526

From 2024, but funny to read....

What makes this situation so ridiculous is that while we're all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!

top 50 comments
sorted by: hot top new old
[-] Shortstack@reddthat.com 2 points 1 day ago

This is why I deliberately keep most text histories as it adds another layer of legitimacy for any infrequent but repeat purchases. When I just bought something or have a doctor's bill and a text comes through on a history from the last time I had to pay someone, it makes all this much simpler. Legit companies stick to the same number and scammers usually don't.

[-] bold_atlas@lemmy.world 13 points 2 days ago* (last edited 2 days ago)

It really is the golden age of stalkers and scam artists. You wouldn't believe how much I know about the previous owner of my phone number. Their name, where they work, where their kids go to school, their pediatrician, their coworkers names and numbers (still included in text conversations). I started responding to the work texts when I realised they were STILL giving out the number (autofill I guess)

This needs to be made for real

[-] sanpo@sopuli.xyz 215 points 3 days ago

Yeah. Recently I was expecting a message from a bank, finally I got a call... from a chatbot claiming it has an important message for me, but first I have to give it my private info to verify myself and there's no way to validate the call is legit first.

When I complained to the bank they just told me I shouldn't worry, they made the call so it's perfectly safe and there's nothing to worry about...

[-] deliriousdreams@fedia.io 134 points 3 days ago

I would change banks over that and list that as the reason why.

[-] tb_@lemmy.world 85 points 3 days ago* (last edited 3 days ago)

My banking app has a "is calling?" button, which is pretty neat. The button is highlighted whenever I open the banking app whilst on a phone call, presumably as a subtle anti-scammer warning.

e: spelling

[-] Buckshot@programming.dev 42 points 3 days ago

My bank has the inverse as well. If i open the app while on a call there's a huge banner across the top stating they are not calling me.

[-] Natanael@infosec.pub 6 points 2 days ago

The Swedish banks has a shared identification app, and it gives a big alert every time a login is prompted asking if you called out or got called, and doesn't let some actions complete if you say you got called

[-] dirthawker0@lemmy.world 20 points 3 days ago

Damn cool. Which bank, if you don't mind me asking?

load more comments (2 replies)
[-] deliriousdreams@fedia.io 12 points 3 days ago

This is honestly a really good idea.

[-] warm@kbin.earth 67 points 3 days ago

Always call back. A legitimate bank will say that its no problem to call them back. Never give any personal details over the phone unless you made the call yourself.

[-] Serinus@lemmy.world 41 points 3 days ago

And don't trust the number they give you. Look it up yourself.

[-] Dultas@lemmy.world 7 points 2 days ago

Our Dr office does that as well. We have a call about your upcoming appointment, can you provide details to confirm it's you. They don't give appointment time, what office it is, patient name nothing. Even if you trust it legit if you or your partner or kid both have upcoming appointments you have no idea which it's for.

We just hang up and call to figure out which it was.

[-] LodeMike@lemmy.today 53 points 3 days ago

I don't get why all these big companies just cannot be serious about anything they do. They're always disorganized.

[-] frongt@lemmy.zip 31 points 3 days ago

It's because they're big companies. The bigger they get, the less they can focus on any one thing. More people means more risk of someone being unqualified, and less oversight through more layers of middle management, most of whom are also unqualified.

Your local business employs fifteen people. One owner, two managers, and 12 staff. Everyone knows everyone and if they're truly bad at their job they can't deflect and skate (unless the owner allows it).

[-] mrgoosmoos@lemmy.ca 2 points 2 days ago

been going through this where I work for the past couple years now. after a few dozen people and with a focus on growth but not the underlying support structures to allow for that, it's been a fucking disaster. it's been very difficult for me to accept that it is impossible for me to meet my previous standards because of the ridiculous workload, scheduling, and piss poor communication and interdepartmental processes.

scale that x1000+ and yep it's clear why it's a disaster at huge companies

you clearly have very different local buisness than where I am, because about half of the ones around here are half run by drug addicts.

load more comments (1 replies)
[-] Evotech@lemmy.world 3 points 2 days ago

Because everyone is just a person

[-] Buddahriffic@lemmy.world 1 points 1 day ago

Yeah, they say don't worry about imposter syndrome because many people feel that way. They don't say that most people aren't imposters out of their league, just that most people feel that way.

[-] Someone8765210932@lemmy.world 2 points 2 days ago

??? The guy you're replaying to is talking about big corporations and this post is about FedEx... you think one one person made and is responsible for this "notification system"?

The answer is: because they dont care, unless it impact their profits.

load more comments (1 replies)
[-] SpaceCowboy@lemmy.ca 74 points 3 days ago

The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn't going to make any kind of effort towards it. That's on you, not on us!

Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you're redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing... why wouldn't it just be login.microsoft.com? I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you're dumping your credentials into random looking domains, then downloading and installing software from other random domains.

They just don't really care as long as there's no legal liability. You're data gets compromised because you didn't notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that's your mistake and no one can sue microsoft for it. As long their negligence doesn't meet the legal definition of negligence, they're not going to put an any kind of effort.

Anti-phishing training could be so much better... "don't put your credentials into anything other that *.microsoft.com". But since these companies won't make any effort, anti-phishing training amounts to "Just be careful or whatever LOL!"

[-] billwashere@lemmy.world 5 points 2 days ago

I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain.

I’ve had to deal with shit like this personally so I guarantee that was at least one reason. The departments that control the domain treat it like some sort of power trip and make it hard to do the smart thing.

[-] daychilde@lemmy.world 22 points 3 days ago

You’re data

Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!

;-)

I think you're spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.

For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says "Don't click links from sources you don't trust" and doesn't teach you what to look for.

To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.

The linked article is a fantastic example of the worst legit comms I've seen. Absolutely looks scammy all the way through.

[-] Zenorbi@lemmy.world 13 points 2 days ago

And what is even better, is that microsoft-online.com isn't owned my microsoft. It is a potential phishing site. The correct one is microsoftonline.com

load more comments (3 replies)
[-] ModernRisk@lemmy.dbzer0.com 89 points 3 days ago

Is this for real? I would’ve automatically deleted and reported it as spam lol.

[-] Ludicrous0251@piefed.zip 39 points 3 days ago

You and the "87%" of people who responded to his Tweet or whatever.

[-] ModernRisk@lemmy.dbzer0.com 13 points 3 days ago

Yeah, of course. Surprised there are “13%” of people of his Tweet that would not or whatever.

[-] RickyRigatoni@piefed.zip 10 points 3 days ago

That 13% is the reason these scams are so popular.

[-] Addv4@lemmy.world 14 points 3 days ago* (last edited 3 days ago)

Yep. Accidentally imported some parts for my car (thought they were in the states, but no, China), got a random message about duty fees. I initially thought it was a scam, but got another, so I followed the link on a safe device (laptop running Linux). It gave a valid address from the shipping company with details that verified my order, so I had to pay or it wouldn't be delivered. Very annoying, should have been told earlier that I needed to pay duties/tariffs so I could plan accordingly.

load more comments (2 replies)
[-] CosmicTurtle0@lemmy.dbzer0.com 43 points 3 days ago

Capital One does something similar and it's so fucking annoying. They send text messages that read "Your transaction for some company was DECLINED! Take action now: http://someweirddomain.com/sketchy/uri"

I used URL Checker to figure out where it ultimately landed and it does go to Capital One.

I've even complained about this and they said, "Well, you should know these texts only come from us."

[-] greatwhitebuffalo41@slrpnk.net 27 points 3 days ago

Then they send the same email saying "phishing scams look like this!" And it's their exact text...

[-] MangoCats@feddit.it 17 points 3 days ago

The solution is: if it looks scammy, get on a different device altogether and use your normal login to the institution to access the issue through the normal channels instead of their "convenient link" through the sketchy service which may well be skimming your data even if they are under contract to your bank.

Unfortunately, a lot of the institutions' own interfaces suck so badly it's sorely tempting to use the quick link.

[-] daychilde@lemmy.world 12 points 3 days ago

But as this article points out - that's not always helpful when the company makes it difficult to contact them - or in this case, the Duty and Taxes [sic] aren't a part of the FedEx process but a part of the government, so to FedEx it's a third-party issue and so when they pulled up the shipment, no mention was made of it (that's my theory why that happened).

Your advice is good - I'm just saying it won't always work. heh. But it is the thing you must do unless you recognize the message source/content and even then, better to just log in separately. heh

[-] Serinus@lemmy.world 14 points 3 days ago

I hate all the sketchy domains. You have a domain I trust; use that one.

[-] sudoer777@lemmy.ml 7 points 2 days ago

There's a healthcare organization where I live that basically dominates everything, and every time they contact me it's through a new phone number and new format of call/text and they're super disorganized as well

[-] spizzat2@lemmy.zip 25 points 3 days ago* (last edited 3 days ago)

A competent government would set up best practice rules, and tools to improve systems. They could even provide some sort of system for consumers to report these issues. Then they could assign companies a cyber security score. Basically, a wall of shame for this stuff, ideally with the option for fines for non-compliance.

Unfortunately, "competent government" seems to be an oxymoron in most places.

Edit: to be clear, I provided examples of half-hearted implementations of what I'm talking about from a couple sources, but I'm making no claims about the competency of those governments.

load more comments (2 replies)
[-] sem@piefed.blahaj.zone 28 points 3 days ago

I usually post the article in the comments so it is easier to read, but Troy hunt 's website is already so easy to read its a joy!

[-] Yaky@slrpnk.net 21 points 3 days ago

With how much effort is being put into phishing awareness and training, some people/companies still put zero effort into their communication.

Duting a lengthy process that involved an attorney, I got an email from a firstnamelastname(at)yahoo(dot)com, with no introduction, no mention of my name, a misspelled address, telling me about an appointment at another address that was... screenshotted from a website and pasted as image. Looks sketchy AF by any measure. Nope, that was a real email from a paralegal.

Filed a helpdesk ticket at work. Get a Teams message from " (external)", asking me my company machine ID in bad English. Responded with "you are helpdesk, do you not know this?". After a few repeated requests for the ID and not answering any of my questions, I just stopped responding.

[-] SpaceCowboy@lemmy.ca 12 points 3 days ago

The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.

Another manager told users to just bypass the certificate errors on a new web service.

Multiple times I've had people tell me over teams to do all kinds of weird things to work around security errors.

It's a weird thing where people in IT think the security rules are for everyone else and not for them. And it's just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company's domain] and the cert is valid and if it's an internal service, use kerberos to validate the user so they don't even enter a password.

The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what's needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.

load more comments (1 replies)
[-] blattrules@lemmy.world 18 points 3 days ago

So many legitimate messages look like phishing schemes nowadays: those class-action ones are probably the worst offenders for me because it would take no effort for someone to create a scam based on that. Banks are another big one. These companies are making it really easy for the scammers to take advantage of people.

load more comments (5 replies)
[-] pHr34kY@lemmy.world 18 points 3 days ago* (last edited 3 days ago)

One cool thing that just went live in the last month or so is SMS Sender ID. You need to file a shitton of paperwork before being given the keys to send an SMS to an Australian with a name instead of a phone number.

https://www.acma.gov.au/sms-sender-id-register

I personally had to write the code to make this work for a rather large financial institution that uses AWS for bulk SMS. It was a lot of hoops to jump through. If you get one detail wrong, your SMS just has a phone number instead of a name.

At this point, it should be impossble to deceptively get "Fedex" into an SMS header.

load more comments
view more: next ›
this post was submitted on 20 Sep 2026
526 points (98.3% liked)

Technology

88199 readers
3873 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS