US govt warns remote workers of ongoing vishing campaign

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory warning teleworkers of an ongoing vishing campaign targeting entities from multiple US industry sectors.

Vishing (also known as voice phishing) is a type of social engineering attack where the attackers impersonate a trusted entity during a voice call to manipulate their targets into revealing sensitive information.

"In mid-July 2020, cybercriminals started a vishing campaign — gaining access to employee tools at multiple companies with indiscriminate targeting—with the end goal of monetizing the access," the agencies said. "Using vished credentials, cybercriminals mined the victim company databases for their customers’ personal information to leverage in other attacks."

According to the joint alert, the attackers are on a very tight timeline given that they sold the stolen credentials very quickly after initially gaining access to companies' networks following a successful vishing attack.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top