FBI Issues Warning to Election and Other Officials About Login Harvesting Scheme

March 30, 2022 by Dan McCue
FBI Issues Warning to Election and Other Officials About Login Harvesting Scheme
Election workers inspect ballots that have been received for the Sept. 14, 2021, recall election, for damage at the Sacramento County Registrar of Voters office in Sacramento, Calif., Aug. 30, 2021. A California Legislative committee advanced a bill on Monday, March, 28, 2022, that would add some election workers to the state's "Safe at Home" program that lets some people to keep their physical addresses secret. State Sen. Josh Newman, a Democrat from Fullerton, Calif., said election workers have faced threats and intimidation following the 2020 presidential election. (AP Photo/Rich Pedroncelli, File) THE ASSOCIATED PRESS

WASHINGTON — The Federal Bureau of Investigation issued a warning to election and other state and local government officials about invoice-themed phishing emails that could be used to harvest officials’ login information.

If successful, the agency warned in a “Private Industry Notification” released Thursday, “this activity may provide cyber actors with sustained, undetected access to a victim’s systems.”

The notification says that on Oct. 5, 2021, U.S. election officials in at least nine states and representatives of the National Association of Secretaries of State received invoice-themed phishing emails containing links to websites intended to steal login credentials. 

These emails shared similar attachment files, used compromised email addresses, and were sent close in time, suggesting a concerted effort to target U.S. election officials. 

These emails originated from at least two email addresses with the same attachment titled, “INVOICE INQUIRY.PDF,” which redirected users to a credential-harvesting website. 

One of the email addresses sending the phishing emails was a compromised U.S. government official’s email account.  

Then on Oct. 18, 2021, cyber actors used two email addresses, purportedly from U.S. businesses, to send phishing emails to county election employees. 

Both emails contained Microsoft Word document attachments regarding invoices, which redirected users to unidentified online credential-harvesting websites.  

The following day, cyber actors used an email address, purportedly from a U.S. business, to send a phishing email containing fake invoices to an election official. 

The emails contained an attached Microsoft Word document titled, “Current Invoice and Payments for report.” 

“The FBI judges cyber actors will likely continue or increase their targeting of U.S. election officials with phishing campaigns in the lead-up to the 2022 U.S. midterm elections,” the notification says. 

“Proactive monitoring of election infrastructure (including official email accounts) and communication between FBI and its state, local, territorial and tribal partners about this type of activity will provide opportunities to mitigate instances of credential harvesting and compromise, identify potential targets and information sought by threat actors and identify threat actors,” it says.

The FBI is recommending that network defenders take a number of steps to reduce the risk of compromise.

These include educating employees on how to identify phishing, spear-phishing, social engineering and spoofing attempts. The agency also recommends advising employees to be cautious when providing sensitive information — such as login credentials — electronically or over the phone, particularly if unsolicited or anomalous.

“Employees should confirm, if possible, requests for sensitive information through secondary channels,” the notification says.

According to the FBI, elections and other government offices should create protocols for employees to send suspicious emails to IT departments for confirmation.  

They should also:

  • Mark external emails with a banner denoting the email is from an external source to assist users in detecting spoofed emails.  
  • Enable strong spam filters to prevent phishing emails from reaching end users. Filter emails containing executable files from reaching end users.
  • Advise training personnel not to open email attachments from senders they do not recognize.
  • Require all accounts with password logins (e.g., service accounts, admin accounts and domain admin accounts) to have strong, unique passphrases. 
  • Passphrases should not be reused across multiple accounts or stored on the system where an adversary may have access. (Note: Devices with local administrative accounts should implement a password policy that requires strong, unique passwords for each administrative account.)  
  • Require multi-factor authentication for all services to the extent possible, particularly for webmail, virtual private networks and accounts that access critical systems. 
  • If there is evidence of system or network compromise, implement mandatory passphrase changes for all affected accounts. 

The FBI also recommends keeping all operating systems and software up to date. 

“Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats,” the notification says.

Dan can be reached at [email protected] and at https://twitter.com/DanMcCue

A+
a-
  • cybercrime
  • Election Officials
  • elections
  • FBI
  • hacking
  • login
  • phishing
  • In The News

    Health

    Voting

    Cybercrime

    April 29, 2025
    by Tom Ramstack
    FBI Reports Sharp Increase in American Cybercrime Victims

    WASHINGTON — The FBI’s new Internet Crime Report released last week shows Americans lost $16.6 billion to cybercrime in 2024... Read More

    WASHINGTON — The FBI’s new Internet Crime Report released last week shows Americans lost $16.6 billion to cybercrime in 2024 despite an intensified government effort to stop it. The losses were up by one-third from a year earlier.  Fraud was the most common crime, particularly among... Read More

    March 10, 2025
    by Dan McCue
    Cyberattack Puts X on Ice as Social Media Platform Suffers Multiple Outages

    WASHINGTON — If at first you don’t succeed, hit retry and retry and retry again. That was the message from... Read More

    WASHINGTON — If at first you don’t succeed, hit retry and retry and retry again. That was the message from Elon Musk’s X as the social media platform experienced multiple outages on Monday. Musk attributed the outages to a "massive" and unusual cyberattack. “We get attacked... Read More

    The US and Microsoft Disrupt a Russian Hacking Group Targeting American Officials and Nonprofits

    WASHINGTON (AP) — A hacking group tied to Russian intelligence tried to worm its way into the systems of dozens... Read More

    WASHINGTON (AP) — A hacking group tied to Russian intelligence tried to worm its way into the systems of dozens of Western think tanks, journalists and former military and intelligence officials, Microsoft and U.S. authorities said Thursday. The group, known as Star Blizzard to cyberespionage experts,... Read More

    June 24, 2024
    by Tom Ramstack
    Russian Software Company Sanctioned as US Warns of Espionage Threat

    WASHINGTON — The U.S. Treasury Department on Friday sanctioned a Russian software company that sells antivirus and cybersecurity software in... Read More

    WASHINGTON — The U.S. Treasury Department on Friday sanctioned a Russian software company that sells antivirus and cybersecurity software in the United States, some of it to government agencies. The Treasury Department said it found links between Kaspersky Lab and the Russian military indicating the software... Read More

    October 7, 2023
    by Dan McCue
    Hackers Access DC Voter Records

    WASHINGTON — Hackers breached the District of Columbia's Board of Elections website on Thursday, gaining access to 600,000 "lines" of... Read More

    WASHINGTON — Hackers breached the District of Columbia's Board of Elections website on Thursday, gaining access to 600,000 "lines" of U.S. voter data, including D.C. voters reports, city officials said. Sarah Winn Graham, the spokeswoman for the board, said a hacking group known as RansomVC claimed... Read More

    July 18, 2023
    by Tom Ramstack
    Congress Told AI Holds Great Risks and Benefits for US Military

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it... Read More

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it falls behind in developing the technology but a bright future by taking the lead. One of the greatest risks would be defending against a foreign enemy... Read More

    News From The Well
    scroll top