WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Phishing Campaign Sets Sights on C-Suite
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partnerships
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Phishing Campaign Sets Sights on C-Suite

Author: ian_41208

Created: Thursday, October 5, 2023 - 18:47

Categories: Cybersecurity

In a recent report from Menlo Security, it was discovered that “Indeed,” a widely recognized global job search platform headquartered in the U.S., boasting over 350 million monthly visitors and a global workforce of more than 14,000 employees, has become the focus of a significant phishing campaign. This campaign underscores the pervasive threat of abusing trust and how actors exploit credible and popular platforms.

Beginning in July 2023, Menlo Security observed adversaries exploiting an open redirection vulnerability within the indeed[.]com website to redirect victims to a phishing page designed explicitly to pilfer Microsoft credentials. The primary targets of these attacks were C-suite executives and other high-ranking personnel in industries such as banking, financial services, insurance, property management, real estate, and manufacturing, with a particular emphasis on the U.S. Menlo Security reported both the open redirection issue and the observed malicious activities to Indeed. However, it remains uncertain whether the job search platform has taken measures to address the issue.

The exploitation of Indeed used in this campaign takes advantage of executives and other senior level staff looking for employment candidates and represents a watering hole style compromise. Watering hole attacks are nearly impossible for an end-user to proactively detect. However, following general cyber hygiene can help mitigate potential fall out after visiting a compromised website. Best practices include keeping all software, including non-security applications, up to date by conducting regular vulnerability scans and applying security patches. Additionally, employing secure web gateways (SWG) can help filter out web-based threats and enforce acceptable use policies. Furthermore, members are encouraged to include reminders of watering hole attacks as part of security awareness and training. Read more at Menlo Security.

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar