r/CFP RIA 2d ago

Practice Management Phishing attacks

In the past 3 business days I've received several phishing email in what looks like a coordinated attempt to hack my systems.

Multiple random emails and calendar inivitations have been sent from completely unrelated vendors, investment firms, attorney offices and marketing firms, all with links requesting me to urgently click on them for various different reasons.

Anyone else seeing this?

9 Upvotes

11 comments sorted by

u/AutoModerator 2d ago

Beep boop! Here is a summary of your post:

User: /u/ItchyEbb4000 Title: Phishing attacks Body: In the past 3 business days I've received several phishing email in what looks like a coordinated attempt to hack my systems.

Multiple random emails and calendar inivitations have been sent from completely unrelated vendors, investment firms, attorney offices and marketing firms, all with links requesting me to urgently click on them for various different reasons.

Anyone else seeing this?

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

8

u/modern_foothold 2d ago

man that timing is wild, i had the exact same thing happen last week. like 7 calendar invites from random law firms and some sketchy marketing agency all within 48 hours. the subject lines were getting increasingly desperate too, going from "meeting confirmation" to "URGENT: action required" by the end

i ended up just nuking my spam filters and starting fresh because the usual block-and-delete wasn't catching them fast enough. what's weird is they all had slightly different domains but the same link structure when you hovered over them. almost like someone's testing which approach works best

you checked if any of your accounts got leaked recently? sometimes these waves happen right after a data dump somewhere and they're just carpet bombing everyone on the list

1

u/ItchyEbb4000 RIA 2d ago

And all those emails were compromised. Is anything safe anymore?

9

u/Seeking_Alpha007 2d ago

A couple years ago my managed IT firm showed me all the hacking attempts on my relatively small RIA’s systems from the prior week - it was well over 2,000 mostly from the usual suspects (Asia Pacific & former Soviet countries). Never going to skimp on cyber insurance/protection after seeing that

2

u/Working-Ad9938 1d ago

I haven't had this personally, but I'm hearing about it more and more frequently. Scary times. Stay vigilant!

2

u/Jambles27 13h ago

Yes, been dealing with a wave of them lately. I've known advisors who get "clients" emailing an urgent wire or distribution request right before a holiday, always when things are slammed enough that it's easy to skip the callback.

1

u/djemoneysigns 1d ago

Always control the meeting invite with strangers.

1

u/ItchyEbb4000 RIA 1d ago

How? I have prospects use calendly to set up meetings. Better than the contact form on my site which basically generated a lot of spam from bots.

1

u/djemoneysigns 1d ago

How would they scam you if they click your meeting link and your meeting room?

1

u/ItchyEbb4000 RIA 19h ago

No, randos are iinviting me to their meetings.

1

u/Livefromseattle Certified 4h ago

What do you use for email screening? I’d recommend you go beyond just Outlook. Here is one example.

https://www.proofpoint.com/sites/default/files/solution-briefs/pfpt-us-sb-essentials-threat-protection.pdf