CSIDB logo
Incident

Boston labor union

Incident posture

Attack window
Feb 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
Boston labor union
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting a Boston labor union's health fund resulted in a $6.4 million loss, though member personal information was not compromised. The social engineering attack prompted involvement from federal and local law enforcement, with investigators expressing optimism about recovering most stolen funds, which were also insured. Forensic reviews confirmed no breach of the union's email systems. In response, the organization enhanced employee cybersecurity training, revised wiring procedures, and advised members to limit sensitive information shared online to reduce future targeting risks. The union represents approximately 3,000 pipefitters, welders, and HVAC-refrigeration workers, assuring members their benefits remained unaffected.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A cyberattack targeting the Pipefitters Local 537 labor union's health fund was discovered on February 7, 2023, resulting in the theft of $6.4 million. Union business manager Daniel O'Brien notified members that federal and local law enforcement agencies were immediately alerted to the incident, while the union retained a cybersecurity forensic investigator to examine the breach. Officials determined the attack utilized social engineering methods rather than technical system vulnerabilities, with investigators concluding there was no evidence of unauthorized access to the fund office's email servers. The investigation confirmed that personal information of the union's approximately 3,000 members—including pipefitters, welders, and HVAC-refrigeration workers—remained uncompromised throughout the incident. O'Brien reassured members that their benefits remained unchanged and emphasized the health fund's continued financial stability despite the theft.

Law enforcement expressed optimism about recovering the majority of stolen funds, supplemented by the health fund's existing insurance coverage. In response to the attack, the union implemented enhanced cybersecurity training for all employees and revised wire transfer authorization protocols to prevent future incidents. O'Brien advised members to exercise caution with their online and social media presence, noting these platforms provide cybercriminals with reconnaissance opportunities. The union did not disclose specific technical details about fund transfer mechanisms exploited during the attack or identities of suspected threat actors. No further public updates were provided regarding the FBI's investigation, as the agency declined to comment when contacted by media.

Sources

Sources available to members: 1 source.

CSIDB