FedEx Communication Habits Mimic Phishing Tactics, Security Expert Warns
Cybersecurity researcher Troy Hunt argues that legitimate corporate messaging patterns are undermining user security training.
Cybersecurity expert Troy Hunt has warned that FedEx's legitimate communication methods frequently mirror the tactics used in phishing attacks. This overlap creates a dangerous environment where users are conditioned to trust suspicious-looking messages, effectively neutralizing standard security awareness training.
According to Hunt, there has been a significant surge in "parcel couldn't be delivered" phishing attacks delivered via SMS. These campaigns are particularly effective because they often bypass the technical controls implemented by telecommunications providers. While Hunt notes that he personally avoids these scams by identifying warning signs—specifically a sense of urgency, a fear of missing out (FOMO), and the use of strange URLs—he argues that the average user is being set up for failure by the companies they trust.
The Normalization of Suspicious Behavior
The core of the issue lies in the inconsistency of how major corporations interact with their customers. Reports from users, including discussions on Hacker News, indicate that legitimate FedEx communications sometimes arrive as plain emails sent from individual employees rather than official corporate channels. In one instance, a user reported receiving a legitimate FedEx customs notice as a plain email from an individual employee with a PDF attachment—a delivery method that is a hallmark of modern phishing and malware distribution.
By utilizing these non-standard communication patterns, corporations inadvertently validate the behavior that security professionals spend years telling users to avoid. When a user receives a legitimate but "suspicious" email from a company like FedEx, it reinforces the idea that unexpected attachments and atypical sender addresses are acceptable, making them far more likely to click a truly malicious link in the future.
Industry Implications
This trend undermines the fundamental principles of security literacy. Most corporate security training instructs employees and consumers to ignore unexpected delivery notifications and avoid clicking links or downloading attachments from unknown senders. However, when a global logistics leader employs those exact behaviors, the distinction between a legitimate corporate request and a credential-stealing attempt becomes blurred.
For the broader industry, this suggests that the burden of security cannot rest solely on the end-user. If corporate communication standards are not aligned with security best practices, the "human firewall" remains porous regardless of how much training is provided.
What to Watch
As phishing attacks continue to evolve and bypass telco filters, the pressure on corporations to standardize their digital communication is increasing. Whether FedEx or other logistics giants will move toward more secure, authenticated communication portals—rather than relying on individual employee emails and attachments—remains to be seen. For now, security experts continue to advise a zero-trust approach to all unexpected delivery notifications.