FedEx Phishing Scams: Why Even Security Experts Can't Tell
Thanks FedEx, This Is Why We Keep Getting Phished (2024)

Troy Hunt, a security expert, received a suspicious FedEx SMS about a parcel, which turned out to be legitimate. He breaks down the 'dodgy AF' signs that made it look like a phishing scam, including typos, urgency, and odd URLs. Despite the red flags, he verified the message through official channels and discovered it was real. This highlights the challenge of distinguishing scams from legitimate communications, especially when companies like FedEx imitate scammers.
Here we are in the era of burgeoning AI-driven scams that are becoming increasingly hard for humans to identify, and FedEx is like 'here, hold my beer' as they one-up the scammers at their own game and do a perfect job of being completely indistinguishable from them.
- lemursage
This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package.
I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.
I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).
The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.
- Terr_
I wonder how we could describe this so that aging non-technical executives understand.
"It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."
- jhbadger
It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!
- kencausey
In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
- walrus01
I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...
List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt