An apparently malicious hacker sent spam emails from an FBI email server Friday night to at least 100,000 people, an email spam watchdog group has found.

The person’s motives are unknown, and it was not immediately clear the extent to which the hacker gained access to the FBI’s email system. The email message was a bizarre, technically incoherent warning that made reference to cybersecurity writer Vinny Troia as well as a cybercriminal group called The Dark Overlord. Troia’s company, Night Lion Security, published research on The Dark Overlord in January.

The email’s author signed off by falsely claiming to be affiliated with the Department of Homeland Security.

The FBI routinely warns American companies of cyber threats targeting particular industries, or when they learn of malicious hackers trying an effective new technique. This is believed to be the first known case of a seemingly malicious actor gaining access to one of those systems to send spam to a large number of people.

The incident comes on the heels of a number of high-profile breaches of U.S. government networks in recent months, including a Russia-based attack that compromised at least nine federal agencies, and a Chinese-based hacking campaign so severe that the Cybersecurity and Infrastructure Security Agency had to issue a rare mandate for all government agencies to immediately update their software.

While it’s common for scammers to make it appear that they’re sending an email from someone else’s address, the emails’ metadata made it clear that they were sent from an FBI server, said Alex Grosjean, a researcher at the Spamhaus Project, a European nonprofit that monitors email spam.

The recipients of the emails appear to be the publicly listed administrators of websites listed on the American Registry for Internet Numbers, Grosjean said.

In an emailed statement, the FBI and Cybersecurity and Infrastructure Security Agency said they were aware of the fake emails sent from the FBI account, but declined to share more information.

“The FBI and CISA are aware of the incident this morning involving fake emails from an @ic.fbi.gov email account,” the statement said. “This is an ongoing situation and we are not able to provide any additional information at this time. We continue to encourage the public to be cautious of unknown senders and urge you to report suspicious activity to www.ic3.gov or www.cisa.gov.”


Source: | This article originally belongs to Nbcnews.com

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Cooling Demand for Goods Threatens to Turn Pandemic Boom Into Bust

Factories around the world are reporting weakening demand for their products, a…

As food prices increase, store brands may have an advantage

Shoppers who want to keep their grocery bills under control or even…

Politicians target LGBTQ kids in national erasure campaign from classrooms to sports fields

Students have repeatedly vandalized Pride posters at Spencer Lyst’s high school in…

Are Taxpayers on the Hook for SVB and Signature Deposits?

Markets Finance U.S. regulators’ guarantee prompts questions about whether taxpayer funds are…