frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-getting-phished/
119•stymaar•1h ago

Comments

darth_avocado•44m ago
Do they build their own software or contract it to the consultants?
Doohickey-d•43m ago
Discussed previously, 2024, 564 comments: https://news.ycombinator.com/item?id=39479001
walrus01•40m ago
I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...

List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

cosmic_cheese•22m ago
The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.
inigyou•21m ago
This was a calculated project by ICANN to 1. bring lots more money to ICANN and 2. prevent decentralisation of the DNS root away from the control of the USA.
ddtaylor•9m ago
I'm not convinced that would help.

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

Its just attempting to work around incompetence, which always just shows up again somewhere else.

dqv•7m ago
For the past 2 years I've gotten backscatter from a phishing campaign that uses a domain I own in the from address. Every single domain they try to get the victims to click on is a .com

The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.

As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.

chuckadams•37m ago
I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.
kencausey•33m ago
In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
inigyou•22m ago
Whois has been replaced by RDAP.
b112•6m ago
There are whois servers, and the whois command, so no, it has not.

I agree that this is the goal.

mixdup•31m ago
There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either
agency•27m ago
This shit drives me insane. Last year I had my home insurer send me a link in an SMS pointing me to allstate.yem.bo to collect some information. Stop training your users to get phished!!
jhbadger•21m ago
It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!
starky•11m ago
We have a training thing at work that sends out phishing emails and you are supposed to report them using a handy button in the email app. If they are training emails you get a good job website that pops up. I greatly enjoy reporting every single genuine email that reads anything like a potential phishing email as there is someone in IT that reviews them and probably gets annoyed at the various groups sending sketchy emails for official business.
lemursage•17m ago
This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package.

I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.

I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).

The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.

eventualcomp•12m ago
If I had a nickel for every post I saw on HN front page involving companies confusing people on phishing-like patterns today, I would have two nickels. Which is not a lot but still weird that it happened twice.

https://news.ycombinator.com/item?id=49172834

antonvs•6m ago
> Why are the "D" and the "T" capitalised? Dodgy AF!

You should be more respectful, you’ve clearly received a Message direct from President Trump!

Big Tech Is Finally Paying for the AI Disaster It Created [video]

https://www.youtube.com/watch?v=XB55jZAYifQ
1•Jazgot•2m ago•0 comments

VibeMathed - Math Problems Solved by AI

https://vibemathed.com
1•frozenseven•2m ago•0 comments

DuckDB – Data power tools for your laptop, now in Clojure (2023)

https://techascent.com/blog/just-ducking-around.html
2•sourdecor•5m ago•0 comments

Luna Forge

https://github.com/RealAhmedOsama/Luna-Forge
1•handfuloflight•6m ago•0 comments

Kimi K3 Inference self hosting study

https://ramshankar07.substack.com/p/kimi-k3-tokenomics-i-spent-300-so
1•Ramshankar07•6m ago•1 comments

Tricki – a repository of mathematical know-how (2020)

https://www.tricki.org/
1•sendes•7m ago•0 comments

Open VSX extensions found harvesting developer info

https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-...
2•sbulaev•8m ago•0 comments

Tabtrail: park your unused tabs and save on memory

https://addons.mozilla.org/en-GB/firefox/addon/tabtrail/
1•batmnnn•8m ago•0 comments

I Tried to Make AI Writing Sound Human by Banning AI Words Through Logit_bias

https://www.vincentschmalbach.com/make-ai-writing-sound-human-logit-bias/
2•gmays•9m ago•0 comments

Amiga clarifies Commodore rights and the future of AmigaOS

https://amiga.com/news/20260804-amiga-update
2•odomus•11m ago•0 comments

Self-Serve E-Prescribing Integration with Photon

https://photonhealth.com/blog/introducing-photon-self-serve
1•arunchaudhuri_•12m ago•0 comments

AI fuels more than half of cybercrime in Africa as digital scams surge: INTERPOL

https://www.africanews.com/2026/08/04/ai-fuels-more-than-half-of-cybercrime-in-africa-as-digital-...
4•bookofjoe•13m ago•0 comments

AVX-512 support is reportedly returning with Intel's next-gen Nova Lake CPUs

https://www.tomshardware.com/pc-components/cpus/avx-512-support-is-reportedly-returning-with-inte...
1•kristianp•15m ago•0 comments

A Civilian Plane Crashed in New Mexico. Was the Military's Tech to Blame?

https://www.wired.com/story/a-civilian-plane-crashed-in-new-mexico-was-the-militarys-tech-to-blame/
3•embedding-shape•15m ago•1 comments

Show HN: Pleasantries

https://github.com/QAInsights/pleasantries
1•qainsights•16m ago•0 comments

As of August 3, 2026, T-Mobile's 2G GSM network will be retired

https://www.t-mobile.com/support/coverage/t-mobile-network-evolution
2•pudgywalsh•16m ago•1 comments

Show HN: Sign language translation with smart glasses

https://github.com/aadisang/hand-wave
1•aadisang•17m ago•0 comments

Pi Is Bad; Or, The Positive Effects of Friction in Automated Development

https://blog.djhaskin.com/blog/the-positive-effects-of-friction-in-automated-development-or-pi-is...
2•djha-skin•20m ago•0 comments

Why a Flock Worker Quit: 'They Lied

https://www.404media.co/why-a-flock-worker-quit-they-lied/
4•trinsic2•20m ago•0 comments

Monopoly Enshittified Amazon

https://pluralistic.net/2022/11/28/enshittification/#relentless-payola
2•chistev•22m ago•0 comments

Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20I...
11•_pdp_•22m ago•0 comments

Show HN: I gave my video editor an MCP server so Claude can edit videos for me

https://www.shorz.ai
1•DonRando•23m ago•0 comments

What You Can't Say (2004)

https://www.paulgraham.com/say.html
1•embedding-shape•24m ago•0 comments

Goodbye, Phase 3

https://medium.com/@mikekuniavsky/goodbye-phase-3-4deb794bc3e8
1•adunk•27m ago•0 comments

AI music generator Suno loses copyright infringement legal case

https://www.nme.com/news/music/ai-music-generator-suno-loses-copyright-infringement-legal-case-39...
2•CharlesW•29m ago•0 comments

Amazon Germany to Accept Wero

https://www.mobiflip.de/amazon-deutschland-wero-kommt/
2•doener•29m ago•0 comments

Russian drone chasing Ukrainian street vendor

https://www.bbc.co.uk/news/articles/cn4n03xg981o
3•zabzonk•29m ago•0 comments

Show HN: All-in-one gamedev toolkit for indie creators

https://reactorcoregames.github.io/
1•not_wowinter14•30m ago•0 comments

Finding 247 solar plant candidates in Brandenburg

https://twitter.com/__snamber/status/2084747946021535975
1•tosh•32m ago•0 comments

Federal loan support cut for degree programs that lead to low wages

https://www.latimes.com/california/story/2026-07-22/low-paying-degrees-federal-student-loan-cutof...
2•anigbrowl•37m ago•0 comments