Nbcconnecticut Phishing Attack Compromises Emails at Connecticut DCF
Article Content
- •Phishing attack on Connecticut DCF compromised two staff email accounts.
- •Personal information may have been accessed; ongoing review of affected emails.
- •State agencies are collaborating with law enforcement for investigation.
On May 20, 2026, the Connecticut Department of Children and Families (DCF) reported a phishing incident that compromised email accounts of two staff members. The attack involved a sophisticated external phishing email that allowed the attacker to download emails from these accounts. The Department of Administrative Services (DAS) quickly expelled the attacker from state systems and removed the malicious email from all user inboxes. DCF is currently reviewing the affected emails to determine the extent of personal information or confidential records compromised. Notifications will be sent to affected individuals, offering credit monitoring and identity theft protection services. The incident has been referred to law enforcement, and the investigation is ongoing. DCF emphasizes the importance of cybersecurity training for state employees to prevent such attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Common questions
What personal information was compromised?
What steps is DCF taking to mitigate the impact?
How can state employees prevent phishing attacks?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…