Law.com
  • News
    • Newswire
    • Supreme Court
    • International
    • Legal Blog Watch
    • The Hot Seat
    • Video
  • Publications
    • The American Lawyer
    • Corporate Counsel
    • Law Technology News
    • The National Law Journal
    • New York Law Journal
    • New Jersey Law Journal
    • Connecticut Law Tribune
    • The Legal Intelligencer (PA)
    • Daily Business Review (FL)
    • Delaware Law Weekly
    • Daily Report (GA)
    • The Recorder (CA)
    • Texas Lawyer
    • Publication E-Alerts
    • More Publication Sites
  • Legal Research & Directories
    • Books Online
    • Smart Litigator
    • ALM Experts
    • Verdict Search
    • Court Reporters
    • Legal Dictionary
    • LegalTech® Directory
    • Newsletters
    • More Directories
  • Surveys, Lists & Rankings
    • Amlaw 100
    • NLJ 250
    • Global 100
    • The A-List
    • ALM Legal Intelligence
    • Surveys
    • More Lists & Rankings
  • Special Reports
  • lawjobs.com
  • LawCatalog Store
  • CLE & Events
    • CLE Center
    • ALM Events
    • LegalTech
    • Virtual LegalTech
    • Insight Legal Events
    • Webinars
Home
 
Article
Twitter LinkedIn RSS
Sign Up for Newsletters

Law.com Home > Businesses Hit With E-Mail Blast of Virus-Carrying Pseudo-Subpoenas

Font Size: increase font decrease font

Businesses Hit With E-Mail Blast of Virus-Carrying Pseudo-Subpoenas

By Mary Pat Gallagher All Articles 

New Jersey Law Journal

April 16, 2008

  •    
  •    
  •    
  •      
 

Related Items

  • 'Tasting,' 'Kiting' Domain Names for Profit
  • Corporate Computer Security Breaches May Be Down, but Costs per Breach Are Rising

Thousands of executives received e-mails on Monday purporting to be federal court subpoenas but which appear to be part of a "phishing" scam to capture sensitive data.

The pseudo-subpoenas bear the seal of the U.S. District Court and docket numbers from real cases, though apparently closed ones, without party names. They command an appearance on May 7 before a grand jury in a particular room at the U.S. courthouse in San Diego.

They identify the originating e-mail address as "subpoena@uscourts.com" and contain a link with an instruction to "download the entire document on this matter ... and print it for you record."

Those who click on the link infect their own computers and those networked to them with a virus aimed at gathering passwords, account numbers, credit card numbers and similar information. Matt Richard, of VeriSign's iDefense Labs, a cybersecurity group, estimates that 1,800 recipients have clicked on the link.

The subpoenas indicate they were issued by "O'Mevely & Meyers," a fictitious entity with the same Los Angeles address as the real firm of O'Melveny & Myers. The name is close enough that O'Melveny has posted a notice on its Web site stating it is not the source of the subpoenas.

The Administrative Office of the U.S. Courts posted an alert on its Web site on Monday after receiving a large number of calls. Captioned "Notice: Invalid Subpoena," it says e-mails containing grand jury subpoenas "are not a valid communication from a federal court and may contain harmful links." It reminds that the judiciary's address ends in ".gov" and says law enforcement authorities have been notified.

Similar warnings have been posted by several district courts, including the Southern District of California (which includes San Diego), the Central District of California and the Southern District of West Virginia.

Scott Christie, of McCarter & English in Newark, says he learned of the scam Monday from the online forum of the American Bar Association's Information Security Committee. Another member described one of the subpoenas and asked whether anyone else had seen one like it and whether it seemed legitimate.

Based on a number of "blatant red flags," that went well beyond the misspelling of O'Melveny & Myers, the subpoena was clearly suspect, says Christie, a former Assistant U.S. Attorney who once headed up the New Jersey office's Computer Hacking and Intellectual Property Section.

Perhaps the most significant tip-off was that "federal courts will never send you a subpoena by e-mail," he says. A subpoena in a civil case comes from the other side's attorney and, in a criminal case, from the U.S. Attorney's Office and, if from the court, by registered or certified mail, says Christie.

In addition, people were being told to appear before a criminal grand jury in a civil case and that if they had any questions about a subpoena designated as federal, to ask the "City Prosecutor." There were also misspellings such as "thas," "offcers" and "wich."

Christie sent an advisory to all McCarter & English lawyers and heard back from those whose clients had contacted them after receiving similar missives. He says the subpoenas "were going to CEOs and upper levels of management of companies who were calling lawyers and saying 'what do I do?'" He says he saw about a dozen "subpoenas" received by firm clients, but to his knowledge, none of them clicked on the link.

'SPEAR-PHISHING'

The bogus subpoena blast appears to be a variant on "phishing," which uses legitimate-looking e-mails to lure people to sites that infect their computers or induce them to input credit card, bank account or other data, exposing them to financial loss.

The subpoenas were "spear-phishing," a more targeted version of phishing, where the scam is geared to a specific type of recipient, says Christie.

The CEOs and upper-management personnel at whom the e-mails were directed "would be more likely than most to be concerned about the receipt of a federal grand jury subpoena" and "be inclined, without speaking to anyone, to click on the link and suffer the consequences," says Christie.

Verisign has been keeping tabs on a group of cyberscammers responsible for similar phishing incidents, in which e-mails used to induce clicks appeared to be from the Internal Revenue Service and the Better Business Bureau.

Based on that experience, VeriSign was able to track the data obtained from the affected computers to a "drop site" located on a server in Singapore. VeriSign is working with law enforcement, Richard says, declining to be more specific.

Historically about 10 percent of those phished go for the bait, says Richard, leading him to estimate that 15,000 to 20,000 e-mails were sent.

Christie says lawyers should be warning their clients, and because unexpected future variants are likely, people should "review their e-mail messages carefully and if there are misspellings or other indicia of impropriety or fraud, immediately contact their attorney."



Subscribe to New Jersey Law Journal

Find similar content

Firms mentioned

    
  • McCarter & English
  • O'Melveny & Myers

Companies, agencies mentioned

    
  • VeriSign
  • US District Court
  • iDefense Labs
  • O'Mevely & Meyers
  • Administrative Office of the U.S. Courts
  • Southern District of West Virginia.Scott Christie
  • American Bar Association
  • Information Security Committee
  • Internal Revenue Service

Key categories

    
  • Information Security

Most viewed stories

    
  1. Court Officials Seek to Reform Process of Naming Acting Justices
    •      
  2. The 2013 Am Law 100
    •      
  3. Prolific ADA Plaintiff Faces Nemesis in Harassment Suit
    •      
  4. Lawyers Sanctioned Over Porn Lawsuits File Appeal
    •      
  5. Law for Laymen
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Hiring Summer Interns? Make Sure You Do It Right

ACC Weighs in on Arizona's In-House Pro Bono Rules

Ex-Dewey Partners Face New Foe in Firm's Bankruptcy

S&C Adds Linklaters Restructuring Partner in London
  •      
    • Subscription Required

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Enron Sandbox Stirs Up Private Data, Again

LegalTech West Coast Wraps Up With Ethics, VC News

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

Summer Programs Still in a Drought

Lawyer Left Without Coverage for Alleged Malpractice at Prior Firm
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Circuit Reinstates Lawsuit by Inmate Over Cell Conditions
  •      
    • Subscription Required

Custody Ruling in Bitter Fight May Turn on 11-Year-Old's Wish
  •      
    • Subscription Required

Castille Testifies in Favor of 'Civil Gideon' Funding

Workers' Comp Judges Can't Fight Rescinded Raise
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Others Over Deepwater Oil Spill Disaster
  •      
    • Subscription Required

Filing Blunder To Cost $142,600
  •      
    • Subscription Required

Court: Injured College Student Can't Sue State
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media