
| The NJCCIC received reports of a phishing campaign impersonating ID.me, which is a US-based digital identity network that allows users to provide proof of their legal identity online to access government services, healthcare portals, and retailer discounts. The phishing email is sent from a “.ar” top-level domain (TLD) for Argentina with a subject line of “New Financial Document Available.” It contains an attachment and link that, if clicked, directs users to a phishing website to set up an ID.me account. The website requests personal information, such as home address, phone number, and Social Security number. It also requires the user to upload a valid, government-issued photo identification, such as a driver’s license or passport. If submitted, the information is sent to the threat actors in the background to commit identity theft and fraud. |
| Recommendations |
| Exercise caution with communications from known senders or legitimate services or platforms. Confirm requests from senders using contact information obtained from verified, official sources before taking action, such as clicking links, opening attachments, and providing personal or financial information. Navigate directly to the legitimate ID.me website and review their FAQs. Enable multi-factor authentication (MFA) and keep systems and browsers up to date. If sensitive information was submitted, review the Identity Theft and Compromised PII NJCCIC Informational Report for additional recommendations and resources. Report malicious cyber activity to the NJCCIC and the FBI’s IC3. |