Scams & Phishing News US Post Office phishing sites get as much traffic as the real one

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,658
During the 2023 holiday season, Akamai Technologies observed a significant volume of DNS queries going to "combosquatting" domains that impersonate the USPS service.

Akamai started investigating USPS-themed phishing in October 2023 after an employee received a suspicious SMS that redirected to a site containing malicious JavaScript code.

Next, the analysts compiled a list of all domains using the same JS file from the past five months and kept only those with the USPS string in their name.

The design of these pages is very convincing and appear as exact replicas of the authentic USPS site with realistic tracking pages for status updates.

In one case, the phishing actors set up what looks like a dedicated postage items shop, which started getting significant traffic in late November, as consumers sought to buy gifts and collectibles for the holiday season.

From October 2023 to February 2024, the most popular malicious domains that Akamai discovered received nearly half a million queries, with two surpassing 150k each.
Consumers should exercise caution and be skeptic about any SMS or email messages about package shipments.

To verify the legitimacy of such communications, it's advisable to use the official website (by manually loading it in the browser) to check the delivery status of a product.

Clicking on the links included in messages for tracking parcels may lead to malicious locations.
 

SpiderWeb

Level 10
Verified
Well-known
Aug 21, 2020
477
Sadly perfect traps for older people who are not tech savvy. Even for tech savvy people they are tempting emails and text messages. I get one, once in a blue moon and if it wasn't for the funny looking URL I might have fallen for some. There is nothing worse than waiting for a package and then getting a message that it was not delivered. You feel like you have to instantly investigate.
 

TairikuOkami

Level 36
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,523
Sadly perfect traps for older people who are not tech savvy.
Sadly so. I work at the post office and an elderly lady asked me, if it is legit. I said it is a scam. She kept asking, is it legit? I kept saying no, ignore it.
She said, I better go ask at the post office. I said, it is Saturday, it is closed. She said, I better go ask anyway and she went to the closed post office.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top