How average folks don't stand a chance against phishing, example #79,488,712: Restaurant
The restaurant, which I will reference as Small Pizza Chain for lack of imagination, has a web site at smallpizzachain.com which is far better than most in that it actually includes the address, opening hours and menu. They use the platform Toast (toasttab.com) for subsrciber advertising.
• Email from "Small Pizza Chain - Town - 123 Main St" <no-reply+12217e0f@toast-restaurants.com> with Subject =?utf-8?q?Join_Our_Loyalty_Program_=F0=9F=8C=9F=F0=9F=8C=9F?=
• Unsubscribe address looks like unsub-61bae21d.0g78z.s1rnuvh2ywtv@bnc3.mailjet.com
• List ID looks like no-reply.12217e0f.toast-restaurants.com.0g68z-5hisx.mj
• Links to sign up to the loyalty program look like https://0g68z.mjt.lu/lnk/AMcAAFIO3YIAAcg4sr4BBaaPrb0AAYCssYYAnGtTAB_7mABnB-qE41xqJo3SHOivejrgkIWcvgAahE8/1/14oYk_G-ZPbEJ4PGjAI10g/aHR0cHM6Ly93d3cudG9hc3R0YWIuY29t3LB1cGF0ZWxsYS1yZXN0b24tMTgyMS13aWVobGUtYXZlL3Jld2FyZHNTaWdudXA
• Visiting smallpizzachain.com and looking around shows no sign of this loyalty program
...until you find the T&C reference which says to create and log in to an account on smallpizzachain.com which has no such thing.
• Following the 0g68z.mjt.lu links redirects to a page on toasttab.com
To save your lookups: mailjet.com, 0g68z-5hisx.mj, and mjt.lu are all Sinch domains (or domain-like names).
#Phishing #ToastInc #Mailjet #Sinch #InfoSec #InformationSecurity #CyberSecurity