The Newberry Group Blog


Archived Categories

Sort By: Title   |   Blog Date
Wednesday, April 18, 2012

Identifying and Reporting Suspicious E-mail


If you are like me, you receive the occasional e-mail that just doesn’t look quite right. It may be from an anxious individual looking for your help to move their recent monetary windfall out of their impoverished country. Or it’s from someone who has a “can’t miss” investment opportunity that just needs some additional capital.  Or it’s from someone who is simply looking for a sales quote for a business that just doesn’t look right.  While I am sure that none of us have taken that bait, we shouldn’t ignore these suspicious e-mails.  We should be reporting them to the Defense Security Service (DSS) and the Federal Bureau of Investigation (FBI). 

How do I know if it’s suspicious?

Most of us understand that phishing is the act of someone trying to elicit personal information from you so they can exploit you or IT systems/accounts that you have access to. However, what if these e-mails do not ask for anything other than your simple response?  Many of the examples above only ask you to respond and, if you do, they will “send you further information.”  Once you respond and essentially confirm your e-mail address is active, these devious folks commonly do a number of things.  They do as they promise and send a response back that is typically malware or spyware that infects your computer or network.  They also typically sell your e-mail address to hackers or spammers who inflict their own damage to your systems.


What does DSS and the FBI do?

The DSS and FBI depend heavily on leads and information from the general public. It is rare for Federal investigation cases to be initiated by the DSS or the FBI. The sources of many of their investigations stem from reports from the general public. To aid in their data collections, we can forward suspected e-mails to them. DSS and the FBI then track these to the source, compile it with other data on file, and determine if an investigation is required.


Should I report everything?

It is important to keep in mind that not all unsolicited e-mail is malicious. Legitimate companies often send mass e-mails hoping to gather customers. And those lengthy “Terms and Conditions” that we all ignore when signing up for an online service or purchasing software often gives the recipient authority to use your e-mail address as they see fit.  Always remember that you should never open any attachments that come from unknown or unexpected recipients.


How do I report suspicious e-mails?

  1. Seek the advice of your company’s Security Officer or IT Department on how to handle and report malicious e-mails.
    OR
  2. Visit the FBI website for instructions: http://www.fbi.gov/scams-safety/e-scams

Posted by: Jerry Kennedy at 3:45 PM
 | permalink







Leave a comment
*First Name  *Last Name 
*Email Address
*Type the code below into the textbox.