I almost got scammed (and it darn made me almost defenseless because it came from a SMS by SMART's special number, y'know, the promo texts you receive from time-to-time from your telco which you can't reply to). It's a good thing I suddenly became vigilant when it tried to get my credit card number just for a delivery fee of 15 pesos (it doesn't accept GCash which is very funny in hindsight)... Now all the signs of it being a scam site ticked for me!
They're trying to pretend to be a website of SMART (the telco). The fake URL they used is "smarte.top/rewards" (you might have to spoof your browser as a mobile Firefox to get it to not return a 404), and they have a TLS cert from Google Trust Services of course...
I'd say if my browser has taken EV certs seriously I could have spotted the scam much earlier but even the real SMART website (
smart.com.ph) doesn't have EV. Just plain DV (but it's from GlobalSign which means they have paid for it...). I bet the anti-EV crusade by Mozilla and Google just made them not choose getting an EV cert (though I don't get why they'd not go just full gratis and get a cert from LE instead of GlobalSign...)
If governments just required any website handling e-commerce (like if they have to process credit cards for example) to get an EV cert (otherwise they get blocked in the country), pressured the browsers to make EV certs easily noticeable in the UI (especially in mobile!) or else also get blocked in the country, and ran public awareness campaigns on how to easily spot a genuine website now that EV certs are easily noticed, these scam sites would quickly become a thing of the past, ISTG!
#Philippines #SMART #telco #TLS #security #cybersecurity #cyberscam #scam