Today I received this text message:

  • Opening the URL from a desktop computer redirects to the real NZ Post website.
  • Opening the URL from mobile shows a convincing spoofed NZ Post tracking page:

The objective of the scam is to get you to click on “Schedule a Redelivery” and give them your personal details:

They will use this information to contact you and attempt to scam money from you, as well as try any future scams they may come up with.

The combination of URL + believable phishing page makes this scam particularly easy to fall for. If you’re from NZ, then it’s a good idea to warn your friends and family about it.

I will report the domain but it usually takes a very long time for anything to be done in these cases.

  • entropicshart@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    I mean the .xyz is a red flag and added with the fact that you should never open links sent to you, makes this pretty unbelievable imo

    • delendum@lemdit.comOPM
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      To you and I, yes, but to the elderly and gullible this will look fairly convincing.

    • Nahvi@lemdit.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      This was exactly my first thought.

      Though I would also wonder how a post office got my phone number without my name or a full street address.