AR Insurance Bulletin 10-2019
Phishing Attack on Insurance Producers
Arkansas Insurance Department
Asa Hutchinson
Allen Kerr
Governor
Commissioner
1200 West Third Street, Little Rock, AR 72201-1904 · (501) 371-2600 · (501) 371-2618 fax · www.insurance.arkansas.gov
Information (800) 282-9134 · Consumer Services (800) 852-5494 · Seniors (800) 224-6330 · Criminal Inv. (866) 660-0888
BULLETIN NO. 10-2019
TO:
ALL LICENSED PRODUCERS, LICENSED PRODUCER BUSINESS
ENTITITES,
AGENTS,
AGENCIES,
BROKERS,
VIATICAL
SETTLEMENT AGENTS AND BROKERS, ADJUSTERS, LIMITED
ADJUSTERS, CONSULTANTS, RISK RETENTION GROUP AGENTS,
PURCHASING
GROUP
BROKERS,
SURPLUS
LINE
BROKERS,
SURPLUS LINE BROKERS FOR PURCHASING GROUPS ONLY, HMO
AGENTS, PREPAID LEGAL INSURANCE AGENTS, FRATERNAL
BENEFIT SOCIETY AGENTS, FMAA AGENTS
FROM:
ARKANSAS INSURANCE DEPARTMENT
SUBJECT: PHISHING ATTACK ON INSURANCE PRODUCERS
The purpose of this Bulletin is to inform you of a phishing scam targeting insurance producers that
began September 4, 2019 and resumed in a modified format a few days later. The phishing emails
have the National Association of Insurance Producers (“NAIC”) as the subject line and directs
recipients to click on a link.
On September 4, 2019, the NAIC notified all State Insurance Departments of an influx of calls to
the NAIC Security Hotline regarding a potential cyber event. Insurance producers located in
Illinois, Michigan, and Wisconsin received emails with NAIC as the subject line from a Google
email account indicating that the NAIC had received notice of a falsified insurance claim and
directed the recipient to click on a link to download the complaint notification.
The emails referenced NAIC and NAIC’s Center for Insurance Policy and Research (“CIPR”) and
included the NAIC/CIPR logos. Clicking on the link would download a malicious payload that
has now been identified as a Remote Access Trojan that could be used to perform various nefarious
functions, one of which is ransomware. The NAIC immediately filed a formal complaint with
Google and as of that same evening it appeared the website being used by the attacker to deliver
the malicious payload had been taken down.
However, as of Friday, September 6, 2019, the phishing attack resumed with a slightly modified
email being sent to insurance producers in additional states such as Minnesota and Washington.
The email presents itself as from consumerprotection@naic.org. This is not a valid NAIC address.
2 | P a g e
Certain anti-virus products will detect the email as malicious, however, if you receive an email
with the National Association of Insurance Commissioners as the subject line and the email
contains a link, this is a phishing email. Please do not click the link.
Questions concerning this bulletin should be directed to the NAIC Service Desk at (816) 783-8500
or help@naic.org.
September 20, 2019
ALLEN KERR
DATE
INSURANCE COMMISSIONER
STATE OF ARKANSAS