HomeSecurityUS Postal Service (USPS): Phishing sites have the same traffic as...

US Postal Service (USPS): Phishing sites have the same traffic as legitimate sites

Security researchers who analyzed phishing campaigns targeting the United States Postal Service (USPS) found that traffic to fake USPS is similar to that on the legitimate site and may even be higher during the holidays.

USPS Phishing

In these phishing attacks, hackers try to steal sensitive information from people or try to trick them into making payments at fake stores or covering some fees, supposedly required to receive items that have been put on hold.

United States Postal Service (USPS): Phishing attacks

During the 2023 holiday season, researchers at Akamai Technologies observed a significant volume of DNS queries going to fake domains impersonating the USPS service.

See also: CryptoChameleon phishing: Hackers impersonate LastPass employees

The volume of traffic to illegal domains was nearly equal to the volume of traffic to legitimate domains on a normal day — and far exceeded legitimate traffic during the holidays,” the researchers noted.

Akamai began its investigation in October 2023 after an employee received a suspicious SMSthat led to a website with malicious JavaScript code. The analysts created a list of all domains that used the same JS file in the last five months and kept only those with the string USPS in their name.

As the researchers explained, the fake pages were designed with great care and attention to detail to look like exact copies of the authentic USPS website.

At some point, what looked like an exclusive store postal, which began to see significant traffic in late November, as consumers tried to buy gifts and collectibles for the holiday season.

From October 2023 to February 2024, Akamai detected some fake USPS sites, so popular that they had almost half a million queries.

See also: LabHost: Phishing service removed – Members arrested

The most popular top-level domains (TLDs) associated with fake USPS domains were:

  • .com – 4459 domains and 271,278 queries
  • .top – 3,063 domains and 274,257 queries
  • .shop – 566 domains and 58,194 queries
  • .xyz – 397 domains and 30,870 queries
  • .org – 352 domains and 16,391 queries
  • .info – 257 domains and 7,597 queries

The total queries related to all malicious websites revealed are over 1,128,146 (slightly less than the 1,181,235 queries recorded for the legitimate USPS website). However, the statistics show that traffic to malicious domains between November and December was higher compared to legitimate ones.

Akamai focused this research only on USPS, so the true scale of these phishing campaigns may be much larger, potentially involving many more brands.

United States Postal Service (USPS) Phishing sites traffic

Phishing protection

Consumers should be cautious and be skeptical of messages regarding parcel shipments. Parcel tracking should only be done through the official website.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In general, all users should always be aware of the latest phishing techniques and learn how to recognize suspicious emails or message scams

See also: Brand impersonation: The 10 brands most used in phishing attacks in 2024

Using reliable security software that provides protection against malware and viruses is also helpful. This can help detect and avoid phishing attacks.

Next, users should be careful about the apps they download and install on their devices. They should only download apps from trusted sources and avoid apps that look suspicious or don't have good reviews.

Finally, it is essential to use different passwords for different accounts . Also, two-factor authentication should be used where available, for an extra layer of security on their accounts.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS