Thanks FedEx, This Is Why We Keep Getting Phished (2024)(troyhunt.com)
308 points by stymaar 15 hours ago | 76 comments
tl;dr: Security researcher Troy Hunt received a FedEx SMS requesting duty/tax payment that had every hallmark of a phishing scam: typos, urgency, weird casing, a non-FedEx payment domain, and a URL where you could freely tamper with the tracking number, name, and amount via query parameters. After extensive verification through FedEx's actual support channels, it turned out to be legitimate. The takeaway: while we train users to spot phishing red flags, legitimate companies like FedEx are undermining that effort by sending messages indistinguishable from scams.
HN Discussion:
  • Sharing similar experiences of legitimate corporate communications being indistinguishable from phishing
  • Corporate training on phishing is undermined by companies' own communication practices
  • Proliferation of new gTLDs and messy domain practices makes phishing detection harder
  • Companies should provide clean, branded URLs with explainer landing pages instead of sketchy links
  • Proposed regulatory solutions like phone KYC would create more problems than they solve