Comment by thewebguyd
7 hours ago
> because doctors’ offices seem to have random numbers they call you from
This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat.
In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify.
Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.
I work in this industry, and a big issue is that a major customer of the cheapest, shadiest telcos is the US federal government. Because they're "being responsible with your tax money." So cracking down on them will affect government calls and quickly generate too much pushback. "I don't care how scammy Bill's Discount No-Questions-Asked VoIP LLC is, the army uses them!"
Just this week I got an email from Amex to be on the lookout for scams, and the email itself had a "login" button right in the top.