The NJCCIC has been receiving reports of phishing campaigns with various lures targeting New Jersey private- and public-sector organizations, including local governments and educational institutions. Threat actors use phishing as a prevalent initial attack vector by convincing their targets to click links, open attachments, download malware, or divulge sensitive information, including account credentials. Phishing can have substantial impacts on an organization.
Once threat actors gain unauthorized access, they impersonate the legitimate user and send emails internally and externally on the victim’s behalf. They can also infiltrate the organization, gain access to internal systems, move laterally to other critical systems, and conduct other malicious cyber activity, such as data exfiltration and ransomware. Once they exfiltrate data, they encrypt systems and servers, shutting down access to essential services and files containing personally identifiable information (PII) and financial information.
Therefore, all users and organizations are highly recommended to practice good cyber hygiene, remain vigilant, and protect information.
Recommendations
- Exercise caution with unexpected or unsolicited communications, including those from known senders or legitimate services or platforms.
- Confirm requests from senders using contact information obtained from verified, official sources before taking action, such as clicking links or opening attachments.
- Navigate directly to legitimate websites and verify before submitting account credentials, providing personal or financial information, or downloading files.
- Refrain from clicking on or contacting unknown telephone numbers found in messages or alerts.
- Avoid downloading software at the request of unknown individuals, and refrain from granting remote access, divulging sensitive information, or providing funds.
- Enable multi-factor authentication (MFA) and keep systems and browsers up to date.
- If you suspect your device is infected, disconnect from the internet, run anti-virus/anti-malware scans, and review your security and privacy settings. A full system reimage may be warranted to restore the compromised device.
- If sensitive information was entered, change passwords for compromised accounts, notify financial institutions of fraudulent transactions, monitor for unauthorized activity, and review the Identity Theft and Compromised PII NJCCIC Informational Report for additional recommendations and resources.

