The Federal Bureau of Investigation (FBI) is releasing this Private Industry Notification to highlight a trend of compromised US and foreign government email addresses used to conduct fraudulent emergency data requests to US-based companies, exposing personally identifying information (PII).
While the concept of fraudulent emergency data requests was previously used by other threat actors, such as Lapsus$, the increase in postings on criminal forums regarding the process of emergency data requests and sale of compromised credentials has led to an increase of their use. The FBI encourages organizations to implement the recommendations in the Mitigations section to reduce the likelihood and impact from submission of fraudulent emergency data requests to attempt to gain unauthorized access to PII.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- Tillerson proposes Cyberspace and Digital Economy Bureau to address security, policy creation
February 7, 2018
US Secretary of State Rex Tillerson wants to develop a Bureau of Cyberspace and the Digital Economy, according to a letter from him to Edward Royce, the chair of the committee of foreign affairs. The bureau, as described in the letter, would help the US lead international efforts in all aspects of cyberspace. As the world, its economy, ...
- DoD Studying Implications of Wearable Devices Giving Too Much Info
January 30, 2018
Defense Department officials are studying security issues raised by physical conditioning trackers that also can be used to track service members’ whereabouts, a Pentagon spokesman told reporters today. The concern comes from a “heat map” posted by Strava — the makers of a fitness tracking application that shows the routes service members run or cycle in ...
- Trump’s national security strategy outlines ‘cyberspace’ goals
December 19, 2017
President Donald Trump unveiled a national security strategy on Monday that highlights his administration’s “America First” approach to the world and foreign policy. The sprawling 68-page document touches on a number of national security concerns, including economic ties with China and the lethality of the US nuclear arsenal, as well as a brief list of action items that ...
- America’s 2020 Census systems are a $15bn cyber-security tire fire
November 1, 2017
Analysis In 2020, America will run its once-a-decade national census, but the results may not reflect reality if hackers manage to have their way. On Tuesday, the US Senate Homeland Security and Governmental Affairs Committee heard that the 2020 census will be the first to make extensive use of electronic equipment. For example, census workers will be given tablets ...
- Kaspersky Opens Antivirus Source Code for Independent Review to Rebuild Trust
October 23, 2017
Kaspersky Lab — We have nothing to hide! Russia-based Antivirus firm hits back with what it calls a “comprehensive transparency initiative,” to allow independent third-party review of its source code and internal processes to win back the trust of customers and infosec community. Kaspersky launches this initiative days after it was accused of helping, knowingly or unknowingly, Russian government ...
- How A Drive-by Download Attack Locked Down Entire City for 4 Days
October 16, 2017
We don’t really know the pain and cost of a downtime event unless we are directly touched. Be it a flood, electrical failure, ransomware attack or other broad geographic events; we don’t know what it is really like to have to restore IT infrastructure unless we have had to do it ourselves. We look at other people’s ...

