The FBI, State Department and National Security Agency issued a warning about attempts by North Korean state-sponsored cyberthreat actors to exploit improperly configured domain-based message authentication, reporting and conformance record policies to conceal social engineering attempts. Without properly configured DMARC policies, malicious cyber actors are able to send spoofed emails as if they came from a legitimate domain’s email exchange, the advisory states. The cyber actors have conducted spear phishing campaigns posing as journalists, academics or other experts in East Asian affairs with credible links to North Korean policy circles.

“Beyond the threat from North Korea, we have seen all types of nefarious cyber actors exploit improperly configured domain-based message authentication to send hospitals and health systems ‘spoofed’ phishing emails,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “This alert serves as a good reminder to ensure this basic cybersecurity protocol is properly configured to ensure that when the bad guys send staff or our contacts an email that appears to be from (someone known)@(your organization).org it will fail the validation test of DMARC and flagged as suspicious  (someone unknown)@(unknown organization).org. Stay vigilant and up to date on basic cybersecurity protocols and ensure phishing email tests and cyber education continue with staff, as our criminal and nation state adversaries are becoming increasingly aggressive and creative in their social engineering techniques.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
New guidance released yesterday by the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI informs health care and other…
Headline
A joint advisory released Nov. 20 by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency and international partners warns of…
Headline
The Department of Justice Nov. 18 announced criminal charges against Evgenii Ptitsyn, a Russian national, for allegedly administering the sale, distribution…
Headline
A United Nations Security Council meeting the week of Nov. 4 discussed ransomware and the severe impacts that cyberattacks can have on hospitals and health…
Headline
AHA President and CEO Rick Pollack was recently a guest on Pinkston's "To the Point" podcast to discuss the future of U.S. health care, touching on a range of…
Headline
The Cybersecurity and Infrastructure Security Agency, FBI and other federal agencies have created a webpage with the latest cyberthreat updates and information…