I recently received a phone call from a Cybersecurity Advisor at CISA informing me that an account belonging to one of my users had been compromised between January and July of this year. They provided a list of recommendations and followed up with an email. The email appeared to be from a legitimate CISA address. I'm feeling pretty suspicious about the call, but it also seems legit. Has anyone else had a similar experience, and how can I verify if this person is authentic?
5 Answers
I contacted CISA myself, and they confirmed the legitimacy of the email. The Cybersecurity Advisor was super helpful and responded quickly to my queries! It’s nice to know they’re proactive in reaching out.
Make sure to validate the call by contacting CISA directly at (844) SAY-CISA. You can find more details on potential scammers impersonating CISA on their official site. It's always good to double-check even if it seems real.
Government communications can look suspicious at times with inconsistent signatures or strange email formats. Just keep an eye out for any red flags in the communication you received.
CISA does reach out for certain issues. Just ensure you don't click on any links or download attachments unless you've verified everything. Scammers can be very convincing!
It's likely legit. CISA often reaches out via public numbers if they can't get through otherwise. If the email's SPF records match, that's a good sign!

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures