Cybersecurity researchers find that fake USPS phishing sites account for at least as much internet traffic as the Postal Service itself
"The way we filtered the data suggests that the malicious traffic significantly outweighs the legitimate traffic in the real world."
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
A recent paper by cybersecurity-focused firm Akamai has found that queries to suspicious domains impersonating the US Postal Service accounted for nearly as much internet traffic as those to the actual USPS in a four month span between 2023 and '24. The firm's conservative criteria for avoiding false positives, meanwhile, might mean that traffic to phishing sites was actually far greater than to the actual Postal Service.
Akamai collected one dataset of domains containing malicious JavaScript and HTML code with "usps" featured somewhere in the address, and a second set of domains with "usps" in the address that led somewhere other than the Postal Service's official IP range. Akamai's researchers noted that this method actually excluded a large number of potentially suspicious domains in the interest of avoiding false positives.
"Our harsh parameters meant that we were exceedingly conservative with our analysis," the paper explains. "Even so, we saw an extraordinary amount of malicious traffic, which makes the true impact of these impersonations astonishing.
"We could have definitely collected appreciably more malicious domains that impersonate the USPS, but it was critical that we avoided including false positives in this dataset."
Over the sample period between October 2023 and February 2024, Akamai observed about 1.13 million queries to its dataset of suspicious domains, just shy of the 1.18 million that went to the official USPS website. In some weeks over the holidays, the suspicious traffic actually vastly exceeded the legitimate queries, suggesting that the holiday season is a busy time for bad actors trying to take advantage of anxious gift givers.
"Although the USPS won with 51% of the total queries for this 5-month period in this analysis," Akamai's researchers write, "the way we filtered the data suggests that the malicious traffic significantly outweighs the legitimate traffic in the real world."
And that's just USPS: what about the likely volume of fraudulent traffic impersonating DHL, FedEx, and a myriad other private or state-run parcel delivery services? Forget about package delivery, so much of internet traffic now consists of mass-add WhatsApp Bitcoin chats, "Hello Dear" cold messages, and the infamous "[redacted for public decency] IN BIO" accounts of recent Twitter fame. Those undersea fiber optic cables are absolutely straining under the weight of all this pointless, malicious spam.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
Ted has been thinking about PC games and bothering anyone who would listen with his thoughts on them ever since he booted up his sister's copy of Neverwinter Nights on the family computer. He is obsessed with all things CRPG and CRPG-adjacent, but has also covered esports, modding, and rare game collecting. When he's not playing or writing about games, you can find Ted lifting weights on his back porch. You can follow Ted on Bluesky.

