FBI alerts about phishing scam aimed at retail corporations

May 9, 2024
1 min read

TLDR:

  • FBI warns of phishing and smishing attack targeting gift card departments of major U.S. retail corporations by cybercriminal group STORM-0539.
  • Group employs tactics such as smishing campaigns and advanced phishing kits to access employee accounts and create fraudulent gift cards.

The Federal Bureau of Investigation (FBI) has issued a warning about a sophisticated phishing and smishing (SMS phishing) campaign targeting the gift card departments of major U.S. retail corporations. The cybercriminal group responsible for these attacks, known as STORM-0539 or Atlas Lion, has been causing significant financial losses through the creation of fraudulent gift cards.

STORM-0539 employs various tactics to breach corporate security, including targeting employees’ personal and work mobile phones with smishing campaigns, advanced phishing kits to bypass multi-factor authentication, and accessing secure shell (SSH) passwords and keys. The FBI alert emphasizes the group’s persistence and adaptability, posing a significant threat to corporate security.

The FBI advises organizations to review and update their incident response plans, provide employee education on identifying phishing attacks, enforce strong password policies, and implement anti-phishing tools to mitigate these threats. Phishing scams remain a prevalent threat, especially during holiday seasons, and it is crucial for individuals and organizations to stay vigilant and informed to reduce the risk of falling prey to cyber threats.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and