IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

FINRA warns of phishing campaign exploiting imposter domain names

The US regulator has requested that domain registrars suspend at least three fraudulent domains

The Financial Industry Regulatory Authority (FINRA) has warned of a new phishing campaign that involves fraudulent emails using domain names pretending to be the financial regulator.

In an advisory, the regulator said that the fake emails used the false domains @finrar-reporting.org, @Finpro-finrar.org and @gateway2-finra.org. The domains were registered on 12 August 2021.

It said that these emails asked recipients to click a link to “view request” and provide information to “complete” that request, noting that “late submission may attract penalties.”

The regulator that anyone who clicked on any link or image in the email should immediately notify the appropriate individuals in their firm of the incident.

“None of these domain names are connected to FINRA and firms should delete all emails originating from any of these domain names,” it said in the advisory.

FINRA also urged any companies receiving such messages to verify the legitimacy of any suspicious email before responding, opening any attachments, or clicking on any embedded links. It has requested that the relevant Internet domain registrars suspend services for all three domain names.

"For more information, firms should review the resources provided on FINRA’s Cyber Security Topic Page, including the Phishing section of our Report on Cybersecurity Practices - 2018," FINRA added.

Related Resource

Prevent fraud and phishing attacks with DMARC

How to use domain-based message authentication, reporting, and conformance for email security

Prevent fraud and phishing attacks with DMARC - whitepaper from MimecastFree download

Earlier in June, FINRA published another advisory warning of similar phishing campaign using the domain name “@gateway-finra.org.” Like the present campaign, this one also asked recipients to click a link to “view request” and provide information to “complete” that request, noting that “late submission may attract penalties.”

In March, the regulator issued an advisory about a phishing campaign using “@finra-online.com” as a fake domain name to catch victims unawares. It said at the time that this domain name was “not connected to FINRA and firms should delete all emails originating from this domain name”.

Finra isn’t the only regulator to be targeted by phishers recently, as the Cyprus Securities and Exchange Commission (CySEC) recently issued a warning about a fake website impersonating them and hosted in India.

Featured Resources

Defending against malware attacks starts here

The ultimate guide to building your malware defence strategy

Free Download

Datto SMB cyber security for MSPs report

A world of opportunity for MSPs

Free Download

The essential guide to preventing ransomware attacks

Vital tips and guidelines to protect your business using ZTNA and SSE

Free Download

Medium businesses: Fuelling the UK’s economic engine

A Connected Thinking report

Free Download

Recommended

Microsoft Security Copilot could be a seismic success for the tech industry
Security

Microsoft Security Copilot could be a seismic success for the tech industry

29 Mar 2023
Enabling secure hybrid learning
Whitepaper

Enabling secure hybrid learning

22 Mar 2023
SOC modernisation and and the role of XDR
Whitepaper

SOC modernisation and and the role of XDR

16 Mar 2023
Analysing the economic benefits of Trend Micro Vision One
Whitepaper

Analysing the economic benefits of Trend Micro Vision One

16 Mar 2023

Most Popular

Getting the best value from your remote support software
Advertisement Feature

Getting the best value from your remote support software

13 Mar 2023
What the UK can learn from the rest of the world when it comes to the shift to IP
Sponsored

What the UK can learn from the rest of the world when it comes to the shift to IP

20 Mar 2023
Why the floppy disk may never die
Server & storage

Why the floppy disk may never die

27 Mar 2023