---
title: "Cyber Security News Update, Week 9 of 2020 | DuoCircle"
description: "This week’s first scam comes courtesy of the U.S. Postal Service."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/"
---

Quick Answer

Week 9, 2020 cyber news: a USPS Delivery Failure Notification phishing wave drops malware that steals usernames, passwords, and banking data; BT and Amex/Chase impersonation phishing emails harvest logins; a fake Amazon phishing link inadvertently exposes the attackers own backdoor; Lookout details a wide SMS phishing campaign targeting mobile banking customers; Overlake Medical Center exposes PHI on 109,000 patients and Wise Health System on 66,834 after phishing breaches; DISA discloses a breach affecting up to 200,000 people; MGM Resorts confirms its 2019 cloud breach affected 10.6 million guests.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2020%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%209%20of%202020&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2020%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2020%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2020%2F&title=Cyber%20Security%20News%20Update%2C%20Week%209%20of%202020 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%209%20of%202020&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2020%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2020/02/Office-365-migration-8421.jpg) 

This week’s first scam comes courtesy of the U.S. Postal Service. From an [article](https://new.thescoopradioshow.com/email-scam-alert-if-you-recently-received-an-email-appearing-to-be-from-the-u-s-postal-service/) online, “USPS® and the Postal Inspection Service are aware of the circulation of a fake email/email scam claiming to be from USPS officials including the Postmaster General.

Some postal customers are receiving **bogus emails** featuring the subject line, ‘Delivery Failure Notification.’ These emails appear to be from the _U.S. Postal Service® and include language regarding an unsuccessful attempt to deliver a package_. The email will prompt you to confirm your personal delivery information by clicking a button or downloading an attachment, that, _when opened, can activate a virus and **steal information**_ , such as your usernames, passwords, and financial account information.”

## British Telecom company Phishing Scam

Not to be outdone by the American postal system, _British Telecom company (BT) was also the vehicle this week for a phishing scam_. According to Hoax Slayer\*\*,\*\* “The email asks you to click a link to provide BT with updated billing information. _To make it appear authentic, the email includes the BT logo along with seemingly legitimate footer information and help links_. Despite its appearance, however, the email is not from BT. It is a **phishing scam** designed to steal your personal and financial information.”

[![phishing email](https://media.mailhop.org/duocircle/images/2020/02/email-migration-service-8632.jpg)](https://media.mailhop.org/duocircle/images/2020/02/email-migration-service-8632.jpg)

## Credit Card Companies Scam

_Credit card companies were also used this week to launch phishing attacks_. From Capital Journal, “The bad guys are sending a new attention-grabbing **phishing email**, and they’re targeting the customers of major credit card companies. The email appears to come from a well-known credit card company, usually American Express or Chase. _The email includes a list of credit card transactions, and you are asked to confirm or deny whether the transactions are valid_. If you click the ‘No, I do not recognize the transactions’ link, you are brought to a fake login page that looks very similar to the credit card company’s actual login page.”

## Phishing Phrontier

Every now and then, hackers are so inept that you just have to laugh. From [Naked Security](https://nakedsecurity.sophos.com/2020/02/21/the-amazon-prime-phishing-attack-that-wasnt/) comes the story of **_The Amazon Prime phishing attack that wasn’t…_** To make a long story short, _the hackers sent out a phishing email pretending to be from Amazon_. That seems pretty straightforward. The surprise came if you fell for the scam and clicked on the link.

According to the article, “instead of reaching a page that demanded our Amazon password, which is what we expected, we ended up at the crooks’ very own **remote access backdoor** \[with\] full remote access with no username or password needed.” Like I said, you have to laugh.

## Smishing Campaign

_It’s one of the worst ideas of all time: enabling hyperlinks in text messages_. What could possibly go wrong? Phishing attacks known as [smishing](/phishing-protection/top-phishing-email-attacks-worldwide-in-2018/), that’s what.

From [TechGenix](http://techgenix.com/sms-phishing-campaign/), “Security researchers at Lookout recently published a [report](https://blog.lookout.com/lookout-phishing-ai-reveals-mobile-banking-phishing-campaign) that details an extensive **SMS phishing campaign**. The SMS phishing campaign specifically targets users of mobile banking sites.” **Bottom line**: _don’t ever visit your bank from a link inside a text message_.

[![email security services](https://media.mailhop.org/duocircle/images/2020/02/office-365-to-office-365-migration-7643.jpg)](https://media.mailhop.org/duocircle/images/2020/02/office-365-to-office-365-migration-7643.jpg)

## Body Count

A couple more healthcare organizations were hit with a phishing attack this week resulting in over 175,000 victims. [First](https://www.hipaajournal.com/phi-of-109000-patients-potentially-compromised-in-washington-phishing-attack/) it was the Overland Medical Center & Clinics in Bellevue, Washington potentially exposing the **PHI of 109,000 patients**. “A review of the affected accounts revealed they contained patient names, addresses, telephone numbers, dates of birth, health insurance provider names, health insurance ID numbers, and diagnosis and treatment information related to the care provided at Overlake.” So, _pretty much everything but social security numbers_.

Next, Wise Health Systems in Decatur, Texas [notified](https://www.hipaajournal.com/wise-health-system-notifies-66934-patients-of-phishing-attack/) 66,834 patients that some of their PHI was potentially compromised in a **phishing attack**. “Out of an abundance of caution, _affected patients have been offered credit monitoring, identity theft recovery, and identity theft insurance coverage through the ID Experts MyIDCare service for 12 to 24 months_. Following the breach, Wise Health System implemented [email security services](/) to improve its cybersecurity posture.” Well I hope so.

## DISA Breach

_Even government agencies aren’t immune to data breaches, because, well, they have human beings working there also_. According to [SC Magazine](https://www.scmagazine.com/home/security-news/disa-breach-likely-exposed-personal-data-on-at-least-200k/), “The breach at one of the networks of the Defense Information Systems Agency (DISA), which secures communications for President Trump and military intelligence and other government officials, _affected as many as 200,000 people, exposing their personal information, including Social Security numbers_.” Ouch.

## MGM Resorts Breach

This comes under the heading of “updated information.” We knew about the breach, we just didn’t know how widespread it was [today](https://www.scmagazine.com/home/security-news/data-breach/mgm-admits-to-2019-data-breach-affecting-10-6-million-customers/). “_MGM Resorts has confirmed there was unauthorized access to one of the company’s cloud servers in 2019_ that contained information on a reported **10.6 million guests**, possibly including several high-profile guests.” Ten point six million!

Maybe it’s time to do what Wise Health System did and implement measures to **improve cybersecurity** posture.

And that’s the week that was.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 1m  April Spam Filtering Uptime Report  May 4, 2016 ](/blog/announcements/april-spam-filtering-uptime-report/)[  News 2m  Changes to Spam Filtering Technology  Feb 8, 2023 ](/blog/announcements/changes-to-spam-filtering-technology/)[  News 4m  Cyber Security News Update, Week 1 of 2020  Jan 3, 2020 ](/blog/announcements/cyber-security-news-update-week-1-of-2020/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 9 of 2020","description":"This week’s first scam comes courtesy of the U.S. Postal Service.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/","datePublished":"2020-02-27T20:18:09.000Z","dateModified":"2025-05-26T12:48:14.000Z","dateCreated":"2020-02-27T20:18:09.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":801,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/02/Office-365-migration-8421.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 9 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 9 of 2020","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 9 of 2020","description":"This week’s first scam comes courtesy of the U.S. Postal Service.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/","datePublished":"2020-02-27T20:18:09.000Z","dateModified":"2025-05-26T12:48:14.000Z","dateCreated":"2020-02-27T20:18:09.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2020/"},"articleSection":"announcements","keywords":"","wordCount":801,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2020/02/Office-365-migration-8421.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
