logoalt Hacker News

Joker_vDtoday at 6:47 PM4 repliesview on HN

Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.


Replies

raesene9today at 7:06 PM

Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).

show 1 reply
spc476today at 7:35 PM

It's probably easier for the marketing department to get a new domain up and running that it is for a new subdomain within their own company. Battling Business Units and all that.

show 1 reply
derektanktoday at 6:52 PM

You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains

show 1 reply
make3today at 6:52 PM

this is the correct take