Heimdal Security Blog

Election Officials Warned by the FBI of Credential Phishing Campaigns

On Tuesday, the Federal Bureau of Investigation (FBI) issued a warning to the US election and other state and local government officials about a widespread phishing operation that has been attempting to steal their credentials since at least October 2021.

If successful, this activity may provide cyber actors with sustained, undetected access to a victim’s systems. As of October 2021, US election officials in at least nine states received invoice-themed phishing emails containing links to websites intended to steal login credentials.

Source

Considering that the phishing emails have similar attachment files, use compromised email addresses, and were sent at the same time, this is most probably a coordinated, ongoing attempt to attack US election officials.

According to the FBI, the threat actors employed a variety of techniques to lead their victims to phishing landing pages that were intended to fool them into entering their logins.

On October 18, 2021, cybercriminals sent phishing emails to county election employees using two email addresses that appeared to be from US enterprises.

The FBI identified three waves of phishing emails aimed at election officials, each of which used different methods to hoodwink them into revealing their credentials:

Mitigations

The FBI believes that cybercriminals will continue or increase their phishing attempts targeting US election officials in the run-up to the 2022 US midterm elections.

Proactive monitoring of election infrastructure (including official email accounts), as well as communication about this sort of activity between the FBI and its state, local, territorial, and tribal partners, will:

To lower the risk of compromise, the US federal law enforcement agency advises network defenders to implement the following mitigations.

How Can Heimdal™ Help?

Heimdal Security has developed two email security software aimed against both simple and sophisticated email threats: Heimdal Email Security, which detects and blocks malware, spam emails, malicious URLs, and phishing attacks, and Heimdal Email Fraud Preventiona revolutionary email protection system against employee impersonation, fraud attempts – and BEC, in general.

For example, you may want to consider Heimdal Security’s Heimdal Email Fraud Prevention, the ultimate email protection against financial email fraud, C-level executive impersonation, phishing, insider threat attacks, and complex email malware. How does it work? By using over 125 vectors of analysis and being fully supported by threat intelligence, it detects phraseology changes, performs IBAN/Account number scanning, identifies modified attachments, malicious links, and Man-in-the-Email attacks. Furthermore, it integrates with O365 and any mail filtering solutions and includes live monitoring and alerting 24/7 by our specialists.

If you liked this article, follow us on LinkedInTwitterFacebookYoutube, and Instagram for more cybersecurity news and topics.