Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
State warns vendors of phishing campaign impersonating Utah ID
Summary
DHHS warned state contractors about a phishing campaign impersonating Utah ID and advised verifying utah.gov senders, avoiding clicking links/attachments, and using official sites or known contact numbers to confirm messages.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Josie relayed a cybersecurity alert from state purchasing: a phishing campaign is targeting Utah contracted vendors by impersonating "Utah ID," the login system vendors use for state business. The scams typically use fake emails or texts that pressure recipients to act quickly (confirm account details, reset passwords or click links) and may lead to malware or credential theft.
"So this campaign is masquerading as Utah ID," Josie said. She advised vendors to verify senders (official messages originate from utah.gov), avoid clicking suspicious links or downloading attachments, and when in doubt to go directly to the official site or contact the vendor by a known phone number. Josie offered to distribute guidance from the Utah Cyber Center after the call to help vendors identify red flags (poor grammar, misspellings, unfamiliar language).
State staff recommended vendor partners check URLs carefully, look for utah.gov senders, and report suspected phishing to the appropriate state cybersecurity contacts. DHHS planned to drop the Utah Cyber Center guidance in the meeting chat and follow up by email.

