Cybersecurity researchers find that fake USPS phishing sites account for at least as much internet traffic as the Postal Service itself

Hacker
(Image credit: Caroline Purser/Getty)

A recent paper by cybersecurity-focused firm Akamai has found that queries to suspicious domains impersonating the US Postal Service accounted for nearly as much internet traffic as those to the actual USPS in a four month span between 2023 and '24. The firm's conservative criteria for avoiding false positives, meanwhile, might mean that traffic to phishing sites was actually far greater than to the actual Postal Service.

Akamai collected one dataset of domains containing malicious JavaScript and HTML code with "usps" featured somewhere in the address, and a second set of domains with "usps" in the address that led somewhere other than the Postal Service's official IP range. Akamai's researchers noted that this method actually excluded a large number of potentially suspicious domains in the interest of avoiding false positives.

"Our harsh parameters meant that we were exceedingly conservative with our analysis," the paper explains. "Even so, we saw an extraordinary amount of malicious traffic, which makes the true impact of these impersonations astonishing.

"We could have definitely collected appreciably more malicious domains that impersonate the USPS, but it was critical that we avoided including false positives in this dataset."

Over the sample period between October 2023 and February 2024, Akamai observed about 1.13 million queries to its dataset of suspicious domains, just shy of the 1.18 million that went to the official USPS website. In some weeks over the holidays, the suspicious traffic actually vastly exceeded the legitimate queries, suggesting that the holiday season is a busy time for bad actors trying to take advantage of anxious gift givers.

"Although the USPS won with 51% of the total queries for this 5-month period in this analysis," Akamai's researchers write, "the way we filtered the data suggests that the malicious traffic significantly outweighs the legitimate traffic in the real world."

And that's just USPS: what about the likely volume of fraudulent traffic impersonating DHL, FedEx, and a myriad other private or state-run parcel delivery services? Forget about package delivery, so much of internet traffic now consists of mass-add WhatsApp Bitcoin chats, "Hello Dear" cold messages, and the infamous "[redacted for public decency] IN BIO" accounts of recent Twitter fame. Those undersea fiber optic cables are absolutely straining under the weight of all this pointless, malicious spam.

Associate Editor

Ted has been thinking about PC games and bothering anyone who would listen with his thoughts on them ever since he booted up his sister's copy of Neverwinter Nights on the family computer. He is obsessed with all things CRPG and CRPG-adjacent, but has also covered esports, modding, and rare game collecting. When he's not playing or writing about games, you can find Ted lifting weights on his back porch.

Read more
3D illustration of a grid of black cpus with different IoT symbols, representing a botnet concept
Cloudflare claims to have mitigated biggest DDoS attack on record with requests flying in from 5,500 IP addresses per second
Mature professional business man suffering from a headache while working online on computer checking emails alone at work. One male manager feeling overworked, stressed and tired due to a deadline - stock photo
A 2023 study concluded CAPTCHAs are 'a tracking cookie farm for profit masquerading as a security service' that made us spend 819 million hours clicking on traffic lights to generate nearly $1 trillion for Google
Three Magikarp Pokémon
The FBI used self-destruct on malware infecting over 4,000 US computers, it's super effective
fibre optics shooting past electronics of broadband hub
Sorry, 2024's record-breaking 402,000,000 Mbps internet connection isn't available at your house yet
Leisure Suit Larry base jumping off a building wearing sunglasses giving thumbs up woman is skydiving behind him
Floridians appear to be frantically Google searching for VPNs in the wake of the state's invasive porn ban
TP-Link AXE75 Wi-Fi 6E router
US congressman calls again for the government to ban Chinese-made TP-Link routers: 'I would not have that in my home'
Latest in Gaming Industry
Gabe Newell in a Valve promotional video, on a yacht.
Go ahead and complain the discounts aren't as steep as they used to be, but Steam just had its biggest year ever for seasonal sales
Pirate Bay co-founder Carl Lundstrom
Pirate Bay co-founder and far-right politician found dead after plane crash
Flag of Saudi Arabia
Saudi Arabia buys Pokémon GO maker for $3.5 billion with a 'B'
Vice President, Games at Netflix Mike Verdu speaks onstage during TechCrunch Disrupt 2022 on October 18, 2022 in San Francisco, California
4 short months after saying 'We'll have to adapt and change', Netflix's AI games VP adapts and changes into a person who isn't working there anymore
Astarion, a beautiful vampire spawn in Baldur's Gate 3, looks dubiously at the player character.
'What do you mean real actors?': Astarion's VO, who shared an awards category with Idris Elba after Baldur's Gate 3, remembers the dark ages of mocap
Yoda Luke and R2 in Lego form.
Lego is going to make its videogames in-house from now on, says it would 'almost rather overinvest'
Latest in News
Closeup of the new Copilot key coming to Windows 11 PC keyboards
Microsoft co-authored paper suggests the regular use of gen-AI can leave users with a 'diminished skill for independent problem-solving' and at least one AI model seems to agree
A lolporrit squeals in excitement while being driven in a moon buggie in Final Fantasy 14: Dawntrail, patch 7.2.
Final Fantasy 14 patch 7.2's trailer has me finally hyped to get stuck back in—and to go to the moon and pilot some mechs, because why not
A pink GameSir Nova Lite, and a purple 8BitDo Ultimate 2C float in a teal void.
Hall effect controllers are so cheap now I’ve got a deal for you AND your player two
Peely from Fortnite with banana-fied Wolverine claws.
Fortnite comes to Snapdragon: Epic Games announces upcoming Arm support for its Easy Anti-Cheat software
Texas Instruments MSPM0C1104 tiny chip
World's smallest microcontroller looks like I could easily accidentally inhale it but packs a genuine 32-bit Arm CPU
Varjo Aero
Varjo Aero VR headsets seem to be not working on RTX 5090s, and its community is opting for strange solutions while waiting for an Nvidia driver release to fix it