1 min read

E-Mail From Department Of Labor Could Be Phishing Attack

There is a new phishing campaign to keep a watchful eye on according to email security firm INKY. It’s a particularly fiendish one.

The attackers have designed an email template that does an admirable job of imitating the look and feel of emails sent from the US Department of Labor.

These are being sent out to recipients asking them to submit bids for an ongoing DOL project with the specifics of the project varying from one email to the next.

The emails are professionally and meticulously arranged. Thanks to some clever spoofing they appear to come from an actual Department of Labor server. Naturally they do not come from the DOL, and there are no ongoing projects that require the Department of Labor to blindly spam out emails seeking bids.

Nonetheless, an unwary recipient could easily be taken in by the scam and click the “Bid” button embedded in the email.  That button is of course masking a malicious link which will take the email recipient to one of the phishing sites controlled by the scammers.

Like the emails themselves, these spoofed sites look completely legitimate. A comparison of the HTML and CSS on the scam sites with the actual Department of Labor reveals that they have identical code behind them which is clear evidence that the scammers scraped those sites and used the code to create their own copies.

What’s different is the fact that the scam site includes a pop-up message that is there seemingly to guide the email recipient through the bidding process.  What it’s really doing is moving the potential victim closer to giving up his or her Office 365 credentials.

Of interest is that after a victim enters his/her credentials they’ll be prompted to enter them a second time.  This is to minimize the risk of the scammers harvesting mis-typed credentials.  They seem to have thought of everything!

Vigilance & Mindfulness Are the Best Defence

There’s no good defense against this except for vigilance and mindfulness so please make sure your employees, friends, and neighbors are aware of the ongoing campaign.

Used with permission from Article Aggregator

Managed IT vs. In-House IT: A Portland Business Owner's Guide

Managed IT vs. In-House IT: A Portland Business Owner's Guide

Key Takeaways Most SMBs outgrow in-house IT faster than they expect. Managed IT shifts your approach from reactive fixes to proactive stability. The...

Read the full blog
Signs Your Portland Business Needs Managed IT

Signs Your Portland Business Needs Managed IT

Key Takeaways Frequent tech issues aren’t just annoying, they're early signs you need managed IT services. Managed IT services shift your business...

Read the full blog
When the Gavel Falls: Emergency Tech That Keeps Law Firms Standing

When the Gavel Falls: Emergency Tech That Keeps Law Firms Standing

If you've read our post Chaos to Control: Crafting Escalation Paths That Never Miss a Beat, you already know that when chaos strikes, having a clear...

Read the full blog
Year-End IT Health Check: Preparing for 2025

1 min read

Year-End IT Health Check: Preparing for 2025

As the year winds down, it’s essential to ensure that your IT systems are primed for the new year. A comprehensive IT health check can identify...

Read the full blog

1 min read

Why Your Law Firm Needs Managed IT & Data Backups in Portland OR

Data is the lifeblood of every law firm. From client information and case files to important legal documents and communications, the loss of this...

Read the full blog

1 min read

Law Firm IT vs. Cyber Threats and Data Vulnerabilities

Law firms are constantly facing a critical clash between their IT infrastructure and the ever-evolving threats posed by cyber-attacks and data...

Read the full blog