CyberScoop reports that Arizona and Pennsylvania county election officers have been facing a deluge of phishing attacks ahead of their primaries in August, indicating extensive cybersecurity threats against election officials prior to the midterm polls.
Malicious emails aimed at Arizona county election officials increased by more than threefold between the first and third quarter of 2022, with phishing activity peaking around the state's primary on Aug. 2, while malicious emails targeted at those in Pennsylvania rose by 382% between the last quarter of 2021 and the first quarter of 2022, before increasing by another 169% during the second quarter, according to a Trellix report.
Phishing attacks were found to either be notifications regarding soon-to-expire email passwords that redirect to a phishing site collecting recipients' credentials, or email thread hijacking involving a county election worker and a ballot distribution and collector contractor.
"Ultimately, this phishing scheme plays on the election workers professional and moral commitment to help a trusted contractor struggling to register people to vote," researchers added.
OSET Institute Board Member Eddie Perez noted that prevalent disinformation has exacerbated the impact of elections-targeted phishing since 2020.
Sixty thousand emails from U.S. State Department accounts were noted by a staffer working for Sen. Eric Schmitt, R-Mo., to have been exfiltrated by Chinese threat actors during the widespread compromise of Microsoft email accounts that commenced in May, according to Reuters.
Threat actors have leveraged the ZeroFont phishing attack technique, which initially involved the insertion of hidden characters or words in emails to evade security detection systems, to modify message previews as shown on Microsoft Outlook and other email clients, BleepingComputer reports.
BleepingComputer reports that individuals who have filed claims against bankrupt cryptocurrency lender Celsius have been subjected to phishing attacks involving the impersonation of the lender's claims agent, Stretto.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news