Slashdot Mirror


Fake Subpoenas Sent To CEOs For Social Engineering

An anonymous reader writes "The Internet Storm Center notes that emails that look like subpoenas are being sent out to the CEOs of major US corporations. The email tries to entice the victim to click on a link for 'more information.' According to the ISC's John Bambenek: 'We've gotten a few reports that some CEOs have received what purports to be a federal subpoena via email ordering their testimony in a case. It then asks them to click a link and download the case history and associated information. One problem, it's [totally] bogus. It's a "click-the-link-for-malware" typical spammer stunt. So, first and foremost, don't click on such links. An interesting component of this scam was that it did properly identify the CEO and send it to his email directly. It's very highly targeted that way.'"

11 of 112 comments (clear)

  1. Re:You already have real problems. by Anonymous Coward · · Score: 4, Informative

    CEOs should know better anyway. Start of process is with your registered agent, not your email address.

  2. Re:Subpoena by *email* ?? by WaltBusterkeys · · Score: 4, Informative

    Stranger things have happened, especially in cases where the events took place online. Normally you're right that service has to be done in person or by US mail.

    BUT, if the only known way to contact a defendant or witness is by email (if, for example, their real names or addresses are unknown), then a court can authorize that as an alternative form of service. It's up to the court to decide if email would give sufficient notice and other means are impractical.

    Here, of course, there's no reason to think that sending certified mail or a process server wouldn't work -- a corporate CEO isn't hard to find and service on a company can almost always be done through the state's secretary of state.

    But, that doesn't mean that electronic subpoenas are never possible, as you suggest.

  3. CEOs read email? by Anonymous Coward · · Score: 1, Informative

    Most I know, the secretaries read it, print it and then file the copies.

  4. Re:I have been saying this... by Digi-John · · Score: 4, Informative

    The real danger lies elsewhere. Stories like this and the cyber-war story about the US and China are the ones that you need to follow and think about.

    It looks a lot like the butterfly effect http://en.wikipedia.org/wiki/Butterfly_effect in the fact that one small chance encounter or small piece of information can greatly affect the outcome of a particular chain of events. Your company makes cheeseburger boxes for a company whose CEO, in turn, is a friend of or associate of some political figure. This information is gleened from your system via email, and phishing email is used to get that political figure to open an email which is a dupe of a previous email sent, but contains an active-x payload... this in turn leads to more serious and useful information down the road... and viola! you have enough for a hack on the RNC mail server...

    That is how spying works, a little bit at a time, patiently looking for a chink in the armor.

    Reminds me of the information security training I had to take before starting my job here at a national lab. First, we watched a video in which an ex-KGB boss who now provides security consulting worldwide says, "Do not think that because you are low-ranking or do not work with classified information, that you are not a potential target for espionage" and goes on to tell us how almost certainly at least a few of the people we work with have been or will be targeted for espionage or potential defection. Then we were told how several pieces of non-classified information can be put together to create classified information, even unintentionally.

    Even if you don't work for the government, you have to be really careful if you want your data to be secure.

    --
    Klingon programs don't timeshare, they battle for supremacy.
  5. Re:Boss got this yesterday by XHIIHIIHX · · Score: 2, Informative

    I wonder... Is there some "hacker code" out there that says if you are sending out a phishing email - you must misspell Yes there is. By mispelling [sic pun] a few words, you can confuse anti-spam filters that are looking for duplicate mass mailed documents or for specific words. Typical spamming programs will allow you to insert random chars (replace 1, l or ! for I) or will substitute some automatically.
  6. I was hit by it... by npal · · Score: 5, Informative

    I saw it on my Treo and it looked very real - at first. There were four issues: It was a Federal subpoena but it mentioned a "city prosecutor" down towards the end. This started some suspicion.
    Then I noticed that it was a grand jury for a civil trial. So I'm wondering, do they use grand jury's for civil trials? It was in California, so I thought maybe they somehow did. Then, I could see that they wanted a credit card to get the information. Big red flag, but it used pricing by the page - so I thought only the government could dream up something like this and maybe it was legit. Finally, the domain name for the link to the credit card page looked okay, but it was phony.

    All and all, I'll bet a number of people fell for it because the targeting was so good.

  7. Re:Subpoena by *email* ?? by WaltBusterkeys · · Score: 5, Informative
    Sure, here's an example of service by email:

    Plaintiffs Tishman and Wilkinson filed a lawsuit against defendant Pine, but had difficulty serving Pine with the summons. The plaintiffs tried the conventional methods of service under New York law, such as personal delivery. They even tried the "nailing and mailing" method by affixing a copy of the summons to the door of Pine's residence, then sending a copy in the mail.

    Tishman and Wilkinson had information, however, that led them to believe Pine was out of the country. . . They petitioned the court for permission to serve Pine by e-mail, pursuant to N.Y. C.P.L.R. Â308(5), which allows service by such manner as the court directs, when the more conventional methods are "impracticable."

    The court allowed service of the summons to an e-mail address Pine had used in a classified ad listing his house for sale. The court held that given the uncertainty about the success of the attempted "nailing and mailing" effort, and the fact that the Pine's attorneys wouldn't give a clear answer as to where Pine was living, alternative service by e-mail was appropriate.


    Most states have similar laws that allow service by any practical means if conventional methods fail.
  8. Re:Subpoena by *email* ?? by davidphogan74 · · Score: 2, Informative

    I received one from the a California state organization about 3 years ago due to a lack of other ways to locate me and give me a written notice. The written notice had no external links whatsoever, and simply asked me to contact them regarding the matter and included a PDF of the subpoena itself, along with corroborating evidence that would relate to it.

    A few phone calls and cross-checks with other resources later, it turned out to be valid.

  9. Re:Hmmm.... by iNaya · · Score: 3, Informative

    Pity his email is actually billg@microsoft.com

    --
    The Unicode standard is over 20 years old. Why does Slashdot not support it?
  10. Re:Boss got this yesterday by XHIIHIIHX · · Score: 2, Informative

    Which doesn't matter if it doesn't get to the user in the first place.

  11. Re:Subpoena by *email* ?? by Anonymous Coward · · Score: 1, Informative
    I received one of these e-mails. It was well targeted in that it got my information correct. However, other than that, it had every hallmark of spam. Links coming from the ".com" version of a ".gov" domain, e-mail from a source that wasn't what it purported to be, and the subject matter (a supeona) coming via e-mail instead of by Sheriff or Lawyer. It was also not caught by our spam filters.

    One problem that I've noticed is that muckity-mucks often feel that they're "above" being targeted by such menial things as malware. Us "Muckity-Mucks" are targeted by more malware, spam, telemarketing than any of you "little people" (tongue in cheek). Our names are on public registers and documents and those get picked up all the time. I get dozens of solicitation calls each week, piles of "official" scam letters in the mail, and hundreds of e-mail messages. This is to say nothing of the "important" faxes we receive. We are used to dealing with this junk.