FedEx向澳大利亚客户发送的关税税费通知短信存在明显的安全隐患,引发了对其真伪的广泛质疑。一位正在等待进口包裹的用户收到多条此类通知后,通过逐一分析发现了短信中的7个可疑特征,包括拼写错误、制造紧急感和奇怪的URL等[1]。在投票调查中,超过4000名投票者中有87%认为该短信"极其可疑"[1]。
通过直接访问FedEx官网验证,用户最终确认短信为合法通知,但却发现了支付系统的严重漏洞。短信中包含的BPOINT支付链接存在URL参数篡改漏洞,允许修改追踪号、客户名称和交易金额[1]。BPOINT由澳大利亚最大银行英联邦银行提供[1]。该用户的Prusa订单金额为US$799,折合AU$1,215.97[1]。此外,FedEx支持电话132610与短信中所留号码并不一致[1]。
诈骗短信问题在澳大利亚日益严重。澳大利亚通讯和媒体管理局最近报告称已阻止336百万条诈骗短信[1],澳洲每年因诈骗造成的损失超过30亿澳元[1]。FedEx这种易被误认为钓鱼攻击的通知方式,正凸显了该问题的严峻性。
An analysis of FedEx customs duty notifications sent via SMS has exposed critical security vulnerabilities that make legitimate payment requests indistinguishable from phishing attacks. A recipient who was genuinely awaiting an imported package received multiple text messages directing them to pay tariffs through a BPOINT payment link, prompting immediate suspicion due to several hallmark phishing characteristics [1].
The SMS messages contained seven red flags including spelling errors, artificial urgency, and suspicious URLs that led 87% of over 4,000 voters to rate the message as "dodgy AF" [1]. Upon investigation, the BPOINT payment system—operated by Australia's largest bank, the Commonwealth Bank—was found to have a query string parameter manipulation vulnerability that could allow attackers to alter tracking numbers, customer names, and payment amounts [1]. While the recipient ultimately confirmed the notification was legitimate after receiving a detailed invoice email, the incident reveals how FedEx's notification methods create the perfect conditions for successful phishing campaigns [1].
The vulnerability is particularly concerning given the scale of fraud in Australia. The Australian Communications and Media Authority recently reported blocking 336 million fraudulent SMS messages, while the country loses over AU$30 billion annually to scams [1]. Adding to the confusion, the support phone number listed in the SMS differed from FedEx's official support line 132610, further eroding consumer confidence [1]. The incident underscores how poor security design and communication practices by major financial institutions can inadvertently train users to distrust legitimate notifications, ultimately increasing vulnerability to actual fraud [1].