Subdomain Scam Hits Australian Government Seeking Money to “Register” Bogus Domain Names

Stu Sjouwerman | Jun 20, 2019

Employees of agencies within the Australian government have been receiving targeted emails offering to register what amounts to a subdomain of a legitimate look-alike domain.

Employees of various agencies within the Australian government have been receiving an email urging them to take advantage of a “first right of refusal” on registering a subdomain of a look-alike domain name to the government’s domain name. The email creates some urgency by warning the recipient that someone else has requested to purchase the bogus subdomain (implying the registration would cause domain name confusion for the agency).

The Australian government’s Cyber Security Unit (CSU) issued an advisory warning agencies about the scam, advising them to not respond:

6-5-19 Blog - Image

As we all know, you can’t sell a subdomain. But, in the case of countries like Australia where a complex base domain of vic.gov.au is used for the government (with the specific agency’s subdomain listed underneath), it’s plausible to see a non-techincal user believing that their agency’s domain could reside under vic.com.

In this particular scam, it appears that the intent of the scammer is to simply get someone at each government agency to cough up about $300 AU. But a scam like this could turn much more deadly; links to register could point to malicious downloads, spoofed logon pages to the existing registrar, etc.

To avoid scams like this, organizations need to educate their users via Security Awareness Training about how these types of scams work, why they’re bogus, and how to safely avoid becoming a victim of fraud or worse.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.