Finra caught up in email phishing scheme

Finra caught up in email phishing scheme
A new cybersecurity alert warns member firms to be wary of fraudulent messages impersonating key members of the regulator’s leadership.
APR 05, 2024

Finra has issued a cybersecurity alert to its member firms warning of an ongoing phishing campaign that impersonates two key members of the organization's leadership.

The fraudulent scheme, which the Financial Industry Regulatory Authority Inc. says impacts all firms, involves emails falsely claiming to be from executives at the industry regulator, using the deceptive email addresses “[email protected]” and “[email protected].”

According to the alert, these email addresses, along with the domain “data-finra.org,” are not associated with Finra, and recipients are advised to immediately delete any emails received from these domains.

Utilizing a classic social engineering ploy appealing to actual authorities, the bogus emails purport to come from members of Finra’s leadership, including Steve Randich, executive vice president and chief information officer of Finra, and Robert L.D. Colby, its chief legal officer.

The phishing messages are also crafted to evoke a sense of urgency, claiming multiple attempts have been made to contact the target “to deliver a notice that requires your attention.” That’s on top of vague tags simply highlighting the notice as “confidential” with a “Due Date” of April 15, 2024.

The fraudulent communication includes a file labeled “Finra [FIRM NAME]_Disclosure290124.pdf,” with a request to “complete the request at your earliest convenience.”

In response to this phishing campaign, Finra has reminded firms to maintain good cybersecurity practices and verify the legitimacy of any suspicious email before engaging with its content, including responding, opening any attachments, or clicking on embedded links.

Finra has also reached out to the registrars behind the fake “data-finra.org” Internet domain, asking for its suspension. To help address cybersecurity threats, Finra is urging member firms to contact its cyber and analytics unit for guidance, and promptly report incidents to the FBI’s Internet Crime Complaint Center or the Cybersecurity and Infrastructure Security Agency via its 24/7 Operations Center.

Younger generations are more interested in impact investing than ever. Here's why

More goRIA

Altruist opens pre-IPO deals to RIA clients as AI listings loom
Altruist opens pre-IPO deals to RIA clients as AI listings loom

The Vanguard-bound RIA custodian is now letting advisors subscribe clients to late-stage private company SPVs from inside its platform.

Savvy Wealth opens its custodial platform to outside RIAs
Savvy Wealth opens its custodial platform to outside RIAs

The AI-native RIA is pitching 90-second client onboarding to independent firms weeks after landing $100 million Series C.

Kay Lynn Mayhue named Merit CEO, still seeks 'big splash' deal
Kay Lynn Mayhue named Merit CEO, still seeks 'big splash' deal

Founder Rick Kent moves to executive chairman, and Zach Mersberger has been named president of the $33 billion hybrid-RIA.

Why female financial advisors are slow to embrace independence
Why female financial advisors are slow to embrace independence

Three senior women in wealth management outline the ownership, capital and confidence gaps still holding top advisors back.

Schwab, Anthropic block model training in Claude deal
Schwab, Anthropic block model training in Claude deal

Schwab's Claude integration blocks Anthropic from retaining advisor and client data for model training, even for users without enterprise plans.

SPONSORED In the Age of AI, Trust Becomes the Advisor's Greatest Asset

As AI makes financial information more accessible than ever, Lana Hock explains why human judgment, trust, and empathy remain the qualities clients value most in a financial advisor

SPONSORED Direct indexing webinar targets tax-loss harvesting amid market swings

Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains