
the staff of the Ridgewood blog
Trenton NJ, on January 6, the NJCCIC observed a phishing campaign targeting New Jersey government employees. In this campaign, the sender claims to be from the employee’s human resources department announcing an annual vacation plan. A link leads to a phishing website where the employee is prompted to log in with their government email credentials. These emails spoof the display name of the sender email address to match the domain of the recipient, making the messages appear to come from a legitimate source in their organization. However, the sender’s hostname originates from the domain sumltomocorp[.]com, a website known for marketing spam URLs. Additionally, the link contains the recipient’s email address in the URL in another attempt to add legitimacy to the message.
Continue reading Phishing Campaign Targets New Jersey Government Employees