FINRA Warns of Phishing Attacks



FINRA Warns Phishing AttackThe Financial Industry Regulatory Authority (FINRA) has warned of a phishing campaign that’s trying to trick users into responding to a phony regulatory non-compliance issue. The emails contain malicious links or documents.

“FINRA warns member firms of an ongoing phishing campaign that involves fraudulent emails purporting to be from ‘FINRA Membership’ and using the email address ‘supports@finra-online[.]com,’ FINRA says. “The email asks the recipient to respond to an issue of ‘regulatory non-compliance for which your immediate response is required’ and then asks the recipient to click on a link or document. FINRA recommends that anyone who clicked on any link or image in the email immediately notify the appropriate individuals in their firm of the incident.”

The documents against which FINRA is warning will presumably deliver malware and the links will lead to a malicious website. The phishing emails read, “Good day, Please find the following attached report from FINRA on regulatory non-compliance for which your immediate response is required. As part of a disclosure review process, we require this background report be completed. Review the enclosed document in respect to our compliance policy. If you've got more questions regarding this letter don't hesitate [sic] to contact us. Regards, Team FINRA.”

This type of issue would catch the attention of many employees, and FINRA recommends that users be vigilant when dealing with emails that seem urgent. (On the plus side, note that the social engineers show that loose idiomatic control that’s helped so many potential victims spit the hook before they’re landed. Spelling and grammar count in life as much as in high school.)

“The domain of ‘finra-online[.]com’ is not connected to FINRA and firms should delete all emails originating from this domain name,” the alert states. “FINRA reminds firms to verify the legitimacy of any suspicious email prior to responding to it, opening any attachments or clicking on any embedded links. FINRA has requested that the Internet domain registrar suspend services for ‘finra-online[.]com.’

New-school security awareness training can teach your employees to be wary of unsolicited emails so they can avoid falling for phishing attacks.

FINRA has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews