Mobile phone holders all over the UK may be seeing an increase in SMS phishing (smishing) attacks from the Royal Mail – the messages say the user owes a small fee to pay on postage or the package will be returned to sender. Cybercriminals using this tactic are preying on people who might actually be expecting something in the post (like me!) I do also have the image of the text if you would like me to send it. The worrying thing about this one is that the link it sends to is an https link, which we often get advice to only click on links with https as it indicates it’s a secure website. Cybersecurity experts commented below on this scam.
<p>The Royal Mail SMS scheme is a typical smishing (SMS phishing) campaign. The scammer pretends to be an authority figure and instils a sense of urgency in the victim to trick them into clicking a link. The link goes to a fake Royal Mail website where users are tricked into entering payment information, which is stolen by the scammers.</p> <p> </p> <p>Many victims might be fooled into thinking the link is secure because it has \"https\" in it. But just because a site is secure doesn\’t mean it isn\’t malicious. In fact, more than half of phishing sites now use HTTPS with valid certificates. Furthermore, just because a shortened link uses HTTPS doesn\’t mean the full URL will. Do not blindly trust HTTPS!</p> <p> </p> <p>More advice on phishing:</p> <ul> <li>Never click on unsolicited links or attachments.</li> <li>Instead, find the site from the supposed sender through Google and log in there.</li> <li>Always check the URL and sender\’s email address for spelling errors and subdomains. A subdomain might look like <strong>royalmail</strong>.<a href=\"https://u7061146.ct.sendgrid.net/ls/click?upn=LHDupLGQbJrIBf0glmWFG2iB21RfAhhdOzqMN3JGX38-3DEI9-_S3RA1gMvL7v1TdZrqvF2X48vY2LyH9KYdxKxBaPFp6Fl1TEEsXDQbgk-2FWPw9Ah5nwh5z3HPLIw79cePUeHvYGbACtpGEOUo9gKA7RdPV7CHYnRZ1BgjoepqPsAq5T4X7K-2Bw26wspumVv2xNKnDUQkYN56Tqm4K4VQlivpx1xLjTDM8eHF2-2F0-2BICrZqvQ5pefMge6qHHkg9TnjGGp-2BglILv-2BZ3zfK1hG8ph5esU502I8sUB1jcscZtjfSuPBomhsOEgTBCBehtf1idJwJgXjwlPim6s0RWbzZXdqjOa6U1oqg4-2F-2B-2BsNJTA1eEaL4LfsapYg-2BGOjjwLLGQQ-2FG-2BxpdH9UR3lOIrFjD4THvdLGTOgeOFAKEDwA5Uew6GhctgCOK-2B\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https://www.google.com/url?q=https://u7061146.ct.sendgrid.net/ls/click?upnLHDupLGQbJrIBf0glmWFG2iB21RfAhhdOzqMN3JGX38-3DEI9-_S3RA1gMvL7v1TdZrqvF2X48vY2LyH9KYdxKxBaPFp6Fl1TEEsXDQbgk-2FWPw9Ah5nwh5z3HPLIw79cePUeHvYGbACtpGEOUo9gKA7RdPV7CHYnRZ1BgjoepqPsAq5T4X7K-2Bw26wspumVv2xNKnDUQkYN56Tqm4K4VQlivpx1xLjTDM8eHF2-2F0-2BICrZqvQ5pefMge6qHHkg9TnjGGp-2BglILv-2BZ3zfK1hG8ph5esU502I8sUB1jcscZtjfSuPBomhsOEgTBCBehtf1idJwJgXjwlPim6s0RWbzZXdqjOa6U1oqg4-2F-2B-2BsNJTA1eEaL4LfsapYg-2BGOjjwLLGQQ-2FG-2BxpdH9UR3lOIrFjD4THvdLGTOgeOFAKEDwA5Uew6GhctgCOK-2B&source=gmail&ust=1621673411173000&usg=AFQjCNEaL-GEefohMGDEoIgjiizQCvvy3w\">scam.com</a>.</li> </ul>