ZeroHour
CyberScooppublished ()ingested @Bing_Chris

OPM-themed ransomware targets U.S. government workers

criticalRansomware exploited in the wildimportance 60
Full article757 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The messages warned receivers that their respective banks had notified OPM of suspicious account activity that could be reviewed via a malicious attachment.

A ransomware campaign designed to target U.S. government workers and employees of federal contractors flooded thousands of email inboxes. Each email contained a malware laden attachment and was written to appear like it came from the Office of Personnel Management. The messages warned receivers that their respective banks had notified OPM of suspicious account activity that could be reviewed via a malicious attachment.

A group of security researchers from Leesburg, Va.-based firm PhishMe first spotted the Locky ransomware campaign Tuesday.

Locky is a common, Windows-based ransomware variant that was first discovered in Feb. 2016. The typical ransom price to receive a decryption key for Locky is roughly .5 bitcoin, which is around $360 as of this article’s publication. 

The researchers believe that the campaign was not designed to coincide with the U.S. election.

“The first messages in this set were captured by PhishMe’s collections at 06:39 Eastern and the last one was received at 12:53 Eastern time. The threat actors’ selection for this timeframe is significant since it encompasses both the earliest risers on the US east coast and the start of the business day for the US west coast as well,” said PhishMe Threat Intelligence Manager Brendan Griffin, “the criminals were likely trying to reach people as they got into the office for work or checked their email for the first time today.”

PhishMe collected more than 10,000 email copies associated with the OPM-themed scheme and estimates far more were distributed, nationally.

“Part of what’s interesting is that of all the governmental entities, the threat actors chose the Office of Personnel Management. This could be interpreted as evidence that the threat actors have some topical understanding of the people they are trying to reach—government employees or those affected by the OPM breach. However, the email message really missed the mark,” said Griffin.

In the real world, OPM is not responsible for notifying citizens of “suspicious movement” apparent in their bank accounts.

“Even if the threat actors were really clever and intended to make a phishing email that appealed to those who signed up for identity theft monitoring services after the loss of personal information, the firms providing those services aren’t going to send an email as the Office of Personnel Management,” said Griffin, “context for email matters and while the threat actors are able to craft a topically-relevant message, anomalies can be quite evident.”

More Scoops

verizon 2018 DBIR
(Getty)

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang

The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe.

Del. Eleanor Holmes Norton, D-D.C., speaks at a press conference outside the U.S. Capitol on March 10, 2024. (Photo by Kayla Bartkowski/Getty Images)

Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming

President Donald Trump, left, and China’s President Xi Jinping arrive for talks at the Gimhae Air Base, located next to the Gimhae International Airport in Busan on October 30, 2025. Trump and Xi have both been publicly impassive about cyber operations in the past few months.(Photo by ANDREW CABALLERO-REYNOLDS / AFP) (Photo by ANDREW CABALLERO-REYNOLDS/AFP via Getty Images)

While White House demands deterrence, Trump shrugs

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/opm-ransomware-targets-u-s-government-workers/