The NJCCIC observed a recent uptick in threat actors targeting New Jersey critical infrastructure and public sector organizations, including local municipalities, school districts, and police departments. Threat actors send phishing emails with links intended to capture account credentials and compromise accounts, and then send additional phishing emails from legitimate accounts to avoid suspicion and keep their campaigns alive.

They lure with shared documents for review, such as payroll or event calendars for department meetings; encrypted or secure messages; payroll processing errors; invitations for upcoming celebrations or events; past-due invoices for services; project proposals; expiring compliance training; and an updated benefits package.

Threat actors also compromise accounts to leverage pre-existing organizational trust, bypass external security controls, and continue their attacks internally and externally. They send unauthorized emails, create mailbox rules, forward emails, move laterally to critical systems, and conduct other malicious cyber activity, such as ransomware and data exfiltration. Therefore, all users and organizations are highly recommended to practice good cyber hygiene, remain vigilant, and protect information.

Additionally, the NJCCIC observed an uptick in compromised websites exploited by cross-site scripting (XSS). XSS is a web security vulnerability that enables threat actors to inject malicious scripts into trusted webpages. When executed, the malicious scripts create fake CAPTCHA or Cloudflare verifications on compromised websites. Unlike real CAPTCHAs that generally prompt users to perform text or image-based tasks to prove they are human, the fake versions involve copying text, pasting commands, downloading files, scanning QR codes, or installing software. However, behind the scenes, targets are inadvertently infected with malware, such as remote access trojans (RATs) or ransomware.

Malicious scripts can access passwords, cookies, browser session tokens, and other sensitive information stored by the browser and used by the website. Targets may risk losing email access, financial information, cryptocurrency wallets, business documents, personal files, and more. Threat actors can also use the malicious scripts to deface websites by silently rewriting webpage content with fake or threatening messages, political statements, information, or ransom notes.

Recommendations

  • Exercise caution with unexpected or unsolicited communications.
  • Confirm requests from senders using contact information obtained from verified and official sources before taking any action, such as clicking links or opening attachments.
  • Refrain from clicking on suspicious links or pop-up notifications, or running untrusted commands or scripts found on websites, forums, or social media.
  • Keep systems and browsers up to date.
  • If sensitive information was entered, change passwords for compromised accounts, monitor for unauthorized activity, and review the Identity Theft and Compromised PII NJCCIC Informational Report for additional recommendations and resources, including credit freezes.
  • If you suspect your device is infected, disconnect from the internet, run anti-virus/anti-malware scans, and review your security and privacy settings. A full system reimage may be warranted to restore the compromised device.
  • Website administrators are advised to conduct a full review of the website and hosting account; inspect all plugins, themes, and software installed on the website; remove any malicious files or code; ensure the website is patched and updated; update administrative credentials; and verify all administrators.

Report malicious cyber activity to the NJCCIC and the FBI’s IC3.

Published in the NJCCIC Weekly Bulletin July 30, 2026