[Mail_treas] Domain Spoofing

Thor Sage sage at mveca.org
Fri Apr 19 11:26:24 EDT 2024


Good morning,
We've received reports of increasing numbers of instances of cyber criminals creating fictitious domain name registrations (domain spoofing) accompanied by targeted research into school staff directories designed to help criminals impersonate real school employees.  For instance, a criminal creates a domain name that varies a real school's domain name by one letter (i.e. greatohioschools.org vs. greatohioschool.org).  That criminal then creates email addresses within the fictitious domain that closely mimic the email address of real school employees (i.e. John.Smith at greatohioschools.org<mailto:John.Smith at greatohioschools.org> vs. John.Smith at greatohioschool.org<mailto:John.Smith at greatohioschool.org>).  One district in our region has been contacted by both Dell and Verizon with confirmation requests for large equipment orders they did not place.  These orders were associated with the name of a real employee and email address, varied only by the one letter in the spoofed domain name.  Please be on the lookout for this type of activity and scrutinize all invoices, regardless of legitimate names and other contact information that might be included.
There is a free domain spoof test available here: https://www.knowbe4.com/domain-spoof-test.  This is a one-time free service specifically for security administrators.
Thank you,
Thor

Thor Sage
Executive Director
Miami Valley Educational Computer Association
937-767-1468  x3101
[http://www.mveca.org/images/logo.gif]<http://www.mveca.org/>       [i] <https://www.linkedin.com/company/mveca/>
Not-for-profit Technology Services for Education and Local Governments


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listserv.mveca.org/pipermail/mail_treas/attachments/20240419/5b407d9b/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.jpg
Type: image/jpeg
Size: 3184 bytes
Desc: image001.jpg
URL: <http://listserv.mveca.org/pipermail/mail_treas/attachments/20240419/5b407d9b/attachment.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.jpg
Type: image/jpeg
Size: 1229 bytes
Desc: image002.jpg
URL: <http://listserv.mveca.org/pipermail/mail_treas/attachments/20240419/5b407d9b/attachment-0001.jpg>


More information about the Mail_treas mailing list