Security News > 2021 > August > US brokers warned of ongoing phishing attacks impersonating FINRA

The US Financial Industry Regulatory Authority warns US brokerage firms and brokers of an ongoing phishing campaign impersonating FINRA officials and asking them to hand over sensitive information under the threat of penalties.
In a notice issued on Friday, the US financial industry regulator said that the phishing messages are being sent from multiple domains impersonating FINRA official sites.
The domains used in these ongoing phishing attacks were registered on Thursday, August 12, using the services of the Hosting Concepts B.V. and NameCheap registrars.
Before issuing the alert, FINRA asked the Internet domain registrar to suspend services for the malicious domains due to their use in active phishing attacks.
According to the US financial market regulator, none of the domain names used to deliver phishing messages are connected to FINRA. Organizations receiving phishing emails originating from these domain names are advised to delete them immediately.
Another alert, issued in March, alerted US brokers of a phishing campaign using fake compliance audit alerts to harvest brokers' information.
News URL
Related news
- Hacker pleads guilty to SIM swap attack on US SEC X account (source)
- US indicts 8Base ransomware operators for Phobos encryption attacks (source)
- Critical PostgreSQL bug tied to zero-day attack on US Treasury (source)
- Microsoft: Hackers steal emails in device code phishing attacks (source)
- Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains Including SharePoint & Zoom Docs (source)
- Phishing attack hides JavaScript using invisible Unicode trick (source)
- FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud Services (source)
- 2024 phishing trends tell us what to expect in 2025 (source)
- Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail (source)
- YouTube warns of AI-generated video of its CEO used in phishing attacks (source)