Url looks suss. Seems kinda sophisticated for the usual ups fishing scam. Here's the text message I got leading here.

"Wishing you a bright and sunny day!" Lol, I almost want to help this guy by explaining that UPS and American companies in general have disdain for their customers and would never wish them to have anything that would not benefit the company.

top 50 comments

sorted by: hot top controversial new old
[–] 299 points 2 years ago* (9 children)

I seriously doubt USPS bought a domain like gflrml dot cyou for their business. It's 300% a scam.

  • source
  • hideshow 9 child comments
  • [–] 107 points 2 years ago (3 children)

    Reminds me of my previous bank.

    They changed some system countrywide, so I got an email that I need to update some data and go to a website to do that.

    If was something like "update-[bankname]-data-now.tld".

    It was sent to a unique mail address I used for them. But still though it was phishing.

    Turns out: No. It was real. Whoever came up with the idea to not host that stuff on at least a subdomain of the bank really needs to get fired. and each and every manager who was part of the decision process.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 45 points 2 years ago

    Ugh. I work in the public sector and let me tell you, there are SO many companies that send the most dogiest, scammiest looking emails telling you to follow a link, only for it to turn out to be perfectly legitimate.

    I honestly can see now why people end up falling for these things when even legitimate companies send emails looking just like phishing scammers

  • source
  • parent
  • [–] 31 points 2 years ago* (last edited 2 years ago) (1 child)

    Had that happen, too. We all try to educate users to NOT click on some dubious phishing/scams and put in qute some effort to explain it over and over again, and then there are companies doing things like that. It's just sad.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 31 points 2 years ago (2 children)

    The text message is the big red flag, that's obviously a scam and has been happening for at least a year. Most scam texts are filtered on my phone, but a few of these slip thru.

    I guess they're just trying to tie phone numbers to addresses so they can sell the phone list for more info.

    Especially with people keeping their cell number while moving states, tying an address to the number and verifying it's that person would be a tidy profit.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 99 points 2 years ago (7 children)

    flip the question around: Why would you think this wasn’t a scam?

  • source
  • hideshow 7 child comments
  • [–] 80 points 2 years ago (5 children)

    Furthermore, wtf did they GO TO THE URL FROM A TEXT MESSAGE at all?! 🤦🏽‍♂️

    FFS, people. There's "I need help with my computer" and then there's "Some of us shouldn't have a smartphone". 🫶🏼

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (2 replies)
  • load more comments (1 reply)
    [–] 89 points 2 years ago (11 children)

    Very well known scam. Some details that give it away:

    (1) They used a url shortener that doesn't let you see the actual domain. (bit.ly)

    (2) Website domain is not legitimate.

    USPS's website is usps.com. If the URL doesn't end in usps.com (meaning usps.fakewebsite.com is still fake) then it's not legitimate.

    (3) Tone: The USPS doesn't text you like you're their friend.

    (4) The number they're texting you from is not an SMS short code number (usually 5 digits). Instead you're getting a text from a 10 digit number with an area code, which means it's a person/individual rather than an application or service.

    source: used to work as cyber sec analyst

  • source
  • hideshow 11 child comments
  • [–] 31 points 2 years ago* (7 children)

    (5) grammatical error(s): "We will ship again in" instead of "we will ship again on"

    Edit: more subtle errors and phrasing that feels like it was written by a non-native English speaker.

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (6 replies)
  • load more comments (3 replies)
    [–] 64 points 2 years ago (11 children)

    A tangent:

    What annoys me is when legitimate companies use non-standard URLs in their hyperlinked emails. For example, if you get a message from Facebook taking you to facebookemail.com, that's actually a domain controlled by the real Facebook.

    They're essentially teaching their customers to click on links in emails which use unfamiliar URLs which are superficially similar to the usual one.

  • source
  • hideshow 11 child comments
  • load more comments (11 replies)
    [–] 59 points 2 years ago* (last edited 2 years ago) (5 children)

    Why the fuck did you click a link like that in the first place? That first message is basically screaming at you that it's a phishing attempt.

    Best opsec is to delete and block, ideally without opening it at all to avoid read receipts (if that's a function in your phone). If you think it might be legit, go to the website on your own and find a way to confirm independently. If that's still too much to follow through with, at the very least don't click random links sent to you unprompted.

  • source
  • hideshow 5 child comments
  • [–] 15 points 2 years ago

    Hey dude, you had an opportunity to educate someone and instead you belittled them. As someone who works in cyber, please don't do that. People get stigmatised against cyber and IT professionals and they stop trusting us. Users don't know what we do, so be kind to them the way you should be kind to anyone learning new things. https://xkcd.com/1053/

  • source
  • parent
  • load more comments (4 replies)
    [–] 51 points 2 years ago (5 children)

    I got one of these today too.

    Something tells me the USPS wouldn't be using bit.ly.

  • source
  • hideshow 5 child comments
  • load more comments (1 reply)
    [–] 46 points 2 years ago (2 children)

    I think there's now a generation gap between kids today and people who were routinely sent to tubgirl and goatse during the internet's formal years.

    If your URL is fucky, it's a scam. If you clicked one, they'll send you more.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)

    You clicked a random link from an sms message?

    That’s a bold move, Cotton.

  • source
  • [–] 42 points 2 years ago

    Bruh, just look at the address bar. That is not a USPS domain. Obviously it's a scam.

  • source
  • [–] 36 points 2 years ago (1 child)
    1. 3rd party URL shortener, immediate red flag
    2. Non-USPS.com domain once you tapped it (which you shouldn't have)
    3. National service sending from a South Carolina area code instead of a short code or a toll free number
    4. Does USPS even have your phone number tied to your delivery address?
  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 34 points 2 years ago

    Look at the URL. Of course it's a scam.

  • source
  • [–] 34 points 2 years ago (1 child)

    PSA you can check a bitly link without clicking it by using their link checker: https://support.bitly.com/hc/en-us/p/link-checker

  • source
  • hideshow 1 child comment
  • [–] 29 points 2 years ago (1 child)

    Go to the official UPS website (do not click that link, google it) and enter your tracking number.
    If you don't have a tracking number it means you didn't order anything, and it's certainly a scam.

  • source
  • hideshow 1 child comment
  • [–] 28 points 2 years ago*

    Report this at https://reportfraud.ftc.gov/.

    Also, because they’re using Bitly for URL obfuscation report it to them at https://bitly.com/pages/trust/report-abuse.

    For any of the fake domains you run into report it to both the registrar of the domain as well as the owner of the actual IP address it points to.

  • source
  • [–] 27 points 2 years ago

    Aside from all of the red flags already listed in other comments....are you even expecting a package to be delivered? I almost never receive a package that I don't expect

  • source
  • [–] 27 points 2 years ago (1 child)

    This is 10000% a scam. That's not the USPS url scheme. Plus, as a government entity, they'll start correspondence through certified mail. Another question you could ask yourself is "Did I order any packages lately?" IF not, then more proof it's a scam.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 26 points 2 years ago

    One thing to note, aside from all the other inconsistencies, that tracking number does not follow the standard tracking number format for a USPS package. The USPS website describes their different tracking numbers for their different services in the FAQ at the bottom of their tracking page. https://tools.usps.com/go/TrackConfirmAction_input

  • source
  • [–] 25 points 2 years ago

    Yes.

    100% scam

  • source
  • [–] 23 points 2 years ago

    An official company is not going to use an URL shortener.

    That's only used when you try to hide the URL, or if you think the user is going to type it out manually.

  • source
  • [+] 23 points 2 years ago* (last edited 11 months ago) (2 children)
    load more comments (2 replies)
    [–] 22 points 2 years ago

    I get these scam texts all the time. It's 100% a scam, and now that you've clicked it, you'll probably get a bunch more scam in the near future, so be extra cautious.

  • source
  • [–] 21 points 2 years ago (2 children)

    USPS tracking numbers are never "US000000" they are only digits.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 17 points 2 years ago (4 children)

    They give you the package info. Just ignore their email and input that into the USPS address manually. Kind of like the FedEx and UPS scams. You don't have to use their link to "check the status" of something. Go to the real site, enter number, see fake, ignore!

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 16 points 2 years ago*

    Make your life easier: NEVER click on any link in an email.
    In this case, if you are actually waiting for a USPS package, go to usps.com, enter your package number manually, and see if it tracks.

  • source
  • [–] 16 points 2 years ago

    It is a scam.

    I've recieved similar texts from Amaz0n.

    Not kidding about the 0 instead of an o.

    The also use the 'Wishing you a bright and sunny day!' line.

    ...

    The url is bullshit, and nobody, literally no legit mail or pacel service is going to use bit.ly.

  • source
  • [–] 15 points 2 years ago

    UPS and American companies in general

    But this is USPS, which isn't an American company, it's a US independent agency.

    Their mandate isn't (AFAIK...) to make a profit, but rather to serve the mail requirements of a very large country.

    Personally, my experiences with USPS have been generally positive, from passports for infants to free change-of-address forwarding service to tracking down quasi-scam products from Amazon. YMMV though.

  • source
  • [–] 14 points 2 years ago (2 children)

    Kinda sad to see some of the comments being assholes about OP clicking a link. Like, how do y'all think phishing works? People click. Get over it and just educate people on why not to. Explain the risks and how to spot the scam. Do any of you think this person would have clicked if they knew for sure? Or if they knew the issues that can occur? It's super easy to sit in the comments and act holier than cos you knew and they didn't.

    Yeah it's a scam. Most people get these quite often. Your Telecom company probably blocks these quite often. Someone else went through all the details of the scam like the fake domain, where to report etc.

    Some of these links allow people to track who clicks. If you click once, they can provide data that you did and they can target you using other numbers and other scams. Might not be the case with this one, but they can also get your device details from accessing the site, using google analytics, ip data, geolocation stuff, etc. Or they ask you to allow notifications but the notifications are also scams.

    General rule of thumb is don't click when you don't trust the source. If youre sceptical, just walk away for a bit. Cops, the government and postmen know where you live, and they won't miss you. It is always okay to trust your gut, be it in a call, messaging platform or on the Web.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 14 points 2 years ago (1 child)

    100% yeah. The browser URL doesn't have ups in it.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 14 points 2 years ago
    [–] 13 points 2 years ago

    Look at the domain name in the url. Not legit

  • source
  • [–] 10 points 2 years ago (3 children)

    In addition to everything else: for weeks our building has been receiving packages addressed only with a name, a number, S, and the zip. The name is someone who has never lived here and may not exist. There's no apartment number. Our street doesn't start with S, if anything the S is for South. It's obviously some kind of fraud, because what's in the packages are little metal clips to clamp the starting tape holding stuff on a pallet. Not anything for residential use. They ship from various Amazon warehouses but through USPS. We can't get the mailman or Amazon people to return them and the Amazon return process only works if the unwanted package is addressed to you, not some random name.

    But I'm now sure as hell that USPS isn't going to let anything as trivial as an unclear address stop them from delivering the package SOMEWHERE. Anything to call it "delivered."

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    load more comments
    view more: next ›