← All regulatory updates

New York State Department of Financial Services · NY

Cybersecurity Threat Alert – Social Engineering of Institutions’ IT Help Desk Personnel

September 27, 2024

Summary

The New York State Department of Financial Services has issued an alert regarding a rise in social engineering attacks targeting IT help desks and call centers. Threat actors are utilizing voice-altering technology and publicly available information to trick staff into resetting passwords and compromising multi-factor authentication (MFA) credentials.

Industry Letter


Date: September 27, 2024

To: All DFS-Regulated Entities

Re: Cybersecurity Threat Alert – Social Engineering of Institutions’ IT Help Desk Personnel

The New York State Department of Financial Services (DFS) alerts all regulated entities to take immediate action to thwart a cybersecurity threat currently being used to gain unauthorized access to information systems. DFS has seen evidence that threat actors are targeting IT help desks and call centers using, among other tactics, voice-altering technology in conjunction with information obtained on the internet about the identities of personnel to convince help desks to reset passwords and divert multi-factor authentication (MFA) to new devices.

In light of these risks, DFS-regulated entities must be on high alert for suspicious communications, especially via phone, and implement secure controls to prevent threat actors from easily changing passwords and intercepting SMS text or messaging applications to obtain MFA. IT and help desk personnel in particular must remain cautious of individuals or vendors requesting support related to accessing information systems.

Please alert personnel, especially those staffing help desks and call centers, about these potential social engineering attempts and ensure they are especially diligent in authenticating the identity of anyone requesting changes in authentication factors.

For further details and best practices, please refer to the U.S. Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) guidelines on avoiding social engineering and phishing attacks: Avoiding Social Engineering and Phishing Attacks | CISA.

Source: https://www.dfs.ny.gov/industry-guidance/industry-letters/il20240927-cyber-alert-social-engineering

Common questions

What does "Cybersecurity Threat Alert – Social Engineering of Institutions’ IT Help Desk Personnel" cover?
The New York State Department of Financial Services has issued an alert regarding a rise in social engineering attacks targeting IT help desks and call…
Which agency issued this update?
This update was issued by New York State Department of Financial Services.
When was it published?
It was published on September 27, 2024.

Get the free weekly digest

Every mortgage regulatory change, summarized, in your inbox. No account needed.

Related updates