<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1027" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="720" style="width:7.5in;border-collapse:collapse">
<tbody>
<tr style="height:1.3in">
<td width="720" valign="top" style="width:7.5in;padding:0in 0in 0in 0in;height:1.3in">
<p class="MsoNormal"><!--[if gte vml 1]><v:shapetype id="_x0000_t75" coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f">
<v:stroke joinstyle="miter" />
<v:formulas>
<v:f eqn="if lineDrawn pixelLineWidth 0" />
<v:f eqn="sum @0 1 0" />
<v:f eqn="sum 0 0 @1" />
<v:f eqn="prod @2 1 2" />
<v:f eqn="prod @3 21600 pixelWidth" />
<v:f eqn="prod @3 21600 pixelHeight" />
<v:f eqn="sum @0 0 1" />
<v:f eqn="prod @6 1 2" />
<v:f eqn="prod @7 21600 pixelWidth" />
<v:f eqn="sum @8 21600 0" />
<v:f eqn="prod @7 21600 pixelHeight" />
<v:f eqn="sum @10 21600 0" />
</v:formulas>
<v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect" />
<o:lock v:ext="edit" aspectratio="t" />
</v:shapetype><v:shape id="Picture_x0020_1" o:spid="_x0000_s1026" type="#_x0000_t75" style='position:absolute;margin-left:0;margin-top:0;width:540.6pt;height:94.3pt;z-index:251659264;visibility:visible;mso-wrap-style:square;mso-width-percent:0;mso-height-percent:0;mso-wrap-distance-left:9pt;mso-wrap-distance-top:0;mso-wrap-distance-right:9pt;mso-wrap-distance-bottom:0;mso-position-horizontal:absolute;mso-position-horizontal-relative:text;mso-position-vertical:absolute;mso-position-vertical-relative:text;mso-width-percent:0;mso-height-percent:0;mso-width-relative:page;mso-height-relative:page'>
<v:imagedata src="cid:image001.png@01D2CB38.16161A00" o:title="" />
</v:shape><![endif]--><![if !vml]><span style="mso-ignore:vglayout;position:absolute;z-index:251659264;margin-left:0px;margin-top:0px;width:721px;height:126px"><img width="721" height="126" style="width:7.5104in;height:1.3125in" src="cid:image002.png@01D2CB38.16161A00" v:shapes="Picture_x0020_1"></span><![endif]><o:p></o:p></p>
</td>
</tr>
<tr>
<td width="720" style="width:7.5in;padding:0in .5in 0in .5in">
<p class="MsoNormal" align="right" style="margin-bottom:6.0pt;text-align:right;mso-line-height-alt:1.15pt;text-autospace:none">
<b><span style="font-size:20.0pt;color:#7F7F7F">Fraud Alert</span></b><b><span style="font-size:14.0pt"><o:p></o:p></span></b></p>
</td>
</tr>
<tr>
<td width="720" valign="top" style="width:7.5in;padding:0in .5in 0in .5in">
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<b><span style="font-size:14.0pt;color:#17365D">Spear Phishing<o:p></o:p></span></b></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626">All organizations, including state agencies and other governmental entities, must be vigilant in combatting ever-sophisticated cybercriminals. Spear phishing, in which cybercriminals use target-specific approaches and social engineering,
 is a particularly challenging scam that often circumvents traditional technological defenses such as spam filters.<o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626">One Treasury customer recently fell victim to a spear phishing attack based on a legitimate vendor relationship. The customer has been paying the vendor via direct deposit since May 2016. Last month, the customer received an e-mail
 that appeared to be from the vendor’s CEO requesting a change to the bank account information used to process payments. In actuality, the e-mail was sent by a cybercriminal. The customer replied with a request for further documentation, which the cybercriminal
 fraudulently provided. The customer subsequently sent a direct deposit payment to what the customer thought was the vendor’s new bank account. A few days after the payment was sent, the vendor contacted the customer indicating payment had not been received.
 It was then discovered that the updated bank account information had not been provided by the vendor but that the customer had been defrauded by a cybercriminal. The customer is currently working with law enforcement, and fraud departments at both the originating
 and receiving banks, in an effort to recover some or all of the payment.<o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<b><span style="font-size:12.0pt;color:#17365D">How to Protect Your Organization<o:p></o:p></span></b></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626">While spear phishing is a sophisticated scam that relies on inside information, there are processes that your organization can use to avoid becoming a victim. In the example above, the customer could have uncovered the attempted
 fraud by calling the vendor at a known phone number and speaking with an authorized individual in order to confirm the requested change. When performing such a call-back process, it is important to use a phone number already on file and
<i>not</i> one provided with the requested change.<o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626">For more tips related to spear phishing and other social engineering attacks, visit the U.S. Computer Emergency Readiness Team’s website at
</span><span style="color:#17365D"><a href="https://www.us-cert.gov/ncas/tips/ST04-014"><span style="color:#17365D">https://www.us-cert.gov/ncas/tips/ST04-014</span></a></span><span style="color:#262626">.<o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<span style="color:#262626"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify;mso-line-height-alt:1.15pt;text-autospace:none">
<o:p> </o:p></p>
</td>
</tr>
<tr style="height:.25in">
<td width="720" style="width:7.5in;background:#17365D;padding:0in 0in 0in 0in;height:.25in">
<p class="MsoNormal" align="center" style="text-align:center"><span style="font-size:9.0pt;color:white">350 Winter Street NE, Suite 100 | Salem, OR 97301-3896 | Phone (503) 378-4000 |
</span><a href="http://www.oregon.gov/treasury"><span style="font-size:9.0pt;color:white;text-decoration:none">www.oregon.gov/treasury</span></a><span style="color:white"><o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>