When Phishing And Disinformation Meet

Stu Sjouwerman | Sep 16, 2020

iStock-174649421The Insider reported that QAnon is co-opting a USPS phishing scam, and claim the Vishing text messages are linked to human trafficking.

"A viral [text] phishing scheme is targeting people across the country with scammy text messages claiming to be from the United States Postal Service (USPS). Now, QAnon conspiracy theorists have jumped into the fray, falsely claiming the scheme is tied to human trafficking, as reported by Insider.

There’s no evidence to suggest this is true. The rumor has spread on Facebook and Instagram, echoing the Wayfair conspiracy theory that went viral earlier this summer. Unlike the Wayfair conspiracy, however, the USPS myth is obfuscating a real phishing threat.

The scam involves text messages that claim to have information about a USPS delivery. To find out more, people have to click a link. On Twitter, security researcher Eric Ellason said the link goes to the domain m9sxv.info, which then redirects to jtuzd.rdtk.io. He speculated the goal was to steal peoples’ credentials, as reported by Gizmodo.

On September 1st, an Instagram user with over 5,000 followers posted a screenshot of the text message, and said that clicking the link would have given traffickers access to her location. “There is a new sex trafficking method where you will receive a text message saying that there was an issue with a package that you have purchased,” she wrote. “Whether the ‘problem’ is your packaged has been lost, damaged, etc. the message will send you to a link to ‘track your package’, and apparently once you open the link your location will begin to be immediately tracked.”

By then, the rumor had already gone viral enough that Polaris, the non-profit behind the National Human Trafficking Hotline, had to put out a statement. It said the organization had received numerous reports about the USPS scheme and its supposed link to human trafficking. It urged people not to spread false information.

“Handling a surge of concern over viral social media posts makes it far more difficult for the Trafficking Hotline to handle other reports in a timely manner and might result in wait times for people who have a limited window of opportunity to reach out safely,” Polaris wrote.

If there’s a bright spot on this bleak horizon, it’s that the rumor could stop people from clicking the link in the scammy text message. Inadvertently thwarting a phishing scam by spreading misinformation about human trafficking is very 2020, to say the least. KnowBe4 just released a new Disinformation training module. You can preview it at no cost at the ModStore. See below.

Cross-posted from The Verge with grateful acknowledgment.

Topics: Phishing

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.