Security News > 2022 > March > FBI warns election officials of credential phishing attacks
"As of October 2021, US election officials in at least nine states received invoice-themed phishing emails containing links to websites intended to steal login credentials."
On 5 October 2021, unidentified cyber actors targeted US election officials in at least nine states, and representatives of the National Association of Secretaries of State, with phishing emails.
On 18 October 2021, cyber actors used two email addresses, purportedly from US businesses, to send phishing emails to county election employees.
On 19 October 2021, cyber actors used an email address, purportedly from a US business, to send a phishing email containing fake invoices to an election official.
The US federal law enforcement agency believes the threat actors behind this phishing campaign will likely continue or increase attacks against US election officials with new phishing emails as the 2022 midterm elections are closing in.
Network defenders are advised to educate email users such as the election officials targeted in these attacks on how to identify phishing, social engineering, and spoofing attempts and always confirm requests for sensitive info-including credentials-through secondary channels.
News URL
Related news
- Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials (source)
- Australian Organisations Targeted by Phishing Attacks Disguised as Atlassian (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks (source)
- Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack (source)
- Brazilian police claim they've cuffed serial cybercrook behind FBI and Airbus attacks (source)
- Phishing scams and malicious domains take center stage as the US election approaches (source)
- FBI: Upcoming U.S. general election fuel multiple fraud schemes (source)
- Midnight Blizzard Escalates Spear-Phishing Attacks On Over 100 Organizations (source)
- Windows infected with backdoored Linux VMs in new phishing attacks (source)