FINRA Yet Again Becomes the Impersonated Brand at the Center of Phishing Attacks on Brokerage Firms

Stu Sjouwerman | Oct 14, 2020

FINRA phishing attack social engineeringA mix of domain, phishing emails, a dash of social engineering, and a survey are the recipe for a simple and yet effective campaign targeting the financial sector.

Cybercriminals use the simple adage of “follow the money”. And where’s one of the largest sources of money? Brokerage firms. All it takes is a little compromised access and the bad guys can pretty much do what they want. What better way to get the attention of users at these firms than by pretending to be FINRA – the regulating body that governs their activity.

According to a new regulatory notice put out by FINRA puts firms on notice that emails have been sent out from the domain “regulation-finra.org” which has since been taken down by the registrar on the request of FINRA themselves.

Potential victims were sent an email asking them to participate in a survey regarding the updating of regulation rules, as shown below.

FINRA%20sample%20phishing%20email

It’s not clear what threat action comes next (e.g., credential phishing, attempted download of malware, etc.), but it’s enough to get FINRA’s attention.

This isn’t the first time FINRA has been impersonated; I’ve discussed both phishing scams and even domain impersonation attacks targeting member firms.

Brokerage firms are a high value target, so propping up a layered defense that includes Security Awareness Training to keep users on high alert when emails like this make their way to the Inbox is critical to stop these attacks in their tracks.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.