RC RANDOM CHAOS

When Legit Beats Phishy: A Real FedEx Bill That Failed Every Smell Test

· via Hacker News

Original source

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

Hacker News →

Troy Hunt received an SMS demanding payment of duty and taxes on a FedEx parcel, and it tripped nearly every phishing alarm: a misspelled sender name, artificial urgency, no currency symbol, erratic capitalization, grammatical slips, and a payment link pointing to bpoint.com.au rather than any FedEx or government domain. When he polled his followers, 87% of more than 4,000 respondents flagged it as fraudulent. The twist: it was genuine. He really was importing a Prusa 3D printer from overseas, and a later email carrying his actual Prusa invoice confirmed the charge was real.

The episode exposes how legitimate systems undermine their own credibility. BPOINT, a payment service operated by Australia’s Commonwealth Bank, let Hunt rewrite the tracking number, customer name, and amount simply by editing URL query parameters — behavior indistinguishable from a phishing page. A follow-up message was worse still, containing a ‘link’ with no scheme, domain, or path, making it impossible to act on. His attempts to verify through official channels devolved into circular phone menus that dead-ended on the same number he started with.

The broader point is that when real companies and banks send communications that look identical to scams, they erode the very instincts that protect people, effectively training users to trust the untrustworthy. With Australians losing over AU$3 billion a year to scams and regulator ACMA reporting 336 million blocked scam texts — while admitting no visibility into how many slip through — the gap between authentic and fraudulent messaging has become a security liability in its own right.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.