Three UK: We're sending you this SMS to warn you not to pay attention to unsolicited texts
- Reference: 1594032306
- News link: https://www.theregister.co.uk/2020/07/06/three_uk_sma/
- Source link:
The definitely-not-smishing-honest message was received by Reg reader Chris, and he was not very chuffed with it. He told us:
"They send an unsolicited out-of-the-blue SMS which asks you to 'click' (not tap) on a link. When checked out in a sandboxed environment this goes to an insecure http-only page which warns of suspicious text messages and a video telling recipients not to tap on any links. Awesome!"
The offending message is reproduced in all its glory below:
This message has all the hallmarks of a smishing (SMS phishing) message. As UK.gov-backed website Get Safe Online [1]explained , such messages "instruct you to either go to a website or make a phone call to a specified number… They play on your basic human emotions and needs, such as trust, safety, fear of losing money, getting something for nothing, eagerness to find a bargain or desire to find love or popularity/status."
As even Three itself warns, you really shouldn't pay attention to smishing messages: "If you've received a suspicious message, don't click on any links. Get in touch with the company it's supposed to be from, first. They'll let you know if it's genuine or not. Until then, don't click on any links or follow any of the instructions."
The cautious telco added: "Would the supposed sender really contact you like this?"
Message sender names can easily be spoofed, as one-time Lulzsec chap Jake Davis [2]explained when UK.gov started bombarding innocent Britons with SMS messages about the pandemic earlier this year.
A mildly irritated Three spokesperson told us: "We regularly and proactively contact our customers with guidance on how to avoid smishing fraud. This includes linking to a genuine website where we communicate about our safety measures. We inform all our customers that the website links we use, and are therefore safe to click on, are 3.uk and three.co.uk. More than 500,000 customers have read the guidance and now have a better understanding of how to protect themselves as a result.”
In fairness, the website does say that 3-dot-uk is one of their own domains. But for cautious consumers it doesn't really seem right.
A few years ago some well-meaning-but-thoughtless British police [3]sent out a ransomware warning link that went to a file called ransomware.pdf . ®
Get our [4]Tech Resources
[1] https://www.getsafeonline.org/protecting-yourself/smishing/
[2] https://www.jake-davis.com/post/uk-government-covid19-text-alert
[3] https://www.theregister.com/2017/05/17/ransomware_wannacrypt_how_not_to_warn_against_it
[4] https://whitepapers.theregister.com/
Same sender and text with bit.ly link
How many would go there? I guess a hundred thousand at least.
We all know Android message clients aren't particularly secure.
They would have done better to put that link as a warning page, to teach people not to click on a link by sticking up a warning banner.
Mind you send some people a link saying click here so you identity can be stolen and I’m sure a good percentage would do so.
Isn't that the whole point. People who are dumb enough to click in the link get educated. People smart enough not to click on the link don't need it.
Typical
I get a monthly email from an international banking entity that just says:
“Notice
Your statement is available. Click here to login and review”
It’s worse than most phishing attempts but is genuinely from them. Doesn’t even address me by name!
Care to guess...
How many people would just follow the instruction and click on the link?