I might as well report this here, as there could be more attacks like this in the future, criminals. They are leveraging Federal Communications Commission (FCC) employees pages for Okta that appear similar to the original.
However, for us, this criminals already uses the same method to target and impersonate okta and uses phishing page for Binance, Coinbase, Kraken and Gemini.
Here is a sample message potential victims received from the groups.
And with that, I think the success of this kind of phishing attempts is very complicated but could be base on the following.
- they uses well crafted phishing URL that really looks similar to the original
- then the psychology of "sense of urgency", in SMS or voice calls from this threat actor.
https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kitSo it's better safe than sorry, as we need to be very cautious not only in email, now the attacks is thru SMS and voice mail.