Thanks FedEx, this is why we keep getting phished

FedEx customs-payment texts that look indistinguishable from phishing are prompting broader criticism of how corporations, banks, and even governments communicate online. Commenters describe real notices arriving from random domains, link shorteners, or SMS numbers that mimic scam patterns, undermining user training to “never click suspicious links” and making fraud harder to spot. Many argue for clearer standards, mutual authentication, and regulatory pressure so that legitimate institutions stop training customers to trust obviously unsafe channels.

Legal responsibility and “reasonable” notifications

  • Several argue for laws shifting liability: if an electronic notice looks so phishy a “reasonable person” doubts it, consequences of ignoring it should fall on the sender, not the recipient.
  • Others note that “reasonableness” standards are legally messy and heavily litigated, but still often better than rigid rules.
  • In the FedEx case, ignoring the message mainly hurts the customer (no package) and the tax authority (no revenue), which reduces pressure on FedEx to improve.

Courier practices, customs, and fees

  • Many report confusing or contradictory customs‑fee flows (FedEx, UPS, DHL), including late bills, surprise brokerage/processing fees much larger than the tax, and unclear who ultimately paid the duties.
  • Some countries allow or require recipients to self‑declare with customs (e.g., Finland, Portugal, Canada with effort), saving fees but often hidden or discouraged by carriers.
  • Complaints that couriers resist letting senders prepay duties, leading to awkward “pay before you get your gift” experiences.

Corporate communications that look like scams

  • Numerous examples across banks, insurers, healthcare, governments, and platforms:
    • Emails/SMS from odd or third‑party domains, with urgency, bad copy, link shorteners, or illegible tracking URLs.
    • Banks and agencies sending terms on USB sticks or CDs, or via shady‑looking sites, justified by “durable medium” regulations.
    • Official sites like householdresponse.com or tax portals on .com/.org domains that visually resemble phishing.
  • Concept of “scamicry”: legitimate organizations imitating scam patterns (urgent tone, off‑brand domains, unexpected links).

Phishing training and internal contradictions

  • Companies run phishing tests while simultaneously sending real internal messages that are indistinguishable from phish, undermining their own training.
  • Some users intentionally report every sketchy‑looking but real email to force feedback loops; others ignore mandated “security training” hosted on dubious third‑party domains.
  • Frustration that reporting obvious design problems to IT often yields no change.

Telecom, SMS, and package scams

  • Many see spikes in courier‑themed SMS scams when expecting packages, leading to suspicions of data leakage, though others note blanket spam plus constant online buying explains much of it.
  • Some countries are rolling out SMS sender registration/verification; enforcement quality varies.
  • Calls for cryptographic authentication of SMS and caller ID, with strong identity vetting and penalties for abuse.

Security policies, passwords, and mutual auth

  • Long subthread on bad password policies: forced rotation, blocked reuse, arbitrary character limits, inconsistent handling of “special” characters, and how these drive weaker patterns and workarounds.
  • NIST guidance against routine password rotation is cited; many organizations still ignore it, often due to auditors or legacy thinking.
  • Desire for “mutual authentication” where users can verify organizations (not just vice versa), via webauthn/passkeys, caller‑verification flows, or better domain practices.

Organizational incentives and UX

  • Repeated theme: organizations externalize security risk and cost onto users, while prioritizing marketing, analytics, and internal convenience.
  • Outsourcing (SMS vendors, IT services, survey platforms) plus bureaucracy around domains encourages off‑brand, confusing communication.
  • Users increasingly avoid certain carriers or services altogether due to chronic delivery failures and scam‑like interactions.