Finra caught up in email phishing scheme

Finra caught up in email phishing scheme
A new cybersecurity alert warns member firms to be wary of fraudulent messages impersonating key members of the regulator’s leadership.
APR 05, 2024

Finra has issued a cybersecurity alert to its member firms warning of an ongoing phishing campaign that impersonates two key members of the organization's leadership.

The fraudulent scheme, which the Financial Industry Regulatory Authority Inc. says impacts all firms, involves emails falsely claiming to be from executives at the industry regulator, using the deceptive email addresses “[email protected]” and “[email protected].”

According to the alert, these email addresses, along with the domain “data-finra.org,” are not associated with Finra, and recipients are advised to immediately delete any emails received from these domains.

Utilizing a classic social engineering ploy appealing to actual authorities, the bogus emails purport to come from members of Finra’s leadership, including Steve Randich, executive vice president and chief information officer of Finra, and Robert L.D. Colby, its chief legal officer.

The phishing messages are also crafted to evoke a sense of urgency, claiming multiple attempts have been made to contact the target “to deliver a notice that requires your attention.” That’s on top of vague tags simply highlighting the notice as “confidential” with a “Due Date” of April 15, 2024.

The fraudulent communication includes a file labeled “Finra [FIRM NAME]_Disclosure290124.pdf,” with a request to “complete the request at your earliest convenience.”

In response to this phishing campaign, Finra has reminded firms to maintain good cybersecurity practices and verify the legitimacy of any suspicious email before engaging with its content, including responding, opening any attachments, or clicking on embedded links.

Finra has also reached out to the registrars behind the fake “data-finra.org” Internet domain, asking for its suspension. To help address cybersecurity threats, Finra is urging member firms to contact its cyber and analytics unit for guidance, and promptly report incidents to the FBI’s Internet Crime Complaint Center or the Cybersecurity and Infrastructure Security Agency via its 24/7 Operations Center.

Younger generations are more interested in impact investing than ever. Here's why

More goRIA

Altruist riding 140% growth trajectory in 'breakout' year, CEO says
Altruist riding 140% growth trajectory in 'breakout' year, CEO says

Jason Wenk says his RIA custodian is far ahead of targets as Altruist Advisors beta program draws five times more applicants than expected

Next-gen advisors are ready to work – are RIA firms ready for them?
Next-gen advisors are ready to work – are RIA firms ready for them?

A new student survey from FP Transitions and the FinServ Foundation reveals eager, career-ready talent are waiting at the door — but firms risk losing them before they begin.

Betterment eyes retail-to-advisor pipeline with RIA referral pilot
Betterment eyes retail-to-advisor pipeline with RIA referral pilot

While unveiling new portfolio management and direct indexing tools for RIAs, Betterment's Devon Klumb said the firm's advisor referral pilot is intended to convert retail users into RIA clients as their financial needs become more complex.

Dynasty Financial Partners, Allocate deepen private markets push for independent RIAs
Dynasty Financial Partners, Allocate deepen private markets push for independent RIAs

Dynasty advisors gain access to white-label fund solutions and relationship pricing as two firms cement long-term build-out.

FINNY launches enterprise AI growth platform with Mercer Advisors
FINNY launches enterprise AI growth platform with Mercer Advisors

The AI prospecting startup expands beyond individual advisors, targeting centralized marketing groups at firms with large home offices.

SPONSORED Why direct indexing stopped being optional

Direct indexing is on pace to outgrow ETFs and mutual funds. Northern Trust's Ken Lassner explains why the advisors who get it wish they had started sooner.

SPONSORED Estate planning isn't a service add-on. It's your retention strategy.

As $84 trillion prepares to change hands, advisors who treat estate planning as peripheral are quietly building a sieve, not a book.