Medusa Ransomware Alert

By |2026-08-18T15:01:36-04:00August 18th, 2026|

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) have released an updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service [...]

IT Help Desk Staff Targeted

By |2026-08-06T13:52:02-04:00August 7th, 2026|

Beware of Threat Actors Targeting IT Help Desk Staff Information technology (IT) help desk staff are heavily targeted because they often possess privileged administrative rights and provide an entry point for account recovery, such as resetting passwords and bypassing multi-factor authentication (MFA). To identify high-value targets, threat actors perform reconnaissance on corporate websites, networking platforms [...]

You DON’T Want this UPS Delivery!

By |2026-08-06T13:52:28-04:00August 6th, 2026|

The NJCCIC observed a phishing campaign impersonating UPS delivery notifications. These messages use subject lines such as “Parcel Arrival Notification,” “Your Package Is Ready for Pickup,” and “Your Parcel Has Arrived” and are purported to be from the following sender(s): "UPS Parcel Services" <contact[@]shipfasts[.]com> "UPS Delivery Support" <contact[@]learnstax[.]com> Messages include an Adobe PDF attachment that [...]

Water & Wastewater System Attacks in NJ

By |2026-08-05T15:34:42-04:00August 5th, 2026|

NJ.com is reporting that at least two New Jersey water systems were hit by cyberattacks similar to those reported in several other states in recent days, officials said Monday. The New Jersey Office of Homeland Security and Preparedness said the incidents affected some automated controls, but did not cause any interruption in service. The attack temporarily limited operators’ ability [...]

Threats Target NJ Critical Infrastrcucture & Public Sector

By |2026-07-30T13:08:56-04:00July 30th, 2026|

The NJCCIC observed a recent uptick in threat actors targeting New Jersey critical infrastructure and public sector organizations, including local municipalities, school districts, and police departments. Threat actors send phishing emails with links intended to capture account credentials and compromise accounts, and then send additional phishing emails from legitimate accounts to avoid suspicion and keep [...]

Malicious Zoom Extensions

By |2026-07-23T14:39:58-04:00July 23rd, 2026|

Organizations Beware: Requests for Assistance Prompting Malicious Zoom Extension Downloads Public and private sector organizations post available services on their websites and online platforms. They may also provide referrals and offer an online search feature to find local assistance. Threat actors exploit this feature to send supposed requests for assistance and trick their targets into [...]

Zoning & Planning Scams

By |2026-07-20T10:02:54-04:00July 20th, 2026|

Nationwide Zoning and Planning Scam Targeting SLTT Residents and Businesses The Federal Bureau of Investigation (FBI) and the Center for Internet Security (CIS) Cyber Threat Intelligence (CTI) team are publishing this product to provide updates to State, Local, Tribal, and Territorial government entities (SLTTs) about a scam in which threat actors masquerade as local and [...]

FIFA World Cup Giveaway Scam

By |2026-07-16T13:02:22-04:00July 16th, 2026|

The NJCCIC has observed a phishing campaign claiming recipients have been selected to enter a giveaway for a prize tied to the FIFA World Cup. This type of free-prize-at-the-cost-of-a-shipping-fee scam tricks users into providing their credit card details to an attacker. The messages claim the offer expires on the day of receipt, and the subject [...]

Denial-of-Service Attacks

By |2026-07-02T10:17:34-04:00July 2nd, 2026|

On Friday, June 26, the Everbridge mass emergency notification system experienced an outage due to a distributed denial-of-service (DDOS) attack, which lasted overnight until June 27. Additionally, on June 28 the US National Weather Service was targeted in a DDOS attack that cause an outage of a few hours. Responsibility for both incidents were claimed [...]

Adobe Warning: Sign In to Review & Approve

By |2026-06-04T13:30:14-04:00June 5th, 2026|

Please Sign In to Review The NJCCIC observed a phishing campaign impersonating Adobe document-completion notices. These phishing emails appear to originate from adobesign[@]adobesign[.]com, the official Adobe Acrobat email address, which the threat actors have likely spoofed . The messages include a link to a counterfeit Microsoft Authentication page. The page presents the user's organization branding [...]

Go to Top