FINRA (Financial Industry Regulatory Authority) has warned brokerage firms about a new series of phishing attacks in which attackers send fake emails posing as FINRA support staff.
FINRA is a self-regulatory organization that monitors compliance with rules and regulations by all US brokerage firms and exchanges. It oversees more than 624,000 financial market professionals and tracks billions of trading events every day.
According to the warning, scammers are sending emails on behalf of “FINRA SUPPORT” from the address [email protected]. In these emails, recipients are asked to “please review the attached report, which requires your immediate attention” and are told that the attachment contains “updated government policy information.” However, there may be no attachment.
The domain westour.org has no connection to FINRA and should be considered suspicious. The regulator advises brokerage firms to delete such emails without opening them, and if opened, to immediately report them to network administrators. FINRA has also asked the registrar NameCheap to block the domain, which was registered on May 27, 2021.
This is not the first case of attacks on FINRA members. In June, the organization warned about fraudsters who sent letters threatening fines, forcing brokers to respond. In March, attackers sent messages allegedly about conducting a “FINRA compliance check.”
Unfortunately, many of the domains used in such campaigns have not been blocked by registrars.