4.9 • 696 Ratings
🗓️ 15 November 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, November 15th, 2021 edition of the Sandcent Storm Center's Stormcast. |
0:08.7 | My name is Johannes Ulrich. |
0:10.5 | And I'm recording from Fort Walton Beach, Florida. |
0:15.1 | This weekend, many individuals received email that claimed to originate from the FBI and informed the |
0:23.3 | individual that their organization was the victim of some form of intrusion that the FBI is |
0:31.1 | investigating. |
0:32.7 | Now, of course, fake emails like this aren't necessarily new, but what was different here |
0:37.2 | was that these emails |
0:38.7 | actually originated from legitimate FBI email infrastructure. Spam House did an analysis |
0:45.9 | of the headers proving that all the signatures and such were correct that the originating |
0:52.8 | mail server was actually operated by the FBI. |
0:57.9 | According to a statement the FBI released on Sunday, the mail server in question here was used |
1:05.3 | by a law enforcement enterprise portal to push notifications and apparently was misconfigured allowing anybody |
1:13.2 | to use it to send arbitrary messages. |
1:17.2 | That being said, if your organization is the victim and part of an FBI investigation, you |
1:23.9 | should expect a personal visit by an FBI agent, maybe a phone call. Always tricky in |
1:31.8 | situations like this to essentially bootstrap trust when you're meeting these people for |
1:36.2 | the first time. Checking credentials, of course, is always a good idea. But I also always recommend |
1:42.0 | to attend your local InfraGard chapters meeting. |
1:46.7 | That's an organization that works with the FBI, |
1:50.3 | and it's typically a good way to meet your local FBI agents, |
1:55.0 | in particular those who are dealing with cybercrime issues. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.