The CISA has released specific details about the discovered malicious email, but we urge our business customers to keep in mind that other similar forms of this email may exist:
Subject Line: SBA Application – Review and Proceed
Sender: disastercustomerservice@sba.gov
Body: Contains a link purporting to be the SBA website, but which actually points to https://leanproconsulting.com.br/gov/covid19relief/sba[.]gov
Clicking the hyperlink in the email brings the recipient to a spoofed version of the SBA login page, which has been captured in the screenshot below:
This is just one of several recent scams targeting small businesses, and given the ongoing prevalence of such schemes BankFive would like to remind its business customers to stay vigilant and alert.
Here are some tips to help keep your business and its sensitive information safe:
- Be wary of unsolicited phone calls, text messages, or emails and never provide sensitive information to a third-party unless you are absolutely sure that the recipient is who they purport to be.
- Be highly suspicious of anyone claiming that you’ve been approved for a grant or loan that you didn’t apply for.
- Don’t assume that every email you receive is legitimate. Remember that even sender email addresses can be spoofed. Check all email links by hovering over them before clicking on them. Whenever possible, visit a website directly by typing the address into your browser, rather than relying on email links. If you have any concerns about the legitimacy of an email you’ve received, call the sender directly using their publicly listed phone number.
- Be on the lookout for phony invoices. Have a system in place for verifying all requests for payment that your business receives.