New York State Department of Financial Services · NY
Cybersecurity Threat Alert – Social Engineering of Institutions’ IT Help Desk Personnel
September 27, 2024
Summary
The New York State Department of Financial Services has issued an alert regarding a rise in social engineering attacks targeting IT help desks and call centers. Threat actors are utilizing voice-altering technology and publicly available information to trick staff into resetting passwords and compromising multi-factor authentication (MFA) credentials.
Industry Letter
Date: September 27, 2024
To: All DFS-Regulated Entities
Re: Cybersecurity Threat Alert – Social Engineering of Institutions’ IT Help Desk Personnel
The New York State Department of Financial Services (DFS) alerts all regulated entities to take immediate action to thwart a cybersecurity threat currently being used to gain unauthorized access to information systems. DFS has seen evidence that threat actors are targeting IT help desks and call centers using, among other tactics, voice-altering technology in conjunction with information obtained on the internet about the identities of personnel to convince help desks to reset passwords and divert multi-factor authentication (MFA) to new devices.
In light of these risks, DFS-regulated entities must be on high alert for suspicious communications, especially via phone, and implement secure controls to prevent threat actors from easily changing passwords and intercepting SMS text or messaging applications to obtain MFA. IT and help desk personnel in particular must remain cautious of individuals or vendors requesting support related to accessing information systems.
Please alert personnel, especially those staffing help desks and call centers, about these potential social engineering attempts and ensure they are especially diligent in authenticating the identity of anyone requesting changes in authentication factors.
For further details and best practices, please refer to the U.S. Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) guidelines on avoiding social engineering and phishing attacks: Avoiding Social Engineering and Phishing Attacks | CISA.
Source: https://www.dfs.ny.gov/industry-guidance/industry-letters/il20240927-cyber-alert-social-engineering
Common questions
- What does "Cybersecurity Threat Alert – Social Engineering of Institutions’ IT Help Desk Personnel" cover?
- The New York State Department of Financial Services has issued an alert regarding a rise in social engineering attacks targeting IT help desks and call…
- Which agency issued this update?
- This update was issued by New York State Department of Financial Services.
- When was it published?
- It was published on September 27, 2024.
Related updates
- Lakeview Loan Servicing, LLC, Pingora Loan Servicing, LLC, Community Loan Servicing, LLC, and Bayview Asset Management, LLC Multistate Settlement Agreement and Consent Order issued by the Division of Banking
- Pionex, Inc. Consent Order issued by the Division of Banking
- Two Ocean No-Action Letter: Digital Asset Custody & Qualified Custodian Status
- Ultralight FS,. Inc., formerly known as Obopay, Inc., also doing business as Obopay USA
- Updated Nonbank Ransomware Self-Assessment Tool (R-SAT)
- ACI Payments, Inc. Settlement Agreement and Consent Order issued by the Division of Banking