Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Crypto gaming scams alert: Philippines police warn of millions at risk as fraudulent play-to-earn schemes surge

    TL;DR Breakdown Philippines’ National Police warns of play-to-earn (P2E) gaming scams, with custom-created apps stealing millions in crypto. The police bulletin highlights both legitimate platforms like Axie Infinity and risks such as market volatility and unsupported wallets. The warning calls attention to the need for regulation and education in P2E gaming, emphasizing the thin line between legitimate games and fraud. Description The National Police Anti-Cybercrime Group (PNP ACG) of the Philippines has warned residents about the risks associated with play-to-earn (P2E) games, revealing that these platforms can be used to steal crypto assets worth millions of dollars. The cybercrime unit’s latest bulletin highlighted the theft of unsuspecting victims’ crypto assets through custom-created gaming apps, luring victims … Read more The National Police Anti-Cybercrime Group (PNP ACG) of the Philippines has warned residents about the risks associated with play-to-earn (P2E) games, revealing that these platforms can be used to steal crypto assets worth millions of dollars. The cybercrime unit’s latest bulletin highlighted the theft of unsuspecting victims’ crypto assets through custom-created gaming apps, luring victims with promises of substantial financial rewards….

    Article 2023年8月20日
  • Floki Inu token sees surge in trading volumes amid China-focused expansion of Valhalla Metaverse game

    TL;DR Breakdown Floki Inu (FLOKI) experiences a surge in trading volumes and attracts new Chinese traders amid its expansion plans for the Valhalla Metaverse game. Ads featured in Chinese sporting tournaments contribute to the increased interest in Floki Inu, with trading volumes exceeding $99 million. Hong Kong’s upcoming crypto legalization fuels speculation of wealthy Chinese speculators entering the cryptocurrency markets, potentially driving the next crypto bull run. Floki Inu (FLOKI), a token inspired by the popular Shiba Inu dog breed, witnessed a remarkable surge in trading volumes, with a staggering 232.83% increase on Monday. This surge marks the highest level of trading activity seen in over three weeks for the cryptocurrency. The renewed interest in Floki Inu can be attributed to its expansion plans in China, particularly its Valhalla Metaverse game. Trading volumes for the tokens surpassed $99 million, significantly surpassing the previous week’s average of $25 million. Chinese sporting tournament ads drive speculation of new traders The recent surge in interest for Floki Inu tokens can be attributed to the exposure gained through the advertisement of the Valhalla Metaverse…

    Article 2023年6月1日
  • Everything to know about GTA 6 Play-to-Earn

    TL;DR Breakdown Grand Theft Auto 6 (GTA 6) is anticipated to introduce a play-to-earn system using cryptocurrency rewards, transforming gaming into a potential income source. The rumors suggest Bitcoin might be integrated as an in-game payment method and reward token. As the global gaming landscape continues to evolve, one forthcoming release is causing ripples of anticipation throughout the industry. The Grand Theft Auto (GTA) series is no stranger to innovation and groundbreaking features. The next iteration, GTA 6, is poised to take a quantum leap in game design and player rewards, embracing the crypto revolution. As the excitement builds up, let’s dive deep into this thrilling development in our favorite open-world action adventure. Driving digital rewards in GTA 6 Reports suggest that GTA 6 is set to join the burgeoning play-to-earn gaming landscape by integrating cryptocurrency rewards. This move would mark a monumental upgrade from its successful predecessor, GTA 5. Based on the leaks circulating on the Internet, the new game could provide players with an added incentive to engage by offering them a chance to earn and trade in-game…

    Article 2023年5月28日
  • Chinese bank launches CBDC-powered settlement service for bulk commodity spot clearing

    TL;DR Breakdown Industrial Bank pioneers China’s first commodity spot clearing digital RMB settlement service, integrating digital yuan into commodity trading scenarios. Chinese banks embrace digital yuan adoption in various operations, with seven other banks planning to offer similar services. The Central People’s Bank of China welcomes regional banks into its pilot, signaling the nation’s commitment to a secure and efficient digital future for financial transactions. Description In a significant move towards embracing the digital yuan, Industrial Bank, a Fuzhou-based joint-stock commercial bank, has introduced the country’s inaugural central bank digital currency (CBDC)-powered settlement service for bulk commodity spot clearing. The initiative carried out in collaboration with the Shanghai Clearing House, marks a milestone in the adoption of the digital yuan in … Read more In a significant move towards embracing the digital yuan, Industrial Bank, a Fuzhou-based joint-stock commercial bank, has introduced the country’s inaugural central bank digital currency (CBDC)-powered settlement service for bulk commodity spot clearing. The initiative carried out in collaboration with the Shanghai Clearing House, marks a milestone in the adoption of the digital yuan in the…

    Article 2023年7月27日
  • Chainlink launches cross-chain protocol on its mainnet

    TL;DR Breakdown Chainlink has announced the launch of its cross-chain protocol on its mainnet. CCIP is hailed as a game changer that will impact the Defi sector. Description Chainlink, a dominant data oracle provider, has unveiled its Cross-Chain Interoperability Protocol (CCIP) on the Mainnet, marking a significant milestone in the blockchain and decentralized finance (DeFi) landscape. With early access support for Avalanche, Ethereum, Optimism, and Polygon (MATIC) networks, CCIP has already garnered adoption from major DeFi lending protocols like Aave and Synthetix. Chainlink … Read more Chainlink, a dominant data oracle provider, has unveiled its Cross-Chain Interoperability Protocol (CCIP) on the Mainnet, marking a significant milestone in the blockchain and decentralized finance (DeFi) landscape. With early access support for Avalanche, Ethereum, Optimism, and Polygon (MATIC) networks, CCIP has already garnered adoption from major DeFi lending protocols like Aave and Synthetix. Chainlink highlights the benefits of its CCIP The protocol’s foundation lies in the same robust security model used for Chainlink’s price oracles, designed to fend off flash-loan attacks and other potential threats. Chainlink’s co-founder, Sergey Nazarov, envisions CCIP becoming the…

    Article 2023年7月19日
TOP