---
title: "Cyber Security News Update, Week 37 of 2019 | DuoCircle"
description: "“Malicious actors target government contractors,” according to SC Magazine."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/"
---

Quick Answer

Cybersecurity headlines for the week of September 12, 2019\. SC Magazine reported a rise in 'invitation to bid' phishing aimed at government contractors, a transactional social engineering pattern that piggybacks on legitimate procurement workflows. A Microsoft Word exploit using legacy macro behavior continued to deliver Emotet and Trickbot. A PayPal phishing scam claimed unauthorized access and pointed users to a credential-harvesting page. A separate Microsoft SharePoint exploit abused link sharing to bypass URL filters. Facebook confirmed an exposed database with around 419 million phone numbers tied to user accounts. French retail-tech firm Aliznet was hit by a data exposure incident leaking customer records of major brands. The phishing roundup covers other notable lures.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2037%20of%202019&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2037%20of%202019 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2037%20of%202019&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2019/09/spf-permerror-7493.jpg) 

“Malicious actors target government contractors,” according to SC Magazine. While [targeting government contractors](https://gtpac.org/2019/09/12/bad-bid-malicious-actors-target-government-contractors/) certainly isn’t a new occurrence, it does seem to be on the rise. “Over the past few months we have observed _the increasing use of yet another type of transaction-based social engineering scheme designed to hook companies dependent on government contracts_: the invitation to bid.”

“Fake bid invitations have been around for a while, to be sure. In many respects, they are a natural variation of the fake RFQ, which leverages a targeted organization’s search for new business to dupe its employees into opening the digital door to security breaches, costly downtime, and financial mayhem.”

## Microsoft Word Exploit

There’s nothing harmful about a Word document, is there? That’s what scammers are hoping you think when they launched their newest exploit. According to [Fortinet](https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document.html), “Recently, FortiGuard Labs captured a number of Word documents from the wild, which were spreading a new variant of the **Ursnif trojan**. _These infected Word documents contain malicious VBA code_.”

“When a victim opens the Word document, it displays a security warning message designed to protect MS Word users from **malicious macros** (VBA code). However, _the document content deceives victims to click the Enable Content button. When the button is clicked_, the malicious VBA code is executed because the code is in an AutoOpen sub that is executed at opening the document.”

## PayPal Phishing Scam

PayPal is back in the news as a favorite target of phishers. According to an article on Hoax-Slayer, “Supposedly, PayPal’s system has detected that you are using a new unknown device.” That’s the hook on this phish.

It’s not a particularly clever phish, but according to the article, “_The criminals responsible for the scam email hope that at least a few recipients will be panicked into clicking the cancel link in the mistaken belief that their PayPal account has been hijacked._”

[![Phishing Scam](https://media.mailhop.org/duocircle/images/2019/09/smtp-service-7495.jpg)](https://media.mailhop.org/duocircle/images/2019/09/smtp-service-7495.jpg)

## Phishing Phrontier

We don’t usually report good security news here, but we have some today. Thanks to some quick action on the part of government officials in the city of Unalaska, Alaska, the city has recovered about **$2.3 million of the $2.9 million** it had sent to fraudsters in a business email compromise phishing scam.

According to [Tripwire](https://www.tripwire.com/state-of-security/security-data-protection/unalaska-recovers-2-3-million-following-phishing-attack/), “In the case of Unalaska, we were able to recover funds and prevent any future loss thanks to the timely and thorough response from the city administration. We are continuing to investigate this case in an effort to identify the perpetrators.” Way to go, civil servants.

## Microsoft SharePoint Exploit

You can be sure if there’s some way to exploit a Microsoft product, hackers will find a way. “The [CofenseTM Phishing Defense CenterTM](https://cofense.com/product-services/phishing-defense-services/) has identified a **phishing campaign** that uses SharePoint to elude the Symantec email gateway and other perimeter technologies. _Using enterprise services like SharePoint almost guarantees the phishing URL will be delivered to the intended target_. Aimed at the banking industry, here’s how this campaign works.”

## Body Count

We know that healthcare providers are constantly being taken in by **phishing scams**, but this last week was one for the books. According to [Paubox](https://www.paubox.com/blog/phishing-attacks-wreck-havoc-on-healthcare-providers), “five separate healthcare providers have reported potential data breaches due to the lack of [email security service](/) in just the span of a week.” The providers include University of Cincinnati Health, East Central Indiana School Trust, Artesia General Hospital in New Mexico, Conway Regional Medical Center in Arkansas, Care Foundation Hospital in Illinois. “In each case, _hackers were able to access employees email accounts through a phishing email._”

[![email security](https://media.mailhop.org/duocircle/images/2019/09/email-security-7496.jpg)](https://media.mailhop.org/duocircle/images/2019/09/email-security-7496.jpg)

## Facebook Breach

If you judge data breach by the number of people affected, last week’s data breach announcement at Facebook is the gold medal winner. According to [SC Magazine](https://www.scmagazine.com/home/security-news/419-million-facebook-users-info-exposed/?utm%5Fsource=newsletter&utm%5Fmedium=email&utm%5Fcampaign=SCUS%5FNewswire%5F20190909&hmSubId=01xQvtS0ero1&email%5Fhash=0da939dab246e8101d6090def505f6f5&mpweb=1325-10013-1896988), “Unprotected databases are behind a leak that exposed information, including unique identifiers and phone numbers, on more than **419 million Facebook users**, 133 million of those records belonging to users in the U.S.” That’s a big number.

“_The exposed data is the latest in a string of privacy and data protection missteps by Facebook,_ which had fallen under intense scrutiny after it suspended [Cambridge Analytica](https://www.scmagazine.com/?s=cambridge+analytica) , the data analytics firm used by the Trump and Brexit campaigns to target voters, for _violating its policies when it collected personal data from accounts of **50 million Americans** without their permission_.”

## Aliznet Exploit

Coming in right behind Facebook this week is Aliznet, French retail consultancy, with a database leak on 2.5 million Yves Rocher customers. According to the [article](https://www.scmagazine.com/home/security-news/aliznet-exposed-database-leaks-data-on-2-5-million-yves-rocher-customers/?utm%5Fsource=newsletter&utm%5Fmedium=email&utm%5Fcampaign=SCUS%5FNewswire%5F20190909&hmSubId=01xQvtS0ero1&email%5Fhash=0da939dab246e8101d6090def505f6f5&mpweb=1325-10013-1896988), “The most sensitive leaked data involves \[**2.5 million Canadian**\] customers of Aliznet’s client Yves Rocher, an international cosmetics and beauty brand. The information exposed included customers full personally identifiable information (PII), along with detailed records of their orders.”

This is one contest where the silver medal is just as bad as the gold.

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2037%20of%202019&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-37-of-2019%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 37 of 2019","description":"“Malicious actors target government contractors,” according to SC Magazine.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/","datePublished":"2019-09-12T14:15:10.000Z","dateModified":"2025-05-16T12:27:54.000Z","dateCreated":"2019-09-12T14:15:10.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":795,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/09/spf-permerror-7493.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 37 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 37 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 37 of 2019","description":"“Malicious actors target government contractors,” according to SC Magazine.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/","datePublished":"2019-09-12T14:15:10.000Z","dateModified":"2025-05-16T12:27:54.000Z","dateCreated":"2019-09-12T14:15:10.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-37-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":795,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/09/spf-permerror-7493.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
