CSIDB logo
Threat actor

PhishScam

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
4 incidents
First seen
2018-11-15
Last seen
2021-02-04
Updated
2026-07-16 15:44
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor tracked under the aliasesPhishScam and PhishLabs has been observed conducting phishing operations that originate from within the United States. Open‑source reports associate the actor with a series of email‑based attacks that aim to harvest credentials or obtain personal documents from employees of various organizations. The actor’s known location is the United States, though no more precise geographic information is publicly available. The aliases appear in multiple breach notifications and news articles that describe the use of spoofed messages pretending to be from trusted internal figures. These messages typically request login credentials, tax forms, or other sensitive data, and they rely on social engineering rather than malicious software.

Targeting has concentrated on the education and healthcare sectors, with confirmed incidents in Minnesota, Kansas, and South Carolina. In a February 2021 attack on a Minnesota school district, an employee received a fraudulent email that appeared to come from the district superintendent; the message requested W‑2 forms, and the actor successfully obtained the tax documents of 677 employees, which contain personal and financial details. The superintendent notified the affected workforce on the same day the breach was discovered. A January 2019 campaign against Wichita State University involved emails that solicited university login credentials; once credentials were entered, attackers accessed employee accounts, diverted paychecks for at least three individuals, and exposed bank account information and student records, resulting in direct financial loss for the affected staff. In November 2018, two related reports describe a phishing effort against Roper St. Francis Healthcare that compromised employee email accounts over a multi‑week period before detection. The organization secured the accounts, launched an investigation, and determined that patient information may have been exposed; notification letters were sent roughly two months after the incident and a dedicated call center was established. While some sources mention approximately thirteen affected employees, this figure has not been verified in official disclosures. Across these events, the actor’s method relies exclusively on deceptive email messages—often employing display‑name spoofing or look‑alike domains—to trick recipients into divulging information; no public reports reference specific malware families, exploit kits, or additional tooling. Attribution remains unclear, with no publicly available evidence linking the actor to a state sponsor, criminal consortium, or any particular threat‑group.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB