Commission warns of phishing scam using fraudulent domain

  • The Guernsey Financial Services Commission has warned of a phishing scam using the fraudulent domain "gfsc.gg.verixsend.com"
  • Recipients are advised not to reply or click links, but to forward suspicious emails to a dedicated email address
  • Genuine Commission emails only come from domains ending in "gfsc.gg"
  • Firms are reminded of cyber security requirements including staff vigilance, security software and timely system updates
  • Any significant cyber security events must be reported to the Commission
audio-thumbnail
Listen to this article
0:00
/0

The Guernsey Financial Services Commission has issued a warning after discovering a phishing attempt targeting financial services firms using a fraudulent domain.

The scam emails purport to be from the Commission but are being sent from the domain "gfsc.gg.verixsend.com", which is not a legitimate Commission address.

The Commission has advised anyone who receives such an email not to reply or click on any links or attachments. Instead, recipients should forward the suspicious email to [email protected].

The regulator has reminded firms that all genuine Commission emails are sent only from domains ending in "gfsc.gg".

The warning comes as cyber criminals continue to target the finance sector with increasingly sophisticated attacks. Phishing attempts often seek to obtain sensitive information or install malware by impersonating trusted organisations.

The Commission has directed firms to its Cyber Rules and Guidance, published in 2021, which sets out requirements for protecting against cyber threats.

Key measures outlined in the guidance include ensuring staff exercise caution and vigilance by not clicking on or opening unfamiliar links in emails, maintaining appropriate cyber security software, implementing IT systems updates in a timely manner, and notifying the Commission if they are subject to a significant cyber security event.

Q&A

Q: How can I identify a genuine email from the Guernsey Financial Services Commission?
A: Genuine Commission emails are sent only from domains ending in "gfsc.gg". Any email claiming to be from the Commission using a different domain should be treated as suspicious.

Q: What should I do if I receive a suspicious email claiming to be from the Commission?
A: Do not reply or click on any links or attachments. Forward the email to [email protected] so the Commission can investigate.

Q: What cyber security measures are financial firms required to maintain?
A: The Commission's Cyber Rules and Guidance requires firms to ensure staff exercise caution with unfamiliar email links, maintain appropriate cyber security software, implement IT updates promptly, and notify the Commission of significant cyber security events.