AR Insurance Bulletin 10-2019

Phishing Attack on Insurance Producers

Year: 2019Length: 436 wordsOfficial source
Arkansas Insurance Department Asa Hutchinson Allen Kerr Governor Commissioner 1200 West Third Street, Little Rock, AR 72201-1904 · (501) 371-2600 · (501) 371-2618 fax · www.insurance.arkansas.gov Information (800) 282-9134 · Consumer Services (800) 852-5494 · Seniors (800) 224-6330 · Criminal Inv. (866) 660-0888 BULLETIN NO. 10-2019 TO: ALL LICENSED PRODUCERS, LICENSED PRODUCER BUSINESS ENTITITES, AGENTS, AGENCIES, BROKERS, VIATICAL SETTLEMENT AGENTS AND BROKERS, ADJUSTERS, LIMITED ADJUSTERS, CONSULTANTS, RISK RETENTION GROUP AGENTS, PURCHASING GROUP BROKERS, SURPLUS LINE BROKERS, SURPLUS LINE BROKERS FOR PURCHASING GROUPS ONLY, HMO AGENTS, PREPAID LEGAL INSURANCE AGENTS, FRATERNAL BENEFIT SOCIETY AGENTS, FMAA AGENTS FROM: ARKANSAS INSURANCE DEPARTMENT SUBJECT: PHISHING ATTACK ON INSURANCE PRODUCERS The purpose of this Bulletin is to inform you of a phishing scam targeting insurance producers that began September 4, 2019 and resumed in a modified format a few days later. The phishing emails have the National Association of Insurance Producers (“NAIC”) as the subject line and directs recipients to click on a link. On September 4, 2019, the NAIC notified all State Insurance Departments of an influx of calls to the NAIC Security Hotline regarding a potential cyber event. Insurance producers located in Illinois, Michigan, and Wisconsin received emails with NAIC as the subject line from a Google email account indicating that the NAIC had received notice of a falsified insurance claim and directed the recipient to click on a link to download the complaint notification. The emails referenced NAIC and NAIC’s Center for Insurance Policy and Research (“CIPR”) and included the NAIC/CIPR logos. Clicking on the link would download a malicious payload that has now been identified as a Remote Access Trojan that could be used to perform various nefarious functions, one of which is ransomware. The NAIC immediately filed a formal complaint with Google and as of that same evening it appeared the website being used by the attacker to deliver the malicious payload had been taken down. However, as of Friday, September 6, 2019, the phishing attack resumed with a slightly modified email being sent to insurance producers in additional states such as Minnesota and Washington. The email presents itself as from consumerprotection@naic.org. This is not a valid NAIC address. 2 | P a g e Certain anti-virus products will detect the email as malicious, however, if you receive an email with the National Association of Insurance Commissioners as the subject line and the email contains a link, this is a phishing email. Please do not click the link. Questions concerning this bulletin should be directed to the NAIC Service Desk at (816) 783-8500 or help@naic.org. September 20, 2019 ALLEN KERR DATE INSURANCE COMMISSIONER STATE OF ARKANSAS
AR Insurance Bulletin 10-2019: Phishing Attack on Insurance Producers | Justis AI