Security researchers who analyzed phishing campaigns targeting the United States Postal Service (USPS) found that traffic to fake USPS is similar to that on the legitimate site and may even be higher during the holidays.

In these phishing attacks, hackers try to steal sensitive information from people or try to trick them into making payments at fake stores or covering some fees, supposedly required to receive items that have been put on hold.
United States Postal Service (USPS): Phishing attacks
During the 2023 holiday season, researchers at Akamai Technologies observed a significant volume of DNS queries going to fake domains impersonating the USPS service.
See also: CryptoChameleon phishing: Hackers impersonate LastPass employees
“The volume of traffic to illegal domains was nearly equal to the volume of traffic to legitimate domains on a normal day — and far exceeded legitimate traffic during the holidays,” the researchers noted.
Akamai began its investigation in October 2023 after an employee received a suspicious SMSthat led to a website with malicious JavaScript code. The analysts created a list of all domains that used the same JS file in the last five months and kept only those with the string USPS in their name.
As the researchers explained, the fake pages were designed with great care and attention to detail to look like exact copies of the authentic USPS website.
At some point, what looked like an exclusive store postal, which began to see significant traffic in late November, as consumers tried to buy gifts and collectibles for the holiday season.
From October 2023 to February 2024, Akamai detected some fake USPS sites, so popular that they had almost half a million queries.
See also: LabHost: Phishing service removed – Members arrested
The most popular top-level domains (TLDs) associated with fake USPS domains were:
- .com – 4459 domains and 271,278 queries
- .top – 3,063 domains and 274,257 queries
- .shop – 566 domains and 58,194 queries
- .xyz – 397 domains and 30,870 queries
- .org – 352 domains and 16,391 queries
- .info – 257 domains and 7,597 queries
The total queries related to all malicious websites revealed are over 1,128,146 (slightly less than the 1,181,235 queries recorded for the legitimate USPS website). However, the statistics show that traffic to malicious domains between November and December was higher compared to legitimate ones.
Akamai focused this research only on USPS, so the true scale of these phishing campaigns may be much larger, potentially involving many more brands.

Phishing protection
Consumers should be cautious and be skeptical of messages regarding parcel shipments. Parcel tracking should only be done through the official website.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In general, all users should always be aware of the latest phishing techniques and learn how to recognize suspicious emails or message scams
See also: Brand impersonation: The 10 brands most used in phishing attacks in 2024
Using reliable security software that provides protection against malware and viruses is also helpful. This can help detect and avoid phishing attacks.
Next, users should be careful about the apps they download and install on their devices. They should only download apps from trusted sources and avoid apps that look suspicious or don't have good reviews.
Finally, it is essential to use different passwords for different accounts . Also, two-factor authentication should be used where available, for an extra layer of security on their accounts.
Source: www.bleepingcomputer.com
