---
title: "Cyber Security News Update, Week 38 of 2019 | DuoCircle"
description: "Use your campus library much? You may be the target of the latest phishing scam."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/"
---

Quick Answer

Cybersecurity headlines for the week of September 18, 2019\. SC Magazine reported the Iran-linked Mabna Institute running a global phishing campaign against universities, sending fake library-service emails that redirect to spoofed login pages to harvest credentials. An Amazon scam used 'order confirmation' emails to extract payment information by phone callback. A banking phishing wave impersonated several US regional banks. The LokiBot infostealer reappeared in Microsoft-themed phishing emails. A Wisconsin medical group disclosed a phishing-driven email compromise exposing PHI. The Mississippi Department of Human Services reported a breach exposing data for around 4,300 individuals. The phishing roundup covers other notable lures.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2038%20of%202019&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2038%20of%202019 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2038%20of%202019&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2019/09/smtp-providers-5837.jpg) 

Use your campus library much? You may be the target of the latest phishing scam. According to [SC Magazine](https://www.scmagazine.com/home/security-news/cybercrime/researchers-iranian-phishing-campaign-targets-universities-with-fake-library-emails/?utm%5Fsource=newsletter&utm%5Fmedium=email&utm%5Fcampaign=SCUS%5FNewswire%5F20190916&hmSubId=01xQvtS0ero1&email%5Fhash=0da939dab246e8101d6090def505f6f5&mpweb=1325-10154-1896988), ” The Mabna Institute, an Iranian firm whose members were indicted last year for cyberattacks against U.S. universities and other organizations, appears to have launched a new global **phishing operation** targeting the education sector last July and August.”

“In an attempt to steal university employees’ credentials, the attackers sent their targets **phishing emails** that impersonated library services. The emails contained links to fake university login pages where victims were encouraged to enter their user names and passwords.”

[![email security service](https://media.mailhop.org/duocircle/images/2019/09/windows-smtp-service-5371.jpg)](https://media.mailhop.org/duocircle/images/2019/09/windows-smtp-service-5371.jpg)

## Amazon Scam

There’s a new Amazon phishing scam circulating now looking to steal credit card data from those who do not have a proper [email security service](/), according to [HackRead](https://www.hackread.com/new-amazon-phishing-scam-stealing-credit-card-data/). _The scam “tricks users into handing over their personal as well as financial information including credit card information to online crooks_. Apparently, the crooks are trying to convince victims that someone has changed the password of their Amazon account.”

## Banking Scam

Once again the banking sector was under siege this week. According to [MetaCompliance](https://www.metacompliance.com/blog/crafty-phishing-scam-targets-santander-hsbc-and-royal-bank-of-scotland-customers/), “Crafty **phishing scam** targets Santander, HSBC and Royal Bank of Scotland customers. _Fraudsters are using new online security checks to trick banking customers into handing over their financial details and personal data._”

## Phishing Phrontier

Perhaps the newest development on the phishing frontier is the **refusal of organizations to pay the ransom**, regardless of amount. [News](https://www.darkreading.com/risk/texas-refuses-to-pay-$25m-in-massive-ransomware-attack/d/d-id/1335763) came this week that “The state of Texas is so far refusing to comply with the demands of a ransomware attack that affected 22 local governments, the Texas Department of Information Resources (DIR) reports. None of the affected municipalities have paid the **$2.5 million ransom** demanded. _On August 16, a coordinated ransomware campaign hit systems of cities and towns across Texas_.”

_This is the great challenge of ransomware hackers_. If their ransom demand is too high, they make it easy for the victim to say “no thanks” I’ll figure it out myself. Of course, the one thing these organizations have yet to figure out is that it’s a lot cheaper to deploy cloud-based [anti-phishing software](/email/phishing-protection) for all their employees and avoid having to make that decision in the first place.

## LokiBot Bot

_The most sophisticated phishing attacks today use bots, with the latest one called LokiBot_. From [Bleeping Computer](https://www.bleepingcomputer.com/news/security/lokibot-info-stealer-used-in-spear-phishing-attack-on-us-company/), “Security researchers discovered a malspam campaign distributing LokiBot information **stealer payloads** using phishing messages targeting the employees of a large U.S. manufacturing company. _After the target unzips the attached archive, they will get infected with the LokiBot information stealer malware_.”

“Once it successfully compromises its victims’ computers, LokiBot is designed to harvest as much **sensitive information** as possible. LokiBot steals a variety of credentials, primarily FTP credentials, stored email passwords, passwords stored in the browser, as well as a whole host of other credentials.”

## Body Count

You would think with all the hackers out there causing all that trouble, eventually, some of them would get caught and prosecuted. Well now they have. According to [SC Magazine](https://www.scmagazine.com/home/security-news/authorities-arrest-281-alleged-bec-scammers-in-operation-rewired-campaign/?utm%5Fsource=newsletter&utm%5Fmedium=email&utm%5Fcampaign=SCUS%5FNewswire%5F20190916&hmSubId=01xQvtS0ero1&email%5Fhash=0da939dab246e8101d6090def505f6f5&mpweb=1325-10135-1896988), “Authorities arrest **281 alleged BEC scammers** in ‘Operation reWired’ campaign.” _The arrests took place internationally over a span of four months_.

“Dubbed Operation reWired, the coordinated campaign began in May 2019 and has resulted in 72 arrests in the U.S., and 167 in Nigeria, which is known to be a hotbed of BEC, ‘419’ and romance scams. Arrests also took place in Turkey (18), Ghana (15), France, Italy, Japan, Kenya, Malaysia and the U.K.”

Chalk one up for the good guys.

## Medical Cyberattack

_At this point we may as well go ahead and put medical facilities on the endangered species list when it comes to ransomware_. [News](https://www.scmagazine.com/home/security-news/cybercrime/ransomware-attack-on-premier-family-medical-reportedly-impacts-records-of-320k-patients/?utm%5Fsource=newsletter&utm%5Fmedium=email&utm%5Fcampaign=SCUS%5FNewswire%5F20190916&hmSubId=01xQvtS0ero1&email%5Fhash=0da939dab246e8101d6090def505f6f5&mpweb=1325-10135-1896988) this week discussing how “Utah-based health care practice Premier Family Medical was struck by ransomware last July 8 in a cyberattack that reportedly affected the records of roughly **320,000 patients**. The medical provider, which operates 10 locations across Utah County, originally announced the incident publicly on Aug. 30, noting that the malware had restricted employees’ access to their systems and data.”

[![phishing attack](https://media.mailhop.org/duocircle/images/2019/09/buy-smtp-2456.jpg)](https://media.mailhop.org/duocircle/images/2019/09/buy-smtp-2456.jpg)

## Department of Human Services Breach

Not to be outdone, the Oregon Department of Human Services [reported](https://www.sesin.at/2019/03/25/oregon-agency-reports-phishing-attack-affecting-350000-inforisktoday/) a **phishing attack** affecting the health information of 350,000, an “_incident among the largest health data breaches so far in 2019_. Client information impacted may include first and last names, addresses, dates of birth, Social Security numbers, case number and other information used to administer DHS programs.”

How many employees clicked on a link in the **spear phishing email**? Nine. SMH

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2038%20of%202019&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-38-of-2019%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Spam](https://media.mailhop.org/duocircle/images/2016/05/spf-permerror-3256.jpg)  April Spam Filtering Uptime Report News ](/blog/announcements/april-spam-filtering-uptime-report/)
- [ ![Spam Filtering](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-7226.jpg)  Changes to Spam Filtering Technology News ](/blog/announcements/changes-to-spam-filtering-technology/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2020/01/spf-permerror-7312.jpg)  Cyber Security News Update, Week 1 of 2020 News ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 38 of 2019","description":"Use your campus library much? You may be the target of the latest phishing scam.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/","datePublished":"2019-09-18T14:26:28.000Z","dateModified":"2025-05-26T18:32:40.000Z","dateCreated":"2019-09-18T14:26:28.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":751,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/09/smtp-providers-5837.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 38 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 38 of 2019","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 38 of 2019","description":"Use your campus library much? You may be the target of the latest phishing scam.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/","datePublished":"2019-09-18T14:26:28.000Z","dateModified":"2025-05-26T18:32:40.000Z","dateCreated":"2019-09-18T14:26:28.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-38-of-2019/"},"articleSection":"announcements","keywords":"","wordCount":751,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/09/smtp-providers-5837.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
