Security News > 2022 > January > Phishing attack spoofs US Department of Labor to steal account credentials

Phishing attack spoofs US Department of Labor to steal account credentials
2022-01-19 13:53

A phishing campaign seen by email security provider Inky tries to trick its victims by inviting them to submit bids for alleged government projects.

A phishing email that appears to come from an official government entity is especially deceptive as it carries an air of authority.

A malicious campaign detected by Inky in the latter half of 2021 spoofed the U.S. Department of Labor as a way to harvest the account credentials of unsuspecting victims.

Claiming to come from a senior Department of Labor employee handling procurement, the emails invited the recipients to bid on "Ongoing government projects." A PDF attached to the email looked like an official DoL document with all the right visuals and branding.

Fourth, the attackers presented what seemed to be a real government website but then redirected victims to a phishing form where their credentials could be captured.

In an instance like this, you would not be asked to log in with your email or account credentials on a totally different network.


News URL

https://www.techrepublic.com/article/phishing-attack-spoofs-us-department-of-labor-to-steal-account-credentials/#ftag=RSS56d97e7