Ad End 1 February 2024
Ad Ends 13 January 2025
Ad End 26 February 2025
ad End 25 April 2025
Ad Ends 20 January 2025
Ad expire at 5 August 2024
banner Expire 25 April 2025
What's new
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
casino
swipe store
adv exp at 23 August 2024
Carding.pw carding forum
BidenCash Shop
Kfc CLub

Phishers Spoof New York Department of Labor

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,544
Reaction score
916
Points
212
Awards
2
  • trusted user
  • Rich User
Scammers are impersonating New York State's Department of Labor to steal personal information from state residents seeking to claim money from a COVID relief fund.

Targets are sent an email bearing the state logo that appears to come from “[email protected].” The email states that by activating their account, the recipient will receive $600 in pandemic aid.

It reads: "Dear Citizen, Due to Covid-19 related issues, NY.GOV will pay $600 for victims who are affected by this pandemic. Please complete the online form to join the aids program. Please click here to active your account. Please do not close out of the browser while completing the account activation. Thank you, New York State."

A malicious link contained within the email directs the target to a webpage controlled by the attackers. The page has been set up to mimic a page on the New York State government site.

Targets are instructed to fill in a form that asks for their name, address, date of birth, Social Security number, and driver’s license number.

The new phishing attack was detected by researchers at Abnormal Security, who believe that it could have landed in as many as 100,000 mailboxes.

Researchers found that the email's true sender was “[email protected],” a Panamanian-registered domain that is not associated with the New York state government.

"The email contains an embedded link that should supposedly lead to a NY.GOV site, but actually points to 'https://thesender[.]org/fjc4'," wrote researchers. "After clicking on the hypertext, the link redirects to 'bo2.cloudns.cl/NYU/cnf[.]php,' a phishing page posing as a legitimate government website."

"Although this landing page displays the official New York state government logo, the URL is not associated with the New York Department of Labor."

Researchers noted that the attackers had used the lure of money coupled with an air of authority created by impersonating an official government entity to incentivize the target to act quickly. They also observed that the timing of the attack may have given it added legitimacy.

"Americans have already received pandemic stimulus checks from the government, so a recipient of this email may be more likely to believe that the government is offering additional relief as the pandemic continues," wrote researchers.
 
Ad End 1 February 2024
Top