Published Staff Contacts Raise the Value of Phishing

Published names and work email addresses make impersonation easier. The usual breach response is to look for stolen passwords, but here the exposed directory data can be used to make fake messages look like they came from a real colleague, service desk, or government contact. PNLD said its July 26 incident exposed contact details for police officers, police staff, criminal justice professionals, government partners, customers, and some Ask the Police users. It said there is no evidence that passwords or other security credentials were taken, and it has notified affected organizations and users. For UK police, justice, and government teams that publish staff contact details, the risk now sits in the inbox. A public name plus a work address is enough to make spearphishing and credential-harvest attempts harder to spot.

Sources