Cyber Incident Victim: Boston labor union
Date:
Feb 2023
Location:
United States of America
Summary
A cyberattack targeting a Boston labor union's health fund resulted in a $6.4 million loss, though member personal information was not compromised. The social engineering attack prompted involvement from federal and local law enforcement, with investigators expressing optimism about recovering most stolen funds, which were also insured. Forensic reviews confirmed no breach of the union's email systems. In response, the organization enhanced employee cybersecurity training, revised wiring procedures, and advised members to limit sensitive information shared online to reduce future targeting risks. The union represents approximately 3,000 pipefitters, welders, and HVAC-refrigeration workers, assuring members their benefits remained unaffected.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A cyberattack targeting the Pipefitters Local 537 labor union's health fund was discovered on February 7, 2023, resulting in the theft of $6.4 million. Union business manager Daniel O'Brien notified members that federal and local law enforcement agencies were immediately alerted to the incident, while the union retained a cybersecurity forensic investigator to examine the breach. Officials determined the attack utilized social engineering methods rather than technical system vulnerabilities, with investigators concluding there was no evidence of unauthorized access to the fund office's email servers. The investigation confirmed that personal information of the union's approximately 3,000 members—including pipefitters, welders, and HVAC-refrigeration workers—remained uncompromised throughout the incident. O'Brien reassured members that their benefits remained unchanged and emphasized the health fund's continued financial stability despite the theft.

Law enforcement expressed optimism about recovering the majority of stolen funds, supplemented by the health fund's existing insurance coverage. In response to the attack, the union implemented enhanced cybersecurity training for all employees and revised wire transfer authorization protocols to prevent future incidents. O'Brien advised members to exercise caution with their online and social media presence, noting these platforms provide cybercriminals with reconnaissance opportunities. The union did not disclose specific technical details about fund transfer mechanisms exploited during the attack or identities of suspected threat actors. No further public updates were provided regarding the FBI's investigation, as the agency declined to comment when contacted by media.
