White House email domains are sitting ducks for phishing attacks: study
Full article576 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Only one of the 26 email domains managed by the Executive Office of the President uses DMARC.
The White House’s delay in implementing an important email security protocol leaves its domain names vulnerable to being used in a large-scale phishing attack, according to a new study.
Only one of the 26 email domains managed by the Executive Office of the President (EOP) uses the Domain-based Message, Authentication, Reporting and Conformance (DMARC) protocol to block phishing attempts, the nonprofit Global Cyber Alliance said. Eighteen of those domains haven’t started deploying DMARC.
A Department of Homeland Security directive gave federal agencies until Jan. 15 to implement DMARC, which creates a public record for checking whether an email sender is authorized to transmit a message on behalf of a domain. Spokespeople for DHS and the National Security Council did not respond to questions on whether the directive applies to the EOP. The White House has previously claimed it was exempt from a governmentwide-reporting requirement under an IT security law.
Email domains managed by the Executive Office of the President, including WhiteHouse.gov, OMB.gov, and USTR.gov, “are crown jewels that criminals and foreign adversaries covet,” Philip Reitinger, the alliance’s president, said in a statement.
Although agencies have made progress implementing DMARC, more than a month after the DHS deadlines passed, an analysis by software vendor Easy Solutions found that over 40 percent of 311 government domains still lacked a DMARC record.
The federal government has been waging a years-long war on phishing that is far from over. In July and August 2015, a spear-phishing, or more targeted, attack that U.S. officials blamed on Russian hackers disabled the Joint Chiefs of Staff’s unclassified email system for more than two weeks.
A steady stream of generic, email-based attacks continues. The Pentagon blocks 36 million malicious emails a day, a defense official said in January.
“We hope the White House utilizes [the alliance’s] research as a call to action to join their government peers in taking this critical, commonsense step,” Patrick Peterson, founder of Agari, an email security firm that has also published research on DMARC, told CyberScoop.
An NSC spokesperson did not reply to questions on the study’s findings by the time of publication.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/white-house-dmarc-global-cyber-alliance/