Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Latest SBA phishing attempt: stealthy social engineering phish using newly registered domains attempts to gain bank details

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Elaine Dzuba
Word Count
1,471
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cyber criminals are exploiting the confusion surrounding the US Small Business Administration's (SBA) loan application procedures amidst the pandemic by impersonating the SBA in Coronavirus-themed phishing messages. These attacks involve a clever social engineering tactic that can fly under almost any radar, with malicious actors opting for a silent attack vector relying on targets believing the email is indeed from the SBA. The latest wave of attacks does not contain any malicious payloads but only a benign attachment named SBA - Disaster Loan Assistance Form.pdf. To thwart these sneaky SBA-themed phish, Area 1 Security uses multiple advanced techniques that leverage insight gained from early identification of attacker campaign infrastructure, enabling superior detection of emails from spoofed domains and accounts.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 2 629 236 77 +1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.