Remix.run Logo
Joker_vD 2 hours ago

Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.

raesene9 2 hours ago | parent | next [-]

Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).

ericlaw 2 hours ago | parent [-]

Fun fact: still can in Chromium-based browsers. https://textslashplain.com/2023/03/22/attack-techniques-spoo...

spc476 an hour ago | parent | prev | next [-]

It's probably easier for the marketing department to get a new domain up and running that it is for a new subdomain within their own company. Battling Business Units and all that.

saghm 25 minutes ago | parent [-]

That's a problem that should be solved then, because literally everyone loses when it's done this way

derektank 2 hours ago | parent | prev | next [-]

You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains

nerdsniper 2 hours ago | parent [-]

Running marketing off a separate domain is often a conscious decision because if they start getting blocked for spam, then critical service/operational emails from your actual domain might also get blocked.

saghm 29 minutes ago | parent [-]

Oh good, I'm glad that Cloudflare, proud defender of internet security, is properly focused on the important goal of optimizing for their ability to send promotional emails to my inbox rather than silly things like helping prevent phishing attacks.

make3 2 hours ago | parent | prev [-]

this is the correct take