I don't get why all these big companies just cannot be serious about anything they do. They're always disorganized.
post
The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn't going to make any kind of effort towards it. That's on you, not on us!
Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you're redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing... why wouldn't it just be login.microsoft.com? I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you're dumping your credentials into random looking domains, then downloading and installing software from other random domains.
They just don't really care as long as there's no legal liability. You're data gets compromised because you didn't notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that's your mistake and no one can sue microsoft for it. As long their negligence doesn't meet the legal definition of negligence, they're not going to put an any kind of effort.
Anti-phishing training could be so much better... "don't put your credentials into anything other that *.microsoft.com". But since these companies won't make any effort, anti-phishing training amounts to "Just be careful or whatever LOL!"
And what is even better, is that microsoft-online.com isn't owned my microsoft. It is a potential phishing site. The correct one is microsoftonline.com
You’re data
Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!
;-)
I think you're spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.
For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says "Don't click links from sources you don't trust" and doesn't teach you what to look for.
To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.
The linked article is a fantastic example of the worst legit comms I've seen. Absolutely looks scammy all the way through.
A competent government would set up best practice rules, and tools to improve systems. They could even provide some sort of system for consumers to report these issues. Then they could assign companies a cyber security score. Basically, a wall of shame for this stuff, ideally with the option for fines for non-compliance.
Unfortunately, "competent government" seems to be an oxymoron in most places.
Edit: to be clear, I provided examples of half-hearted implementations of what I'm talking about from a couple sources, but I'm making no claims about the competency of those governments.
Capital One does something similar and it's so fucking annoying. They send text messages that read "Your transaction for some company was DECLINED! Take action now: http://someweirddomain.com/sketchy/uri"
I used URL Checker to figure out where it ultimately landed and it does go to Capital One.
I've even complained about this and they said, "Well, you should know these texts only come from us."
Then they send the same email saying "phishing scams look like this!" And it's their exact text...
The solution is: if it looks scammy, get on a different device altogether and use your normal login to the institution to access the issue through the normal channels instead of their "convenient link" through the sketchy service which may well be skimming your data even if they are under contract to your bank.
Unfortunately, a lot of the institutions' own interfaces suck so badly it's sorely tempting to use the quick link.
But as this article points out - that's not always helpful when the company makes it difficult to contact them - or in this case, the Duty and Taxes [sic] aren't a part of the FedEx process but a part of the government, so to FedEx it's a third-party issue and so when they pulled up the shipment, no mention was made of it (that's my theory why that happened).
Your advice is good - I'm just saying it won't always work. heh. But it is the thing you must do unless you recognize the message source/content and even then, better to just log in separately. heh
I hate all the sketchy domains. You have a domain I trust; use that one.
Yeah. Recently I was expecting a message from a bank, finally I got a call... from a chatbot claiming it has an important message for me, but first I have to give it my private info to verify myself and there's no way to validate the call is legit first.
When I complained to the bank they just told me I shouldn't worry, they made the call so it's perfectly safe and there's nothing to worry about...
Our Dr office does that as well. We have a call about your upcoming appointment, can you provide details to confirm it's you. They don't give appointment time, what office it is, patient name nothing. Even if you trust it legit if you or your partner or kid both have upcoming appointments you have no idea which it's for.
We just hang up and call to figure out which it was.
Always call back. A legitimate bank will say that its no problem to call them back. Never give any personal details over the phone unless you made the call yourself.
I would change banks over that and list that as the reason why.
My banking app has a "is calling?" button, which is pretty neat. The button is highlighted whenever I open the banking app whilst on a phone call, presumably as a subtle anti-scammer warning.
e: spelling
So many legitimate messages look like phishing schemes nowadays: those class-action ones are probably the worst offenders for me because it would take no effort for someone to create a scam based on that. Banks are another big one. These companies are making it really easy for the scammers to take advantage of people.
With how much effort is being put into phishing awareness and training, some people/companies still put zero effort into their communication.
Duting a lengthy process that involved an attorney, I got an email from a firstnamelastname(at)yahoo(dot)com, with no introduction, no mention of my name, a misspelled address, telling me about an appointment at another address that was... screenshotted from a website and pasted as image. Looks sketchy AF by any measure. Nope, that was a real email from a paralegal.
Filed a helpdesk ticket at work. Get a Teams message from " (external)", asking me my company machine ID in bad English. Responded with "you are helpdesk, do you not know this?". After a few repeated requests for the ID and not answering any of my questions, I just stopped responding.
The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.
Another manager told users to just bypass the certificate errors on a new web service.
Multiple times I've had people tell me over teams to do all kinds of weird things to work around security errors.
It's a weird thing where people in IT think the security rules are for everyone else and not for them. And it's just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company's domain] and the cert is valid and if it's an internal service, use kerberos to validate the user so they don't even enter a password.
The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what's needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.
Yeah, there were two IT techs at one company who routinely asked for user passwords, in part because some of the software we used require setup in the user account. I'd say no, but I was on a few reply all emails where others provided their password to everyone on the email.
I forwarded those emails after the IT manager after the company email server got blacklisted by a client for our emails being used as an attack vector to phish.
Is this for real? I would’ve automatically deleted and reported it as spam lol.
Yep. Accidentally imported some parts for my car (thought they were in the states, but no, China), got a random message about duty fees. I initially thought it was a scam, but got another, so I followed the link on a safe device (laptop running Linux). It gave a valid address from the shipping company with details that verified my order, so I had to pay or it wouldn't be delivered. Very annoying, should have been told earlier that I needed to pay duties/tariffs so I could plan accordingly.
You and the "87%" of people who responded to his Tweet or whatever.
I usually post the article in the comments so it is easier to read, but Troy hunt 's website is already so easy to read its a joy!
This is definitely not the reason I do it, but it's an added advantage of always getting packages delivered to my AusPost parcel locker. They always arrive in a very consistent format and don't require clicking any links.
One cool thing that just went live in the last month or so is SMS Sender ID. You need to file a shitton of paperwork before being given the keys to send an SMS to an Australian with a name instead of a phone number.
https://www.acma.gov.au/sms-sender-id-register
I personally had to write the code to make this work for a rather large financial institution that uses AWS for bulk SMS. It was a lot of hoops to jump through. If you get one detail wrong, your SMS just has a phone number instead of a name.
At this point, it should be impossble to deceptively get "Fedex" into an SMS header.
top 50 comments