Friday, July 6, 2018

ExxonMobil - Sends mail with a confusing toll free number and directs customers to a parked page that tries to foist Web browser extensions on visitors.



Looks like, ExxonMobil marketing team did not bother to perform a sanity check with security team


Many people on Twitter who expressed confusion about the mailer said they accidentally added an “e” to the end of “exxonmobil” and ended up getting bounced around to spammy-looking sites with ad redirects and dodgy download offers.

It always amazes me when major companies roll out new marketing initiatives without consulting professionals who help mitigate security and privacy issues for a living. It seems likely that happened in this case because anyone who knows a thing or two about security would strongly advise against instructing customers to visit a parked domain or one that isn’t yet fully under the company’s control.

https://krebsonsecurity.com/2018/07/exxonmobil-bungles-rewards-card-debut/

No comments:

Post a Comment