‘Tis The Season To Be Smished

16th November 2021 | Blog ‘Tis The Season To Be Smished


FedEx Smishing Scam

The holiday shopping season means big business for retailers around the world, but it unfortunately also means big business for hackers. The reasoning is, people tend to be on the lookout for various package delivery emails, lowering their guard when potential phishing emails arrive. Hackers know this and are already on the move with their holiday scams.

Package Delivery Scam

Louis Morton, a security professional based in Fort Worth, Texas, was sent a suspected Smishing message (SMS-based Phishing Attack) by his wife, indicating that a package couldn’t be delivered and action was needed for redelivery. Morton attempted to visit the domain in the phishing link, which looked something like the following (but isn’t exactly the same for safety reasons)  9991_c_fedeex[.]com from a desktop web browser, but found it redirects the visitor to a harmless page with ads for car insurance quotes. This is a typosquatted Fedex domain.  But by loading it on a mobile device (or by mimicking one using developer tools), the browser directs them to, returns-fedex.com, shown below.

fed ex smishing

This attack followed an unusual setup by blocking non-mobile users from visiting the domain. This helps minimize inspection of the site from security researchers, potentially keeping the malicious site online longer.

After You Click The Link

Clicking “Schedule New Delivery” brings up a page that requests your name, address, phone number and date of birth. Those who click “Next Step” after providing that information are asked to add a payment card to cover the $2.20 “Redelivery Fee”. After clicking “Pay Now,” the user is prompted to verify their identity by providing their Social Security Number, driver’s license number, email address and email password. Scrolling down on the page revealed more than a half dozen working links to real fedex.com resources online, including the company’s security and privacy policies. After clicking “Verify,” the user is redirected to the real FedEx at Fedex.com.

Don’t Fall Victim

A hacker’s main weapon of choice is social engineering. Once you’re aware of this, you can confidently watch out for Phishing/Smishing Attacks, Impersonation Attacks, Romance Scams, and other various attacks all based upon social engineering. Being aware of specific holiday-based scams like this shipping delivery scam is essential to keeping you and your family secure.

Other Cybersecurity Best Practices 

There are other actions you should take to protect your business from attacks including:

To learn more about Smishing, watch this short video:

To learn more about the Package Delivery Scams, watch this short video:

https://www.youtube.com/watch?v=ZOZGQeG8avQhttps://www.youtube.com/watch?v=aEB4tQBTe6I

Sources:

KrebsOnSecurity – ‘Tis the Season for Wayward Package Phish

Additional Readings:

Smishing, The New Phishing

UK Census Phishing Attack

PayPal Smishing Attack

Find out how CyberHoot can secure your business.


Schedule a demo

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

CyberHoot Newsletter – June 2025

CyberHoot Newsletter – June 2025

CyberHoot June Newsletter: Stay Informed, Stay Secure Welcome to the June edition of CyberHoot’s newsletter,...

Read more
Make Phishing Training Count with HootPhish

Make Phishing Training Count with HootPhish

Stop tricking employees. Start training them. Take Control of Your Security Awareness Training with a Platform...

Read more
Apple Alert: Critical AirPlay Vulnerabilities Expose Millions to Cyber Threats

Apple Alert: Critical AirPlay Vulnerabilities Expose Millions to Cyber Threats

A recent discovery by cybersecurity firm Oligo Security has unveiled a series of critical vulnerabilities in...

Read more