...
[0]here is just one: https://www.reddit.com/r/explainlikeimfive/comments/3piv7w/e...
Seems failing businesses is also on brand for those guys.
They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is legit and what isn't. And know that things like onmicrosoft.com is legit while atmicrosoft.com is probably not. Or whatever link shortener some legit organizations are using.
But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.
If I search for whatsapp, in the sponsored section there are 10+ apps with white speech-bubble style icons on green backgrounds that aren't WhatsApp
You could do a similar thing with banks. Require them to use a .bank TLD (or .bank.us, .bank.uk, etc.), only let actual, regulated banks register them, and give them special decorations. Use eminent domain if those domains are already taken.
Unlike EV cert validation, it would actually mean something if you restricted decorations to specific known regulated groups.
I had never considered that if there were multiple 9-digit expansions of a 5-digit zip code, the correction might turn out wrong unless the full 9-digit code is specified.
It is not required and will likely never be required to provide a 9 digit ZIP for reliable delivery. It may, and does sometimes, impact speed of delivery due to sorting/distribution rounds.
That depends on who you are.
If you are a regular person, then yes, 5 digits is sufficient. But if you are a sender of presorted commercial bulk mail (which is discounted from first class), you may actually be required to provide a 5 + 4 + 2 = 11 digit ZIP.
That little barcode the post office prints on your letters is actually just the 11 digit zip. The final two digits are the last two digits of the house number. So "123 Any Street, Anytown FL, 45678" the final two digits of the zip would be 23.
"Identify theft" should simply not be a thing at all - it's fraud against the bank and the person's whose "identity" was stolen shouldn't be involved. Combined with simple fraud chargebacks that make the bank accountable if they can't make their (fraudulent) customer accountable would reduce much of it.
The best solution to this is using your browsers built-in password manager (or your favourite browser-integrated password manager) then your randomly-generated password for ups.com won't auto-fill for myups.com and you at least have to think about it and wonder why you need to fish the password out of the password manager.
A lot of people look at scams and think "I'd never fall for that" because at face value something looks obvious and you think you can use these obvious filters. BUT in reality there's tons of fuckups like this that make the space confusing because the "red flags" just look like flags.
For example, in the scams where people fake a voice of a loved one people think they'd know. But there's bad connections and scammer makes it feel like an emergency so you'll let little weird things slip by. Or how every year or two Google changes its login page format (and currently I seem to hit two very different formats...). Or a week ago with the rabbit leak I said this was a reason not to push people to download a file[0] and people concentrated on the part of it being a zip and not that 1) you download something and 2) that zip has to be opened even if a zip alone can't do anything.
This really is one of the big dangers of enshitification. It becomes difficult to distinguish legitimate things from scams.
https://economynext.com/sri-lanka-to-study-infobip-centraliz...
Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.
Luckily they still look so lame its trivial to spot them, and gmail is doing a fine service filtering them right into spam.
Americans are lucky in they usually don’t have to buy from abroad and when they do, rarely is tax/duty payment required from the recipient (unlike many other parts of the world).
The core challenge of phishing attacks is that USPS is not, in fact, the primary victim of these attacks.
The victims are distributed citizens who fall for the scam. USPS doesn't have very many levers available to them to address the attacks (besides a warning on their site, which they have), but also doesn't 'feel' the impact so would have a hard time justifying substantial investment in addressing it.
Ultimately the solution needs to come from regulatory regimes that target fraud, particularly SMS message spam.
The problem is usually that domestic law enforcement is powerless against international crime, which gets laundered by international utilities like DNA and IP routing/peering.
USPS jumps to first place as most imitated brand in phishing attacks
This is my problem with almost every "report spam/fraud/etc" flow. It's always a digital shrug, and then nothing happens.
Only one site I know of ever had it right: Instagram, up to about 2021. When you reported an account or post, you would actually be notified when they took action, which would usually take about a week and be something like "the account was removed". It was so satisfying to see a spam account get taken down after a report. But, they removed that in favor of the "hey thanks for the report we've tossed it right in the trash lol" user flow that every other site uses. Unfortunate.
The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.
« Êtes-vous une pamplemousse? »
They're training taxpayers to put in large amounts of extremely sensitive personal information into a third-party domain called "id.me". Even if you trust the private company, I think it's insane they didn't at least whitelabel the process through a *.irs.gov domain!
(For those curious, the .me TLD is run by the country of Montenegro. Control over DNS has some security implications for phishing and man in the middle attacks.)
Equifax had its entire response to its breach on a different domain, the kind of thing we tell people to watch out for.
https://www.equifaxsecurity2017.com/
This looks like phishing. But it is legitimate.
Most have been fixed but my current pet peeve is receiving email newsletters from these companies with tracking links. I get it, you're trying to measure something. But they're genuinly sending you links like sx4pv.mjt.lu/lnk/EEEAAAA-3434-asdfasdfasdf
AT&T finally copped to enormous breach this month. In their notification to individuals (sorry, sign up for identity protection, etc), they made sure to let you know official email always comes from: att@message.att-mail.com
...an email address and subdomain that have never contacted me before on a sketchy sounding domain that doesn't match the service (hosted at https://att.com). The email links to experianidworks.com which asks for email, address, and SSN upon clicking the CTA.
But even if you follow all of these best practices there are still powerful attack vectors. A threat actor could host their phishing page on an unrelated (compromised) domain with good domain reputation, in that case you wouldn't even know about that site until the first email or SMS hits your customers. Or the threat actor could use one of the many file-hosting or website services to create their site and host it on a shared third-party domain with perfect domain reputation (e.g. amazonaws.com).
And then there's incentive: It's no the companies that suffer financial losses, it is their customers. If you were talking about their employees being phished that would be a different story. Same thing for Google Safe Browsing: Their incentive is to protect against most of the obvious phishing, without any false positives, ever. If they are slow to detect something they won't suffer any losses. If they generate a False Positive their Chrome browser might suffer significant reputational damage if a popular legitimate domain is blocked.
This is a huge issue and it seems like we've just given up on it. There used to be EV SSL certs, but they are essentially dead now. There's BIMI for email, but support is mixed, and only partly addresses the issue.
[1] https://en.wikipedia.org/wiki/Do_Androids_Dream_of_Electric_...
The idea of reaching out to someone you don't know at all and attempting to steal their money by lying and betraying their confidence is morally disgusting. The type of people who can do this hundreds or thousands of times a day are criminals of the worst and least redeemable kind, yet if caught they would likely face a smaller penalty than someone who steals a single piece of jewelry from a store.
We are slowly losing our ability to trust each other because of the prevalence of scams which adds massive transaction costs to every legitimate exchange. These costs are unseen but they make almost everything we buy slower and more expensive.