CERT-BG Warning on Phishing Campaigns
On September 2025, the Bulgarian National Computer Security Incident Response Team (CERT-BG) issued a security alert about active phishing campaigns targeting state institutions and financial organizations. Attackers use fake domains mimicking government portals and banks to steal login credentials.
Facts
Malicious emails attempt to trick users into entering sensitive information on cloned websites.
Attackers leverage lookalike domains and SSL certificates to bypass suspicion.
CERT-BG recommends organizations implement SPF, DKIM, and DMARC policies, enforce MFA, and conduct employee awareness training.
Public sector and financial institutions are particularly targeted, but private businesses remain at risk.
Significance for Businesses
Phishing remains one of the most effective attack vectors, often leading to ransomware or data breaches.
Organizations without proper email security, monitoring, and awareness programs face higher risk.
This case highlights the importance of adopting Zero Trust principles and 24/7 monitoring.
DIAMATIX Perspective
Email is still the most exploited entry point for attackers. At DIAMATIX, we help organizations deploy AI-powered email filtering, MDRaaS, and Zero Trust Network Access, ensuring phishing attempts are detected and contained before they cause damage. Vigilance and proactive monitoring are key to protecting sensitive data in both the public and private sector.
Trusted · Innovative · Vigilant.






