FINRA Alerts About Yet Another Phishing Campaign Using Imposter Domain

Date:

Share post:

The U.S. Financial Industry Regulatory Authority (FINRA) warned its brokerage firms about an ongoing phishing campaign targeting users to steal personal information. In a security alert,  FINRA stated that malicious actors are sending fraudulent emails to users with a source domain “@invest-finra.org.” FINRA has asked users to verify the legitimacy of the email before downloading any attachments or clicking on any links, and also requested the Internet domain registrar to suspend services for the invest-finra.org.

FINRA is a non-profit organization supervised by the Securities and Exchange Commission (SEC) that regulates member brokerage firms and exchange markets in the U.S.

A Homoglyph Technique?

Attackers are impersonating FINRA members by using their real names and images to trick users into believing that they are legitimate.  This technique is used in a homoglyph attack, where, cybercriminals misuse the similarities of character scripts to create phony domains of existing brands to trick users into clicking on fraudulent emails.  A homoglyph is one of two or more characters or glyphs with shapes that appear identical or very similar.

FINRA has asked users to delete all emails originating from “invest-finra.org.”

Not the First Time

Earlier, FINRA stated that attackers used registered brokers’ data to create phishing emails and imposter websites. The fake emails were embedded with phishing links or malicious attachments that contained malware. Several members fell victim to these sites, compromising their personally identifiable information (PII) like names, email addresses, and contact details. Read the full story here…

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...