HeadlinesBriefing favicon HeadlinesBriefing.com

FedEx Phishing Scams: A Deep Dive

Hacker News •
×

The author details a recent surge in "parcel couldn't be delivered" phishing SMS messages, noting their persistence despite technical controls. These scams often employ urgency and suspicious URLs, but the author, expecting a FedEx delivery, initially questioned a message requesting payment for duty and taxes.

A poll indicated 87% of respondents found the message "dodgy AF," citing numerous red flags: typos, an unusual shipment number, urgency, inconsistent capitalization, missing currency details, and an unfamiliar payment domain (bpoint.com.au). The author's own investigation revealed the payment link's parameters could be easily manipulated, suggesting a vulnerability.

Despite receiving a follow-up, even more flawed SMS, the author eventually received an email with the actual invoice from Prusa, revealing the original SMS, while suspiciously similar to the invoice details, was indeed a phishing attempt. The article highlights the scale of scam losses, with Australians losing over AU$3B annually, and the difficulty in tracking unblocked scam messages.