Idaho Official Government Website
|
|

Financial Scams Targeting Idaho

Laptop with viruses

Over the last couple months, ITS has noticed an increase in scam emails attempting to steal money from state agencies. The targets are often billable accounts, payroll, and employee direct deposits. To help state employees respond, we will walk through how these emails work at a high level and what to do if you receive one.

Set-up

  • Employee gets an email from a coworker about a vendor.
  • The vendor account needs to be moved to a new account.
  • Vendor is demanding payment because the agency has not made a request to change.
  • Message shows an email chain between vendor and coworker showing a late payment.
  • Coworker has admitted delayed payment is their fault. 
Rendering of alert logo on laptop computer.

Scam

  • Attacker is faking (spoofing) coworker’s email and has created a fake set of “historical” emails creating a false sense of urgency.
  • Example, they are trying to get employee to obtain banking information and pay them. 
  • Attacker may also fake a known vendor name and logo, or it may create a fictional vendor name or logo. 
  • In other cases, attackers may also target payroll and employee accounts.

How to spot the attack

  • Email looks out of place due to its contents, language, and style.
  • Email may not follow agency templates or details.
  • Message will be written requesting an urgent response.

What to do if you get a suspicious email?

Step 1. Report suspicious email.

  • Submit email as suspicious by using your agency’s phishing or malicious email procedures.
  • Immediate action may be required.

Step 2. Contact coworker.

  • Don’t reply to suspicious email.
  • Verify the request directly by contacting your coworker:
    • In person
    • By phone
    • Via video call (preferred, since you can see and hear them)
  • If those options aren’t available, start a new email instead of replying to suspicious one.
  • Act quickly. Your coworker can confirm whether they sent the message and take action if their identity is being spoofed.
  • Remember that multiple employees may have received the same spoofed email, so reporting it promptly helps protect others.

Step 3. Update initial notification.

  • If you talk with your coworker in person and trust their response, update the responders on the situation. 
  • For ITS directly supported agencies, please identify the email as suspicious, submit the email by using the Phish Alert button in Outlook.

For additional information:

https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/spoofing-and-phishing

Feedback