Thanks FedEx, This Is Why We Keep Getting Phished (2024)

313 points · 77 comments on HN · read original →

Points and comments are a snapshot, not live.

FedEx's legitimate SMS notifications look exactly like phishing attacks, confusing customers.

Troy Hunt documents receiving an SMS about FedEx duty/taxes that appeared identical to a scam: urgent tone, strange URL (bpoint.com.au), grammatical oddities. Despite being a security expert expecting a Prusa 3D printer shipment, 87% of Twitter respondents judged the message fake. Hunt confirmed legitimacy only after FedEx emailed his full Prusa invoice. He criticizes FedEx for imitating scammers, noting Australians lose AU$3B+ annually to scams and 336M scam texts were blocked in one ACMA report period.

He demonstrates the BPOINT payment system allows trivial URL parameter tampering to change tracking numbers and amounts.

What commenters are saying

Commenters highlight similar problems: PayPal sending genuine 'verify account' emails that phishers copied, Google using c.gle domains in storage alerts, and Microsoft's onmicrosoft.com addresses looking like phishing. Many blame ICANN's gTLD proliferation and large organizations misusing or not using their own domains. One camp argues the root cause is institutional incompetence-departments outsourcing payment processing to third-party services that look dated and insecure. Another notes that businesses using link shorteners and non-obvious domains erodes trust signals for ordinary users.