
When a USPS Text is not a USPS Text
It’s an all-too familiar cycle. New types of communication channels bring new types of deception. Telemarketing brought robocall scams, the growth of email brought about phishing, and now, as more companies communicate with customers through text messages, comes… smishing.
What’s smishing? A fraudulent text message pretending to be from a reputable source – your bank, for example, or the U.S. Postal Service. Usually the message tries to get the target to reveal personal information, such as passwords or credit card numbers, or to convince the recipient to click on a link that installs malware.
During an audit of the Postal Service’s social media activity, the OIG uncovered a smishing campaign which involved a third party posing as USPS, claiming to have a link to information about a package. In our recent Management Alert, Active Smishing Campaign Masquerading as the U.S. Postal Service, OIG auditors examined the Postal Service’s response to the attack.
We reviewed Postal Service social media channels as well as USPS.com and found that at the time the Postal Service had not provided any public notification of this campaign. However, in late October the U.S. Postal Inspection Service rolled out a smishing awareness campaign on its public website.
Alerting customers to potential fraud helps protect their personal information and preserves the Postal Service’s brand, reputation, and customer loyalty.
Have you received a fraudulent Postal Service text message? What did you think when you received it?
Leave a Comment
"USPS: the scheduled delivery for the package XXXXXXX has been changed. Please confirm here: [LINK]"
I mailed a package yesterday with the self-service kiosk and paid with my debit card. I wonder if there's some kind of data leak.
Received one yesterday from a 619 area code with message USPS: the scheduled delivery for the package xxxxxxx has changed. Please click (to a link). The other was from area code 657 with the exact same message.
Did I compromise anything by just clicking on 1st link (that asked for no information) but with a screen message to 'CONTINUE' which is where I stopped.