CSA Warns Registrants About Malicious Impersonation Scam Emails
Summary
The Canadian Securities Administrators (CSA) has issued a warning to registrants about a malicious spear phishing scam. The emails impersonate the CSA and aim to obtain personal or confidential business information. Registrants are urged to be vigilant, verify sender addresses, and report suspicious emails.
What changed
The Canadian Securities Administrators (CSA) has issued a notice warning registered entities about a sophisticated spear phishing scam. The fraudulent emails impersonate the CSA, using a domain not associated with the organization, and are designed to trick recipients into revealing personal or confidential business information. The CSA emphasizes the importance of verifying sender authenticity and treating any suspicious communication with extreme caution.
Regulated entities receiving such emails are advised to delete them immediately and report them to their local securities regulator. If a link has been clicked or an attachment opened, individuals should take immediate steps to change passwords and notify their internal security departments. This notice serves as a reminder for vigilance against evolving cyber threats targeting financial professionals in Canada.
What to do next
- Verify the authenticity of all emails claiming to be from the CSA or its member organizations.
- Do not click on links or open attachments in suspicious emails.
- Report any suspected phishing emails to your local securities regulator and the CSA.
Source document (simplified)
Montreal – The Canadian Securities Administrators (CSA) is warning registrants about an email impersonating the CSA that uses publicly available information to target them. The emails are believed to be malicious “spear phishing” attempts by unknown individuals who are trying to obtain personal information or confidential business information. We urge all Canadians to be vigilant, to check the source, not to click links or provide any information.
The phishing email claims to be sent on behalf of the CSA but is from a domain (@securities-administrators.ca.cazepost.com) that is not associated with the CSA or any of its member organizations. Any information sent from this domain is not from the CSA and should be treated with extreme caution. Recipients should delete the email and report it to their local securities regulator.
The CSA strongly urges anyone receiving an email from the CSA to remain vigilant and consider the following:
Is the message from a real, consistent and verifiable email address?
Is the message from someone you know who works at the CSA or works in one of its member organizations?
Were you expecting this email?
If you have clicked on a link, or opened an attachment, it is important that you take immediate steps to change your passwords and inform your security department.
Should you receive a suspicious email claiming to be from the CSA contact us at CSA-ACVM-Secretariat@acvm-csa.ca.
The CSA, the council of the securities regulators of Canada’s provinces and territories, co-ordinates and harmonizes regulation for the Canadian capital markets.
For investor inquiries, please contact your local securities regulator .
For media inquiries, please contact:
- Ilana Kelemen Canadian Securities Administrators media@acvm-csa.ca
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Financial Regulation alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CSA News (Canadian Securities) publishes new changes.