Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • 5 Active Malware Campaigns in Early 2025: What You Need to Know
    • 10 Critical Network Pentest Findings IT Teams Overlook
    • Report Phishing Instantly with PhishAlarm
    • Password Reuse Epidemic: Nearly Half of User Logins Compromised
    • Women in Cybersecurity: Interest, Exposure, or Just Stereotypes??
    • Stay Ahead of Scammers in 2025
    • Cybersecurity Alert: Risks of Abandoned Websites
    • DHS Unveils Playbook for the Deployment of Artificial Intelligence for the Public Sector
    Fordham University Information Security and Assurance
    • Information Security and Assurance Homepage
    • Privacy Blog
    • About
    Fordham University Information Security and Assurance
    You are at:Home»News and Events»Compromised FBI Email Server Used to Send Spam Messages
    News and Events

    Compromised FBI Email Server Used to Send Spam Messages

    By Louis PapaNovember 15, 20213 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Copy Link

    Federal Bureau of Investigation email servers were compromised and then used to send fraudulent messages mimicking FBI warnings that the recipient’s systems were breached and data was stolen.

    The emails came from a legitimate FBI email address, eims@ic.fbi.gov. The subject read “Urgent: Threat actor in systems.” All emails came from the FBI’s IP address 153.31.119.142 (mx-east-ic.fbi.gov). This lent a significant amount of credibility to the messages. The body of the message reads:

    Our intelligence monitoring indicates exfiltration of several of your virtualized clusters in a sophisticated chain attack. We tried to blackhole the transit nodes used by this advanced persistent threat actor, however there is a huge chance he will modify his attack with fastflux technologies, which he proxies trough multiple global accelerators. We identified the threat actor to be Vinny Troia, whom is believed to be affiliated with the extortion gang TheDarkOverlord, We highly recommend you to check your systems and IDS monitoring. Beware this threat actor is currently working under inspection of the NCCIC, as we are dependent on some of his intelligence research we can not interfere physically within 4 hours, which could be enough time to cause severe damage to your infrastructure.

    Stay safe,

    U.S. Department of Homeland Security | Cyber Threat Detection and Analysis | Network Analysis Group

    The emails falsely claim that “a sophisticated chain attack” was carried out by Vinny Troia, a security researcher. The spam appears to be an attempt to smear him. Troia has suggested that the spam messages are the work of “pompompurin,” a self-described “threat actor on the internet.” The two have been part of an ongoing feud. “The last time they [pompompurin] hacked the national center for missing children’s we site (sic) blog and put up a post about me being a pedophile,” Troia claimed. A few hours before the spam campaign began, pompompurin contacted Troia with a one word message: “enjoy.”

    According to the FBI, a misconfiguration on the Law Enforcement Enterprise Portal (LEEP) allowed the attacker to send fake emails. The vulnerability was remediated shortly after the FBI became aware of the incident. No data was compromised or PII stolen as a result of this incident.

    If you receive questionable or suspicious emails, contact IT Customer Care and allow the University Information Security Office (UISO) to validate the legitimacy of these emails.

    You may also report potential phishing and malicious emails with one click from your Fordham Gmail safely and in real-time with the Cofense Reporter Gmail add-on. You can learn more about Cofense here: https://itsecurity.blog.fordham.edu/2018/10/04/introducing-cofense-reporter/

    Share this:

    • Click to share on X (Opens in new window) X
    • Click to share on Facebook (Opens in new window) Facebook
    • Click to share on LinkedIn (Opens in new window) LinkedIn

    Like this:

    Like Loading...
    Previous ArticlePhishers Impersonate Proofpoint to Steal O365, Google Passwords
    Next Article Data can be obtained from encrypted messaging apps as shown by a newly discovered FBI document

    Related Posts

    10 Critical Network Pentest Findings IT Teams Overlook

    Cybersecurity Alert: Risks of Abandoned Websites

    What You Need to Know About Emerging Data Privacy Trends in 2025

    Follow Us on Twitter!
    Follow @FordhamSecureIT
    My Tweets
    Archives
    Categories
    • AI (1)
    • Alerts (384)
    • CISO (19)
    • Cyber Security Awareness Month Tip (150)
    • Data Privacy Week (2)
    • Executive Director (1)
    • Exploits and Vulnerabilities (35)
    • General Information (34)
    • Identity and Access Management (12)
    • Identity Theft (26)
    • Jason Benedict (19)
    • Legitimate Email (14)
    • Malicious Email (24)
    • Mobile (25)
    • Network Security (2)
    • News and Events (143)
    • Newsletter (13)
    • Password (17)
    • Phishing (333)
    • Phishing Email (340)
    • Privacy (10)
    • Ransomware (9)
    • Scam (104)
    • Security Awareness (262)
    • Security Guides (34)
    • Social Engineering (12)
    • SPAM (40)
    • Suspicious (6)
    • Telework (2)
    • Teleworking (3)
    • Trojan (7)
    • Uncategorized (9)
    • Virtual Meeting (4)
    • Virus (28)
    • Viruses (8)
    • World Backup Day (1)
    • Zoom (6)
    Tag Cloud
    Alerts Artificial Intelligence Backups cell phones CISO Cybersecurity Awareness Month Tip Cybersecurity Month Data Privacy Device email Exploits and Vulnerabilities fordham fraud Identity and Access Management Identity Theft Information Security Guides Jason Benedict Legitimate Email malicious email Mobile Multi-Factor Authentication networks Network Security News and Events Newsletter online safety Online Shopping Password Phishing Phishing Email Privacy ransomware scam scams Security Awareness social engineering Social Media spam trojan Virus Viruses Wireless wire transfer scam World Backup Day zoom
    About
    About

    Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.

    Copyright © Fordham University
    Facebook X (Twitter) Instagram YouTube LinkedIn
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    %d