A California man along with his teammates targeted the United States Department of Defense in a sophisticated phishing attack.
The crew scammed the Dod vendors by sending emails and presenting them with a lookalike login page of GSA and capturing their login credentials and hacking their accounts and routing payments to the shell entity they had set up for the attack.
The attackers apparently collected about $23.5 million in payments from DoD before the scam and all the conspirators were put behind the bar.
TPRM report: https://scoringcyber.rankiteo.com/company/deptofdefense
"id": "uni141212522",
"linkid": "deptofdefense",
"type": "Cyber Attack",
"date": "10/2018",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of a geographical region"
{'affected_entities': [{'industry': 'Defense',
'location': 'United States',
'name': 'United States Department of Defense',
'type': 'Government'}],
'attack_vector': 'Email and fake login page',
'data_breach': {'type_of_data_compromised': 'Login credentials'},
'description': 'A California man along with his teammates targeted the United '
'States Department of Defense in a sophisticated phishing '
'attack. The crew scammed the Dod vendors by sending emails '
'and presenting them with a lookalike login page of GSA and '
'capturing their login credentials and hacking their accounts '
'and routing payments to the shell entity they had set up for '
'the attack. The attackers apparently collected about $23.5 '
'million in payments from DoD before the scam and all the '
'conspirators were put behind the bar.',
'impact': {'data_compromised': 'Login credentials',
'financial_loss': '$23.5 million'},
'initial_access_broker': {'entry_point': 'Email',
'high_value_targets': 'Vendors of DoD'},
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': 'Human vulnerability to phishing '
'attacks'},
'threat_actor': 'A California man and his teammates',
'title': 'Phishing Attack on United States Department of Defense',
'type': 'Phishing',
'vulnerability_exploited': 'Human vulnerability through phishing'}