FINRA Yet Again Becomes the Impersonated Brand at the Center of Phishing Attacks on Brokerage Firms

FINRA phishing attack social engineeringA mix of domain, phishing emails, a dash of social engineering, and a survey are the recipe for a simple and yet effective campaign targeting the financial sector.

Cybercriminals use the simple adage of “follow the money”. And where’s one of the largest sources of money? Brokerage firms. All it takes is a little compromised access and the bad guys can pretty much do what they want. What better way to get the attention of users at these firms than by pretending to be FINRA – the regulating body that governs their activity.

According to a new regulatory notice put out by FINRA puts firms on notice that emails have been sent out from the domain “” which has since been taken down by the registrar on the request of FINRA themselves.

Potential victims were sent an email asking them to participate in a survey regarding the updating of regulation rules, as shown below.


It’s not clear what threat action comes next (e.g., credential phishing, attempted download of malware, etc.), but it’s enough to get FINRA’s attention.

This isn’t the first time FINRA has been impersonated; I’ve discussed both phishing scams and even domain impersonation attacks targeting member firms.

Brokerage firms are a high value target, so propping up a layered defense that includes Security Awareness Training to keep users on high alert when emails like this make their way to the Inbox is critical to stop these attacks in their tracks.

Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe To Our Blog

New call-to-action

Get the latest about social engineering

Subscribe to CyberheistNews