WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts CISA and FBI Warn of Sophisticated Campaign Targeting Government Organizations, IGOs, and NGOs
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA and FBI Warn of Sophisticated Campaign Targeting Government Organizations, IGOs, and NGOs

Author: Charles Egli

Created: Tuesday, June 1, 2021 - 13:35

Categories: Cybersecurity

The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued an alert regarding a sophisticated spearphishing campaign targeting government organizations, intergovernmental organizations (IGOs), and non-governmental organizations (NGOs). They note a sophisticated cyber threat actor leveraged a compromised end-user account from Constant Contact, a legitimate email marketing software company, to spoof a U.S.-based government organization and distribute links to malicious URLs. CISA and FBI have not determined that any individual accounts have been specifically targeted by this campaign. The alert contains information on tactics, techniques, and procedures (TTPs) and malware associated with this campaign. CISA and FBI urge governmental and international affairs organizations and individuals associated with such organizations to adopt a heightened state of awareness and implement the recommendations in the Mitigations section of this advisory. Access the alert at CISA or below.

With the release of the alert, they acknowledge recent open-source reporting attributing this activity to APT29. Also known as Nobelium, Microsoft released an alert on a new campaign by this group late last week, which WaterISAC reported on in an advisory sent to members on Friday. However, CISA and FBI report they are investigating this activity and have not attributed it to any threat actor at this time.

Attached Files:

AA21-148A-Sophisticated_Spearphishing_Campaign

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar