Thanks FedEx, This Is Why We Keep Getting Phished (2024)

Even real delivery texts now look so sketchy the internet yelled ‘scam’

TLDR: A real FedEx payment text looked so suspicious that nearly nine in ten people thought it was a scam, showing how badly official messages now mimic phishing. In the comments, readers blamed confusing links, sloppy company messages, and a web full of sketchy-looking addresses for training everyone to distrust everything.

The internet has officially reached peak trust issues: security expert Troy Hunt got a FedEx text asking him to pay duty fees on a real package he was actually expecting... and 87% of more than 4,000 voters still called it “dodgy AF.” Honestly? The comments were not shocked. They were exhausted. The mood was basically: this is why phishing keeps winning — because legit companies keep sending messages that look exactly like scams.

That’s where the community drama really kicked in. One camp was furious at the companies behind this mess, with one commenter sniping, “Do they build their own software or contract it to the consultants?” — a line with enough eye-roll energy to power a small city. Another big hot take: the modern web itself is a chaos machine. Commenters groaned that weird web addresses and endless new domain endings make it nearly impossible for normal people to know what’s real anymore. As one person put it, there are “so damn many of them.”

And then came the most depressing part: this isn’t even new. Users remembered PayPal sending totally real emails that looked exactly like phishing bait, and one person said even a genuine Google warning from the shortened c.gle address looked suspicious enough to send them down a rabbit hole. The running joke underneath all of it? Maybe the phishers didn’t lower the bar — maybe big brands did.

Key Points

  • Troy Hunt received an SMS requesting duty and tax payment for a FedEx shipment that closely resembled common parcel phishing messages.
  • A poll tied to the message received over 4,000 responses, with 87% of respondents judging the SMS suspicious.
  • Hunt identified multiple suspicious traits in the message, including branding inconsistencies, urgent wording, grammar issues, missing currency notation, and a BPOINT link instead of a FedEx domain.
  • He attempted to verify the request through official FedEx shipping information from his Prusa order but could not find a clear way on FedEx’s site to confirm the duty or tax demand.
  • Hunt found that the linked BPOINT payment page allowed tracking number, customer name, and amount to be changed through URL parameter tampering, which he says resembled reflected XSS-style behavior.

Hottest takes

"Do they build their own software or contract it to the consultants?" — darth_avocado
"There’s so damn many of them" — walrus01
"The phishers didn’t make it up, they were just copying actual emails PayPal sent" — chuckadams
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.