HomeSecurityFake 401K year-end statements used to steal corporate credentials

Fake 401K year-end statements used to steal corporate credentials

Malicious actors use personal retirement accounts (401k plans in the US), salary increases, and performance reports to steal the credentials of a company's employees.

See also: ownCloud: Critical vulnerabilities expose credentials
401K

Email security company Cofense warns that these attacks are becoming more common and even organizations with reliable email security practices are having problems with them.

A 401k is a popular retirement savings plan in the United States, which offers a convenient way for employees to save for the future with tax benefits, often including additional contributions from their employer.

Cybercriminals are exploiting this issue and sending out 401(k) notifications, pretending to be someone from their company's Human Resources department, claiming an important update about the plan or an increase in contributions.

Cofense reports that over the past year it has noticed an increased number of QR codes embedded in these emails , taking recipients to a fake login page designed to steal credentials.

Other types of incentive measures that are more commonly seen towards the end of the year include open enrollment, surveys, and salary structure reorganization communications.

See also: Hot Topic: Reveals wave of credential-stuffing attacks

Open enrollment typically occurs toward the end of the year, allowing employees to enroll in insurance or retirement plans. Recipients take these messages seriously, as failure to enroll by the deadline results in loss of eligibility for certain benefits until the next enrollment period.

theft of corporate credentials

Cybercriminals seem to be increasingly using tempting tricks regarding compensation adjustments, especially regarding bonuses and raises, which are usually decided at the end of the year.

Finally, Cofense warns about fake employee satisfaction surveys and evaluation reports sent to targets by supposed human resources departments.

In one example, the phishing email uses a subject line “employee of the year award” to trick recipients into opening their performance reports, ostensibly to review and sign them.

See also: TeamTNT's Cloud Credential Theft Campaign Now Targets Azure and Google Cloud

New technologies can improve the security of corporate credentials through the use of two-factor authentication. This means that the user must provide two forms of proof of identity before being allowed access to the system

Additionally, artificial intelligence and machine learning technology can be used to detect threats and prevent attacks. These systems can learn from past data and recognize patterns that indicate malicious activity.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, blockchain technology can provide an additional layer of security. By recording every transaction in an immutable and transparent ledger, blockchain makes it difficult for corporate credentials to be forged or stolen.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS