Threat Alert

Fake SSA "Statement" Emails Are Coming From Real, Compromised Government Mail Servers

When SPF, DKIM, and DMARC all pass — and the email is still malware

Published August 4, 2026 • OpenEFA Security Operations

Summary

OpenEFA has been tracking a recurring U.S. Social Security Administration (SSA) impersonation campaign since May 2026. Victims receive a professional-looking email — "Your Retirement Estimate is now available" or "Social Security Administration Statement" — with a button to download their "statement." The download is a Windows malware lure, not a document.

The newest wave, analyzed today, marks a significant escalation: the mail is injected through the compromised mail server of a national government ministry (Argentina's Ministry of Foreign Affairs, mrecic.gov.ar). Because the phishing leaves that server exactly like legitimate ministry mail does, it passes SPF, DKIM, and DMARC — every authentication check — and major mailbox providers delivered it straight to the inbox.

Why this matters: most email security tooling leans heavily on sender authentication and sender reputation. A phish sent from genuine government infrastructure with a valid DKIM signature defeats both. Content and intent analysis are the only signals left — which is exactly where filtering has to be strong.

↓ Download the full technical report (PDF) — complete header forensics, infrastructure attribution, campaign timeline, and IOC set.

The Lure

The campaign rotates sending infrastructure roughly monthly — we have intercepted four distinct waves since May across OpenEFA-protected domains, every one caught by content, intent, and infrastructure analysis at scores far above quarantine thresholds.

A Pattern of Compromised Government Mail Servers

This is the fourth distinct Argentine government mail system we have observed abused by spammers and phishers in the last 90 days — municipal governments, a provincial tax agency, and now a federal ministry. That cadence suggests systematic credential theft or underground resale of access to .gov.ar mail infrastructure.

Notably, the ministry's own spam filter scored the phishing message below its tagging threshold — including a whitelist bonus for being internal mail. Compromised infrastructure doesn't just relay abuse; it vouches for it.

What We Did

Blocked everywhere, immediately. The phishing domain, landing host, hosting IP, and surrounding network range were blocked on OpenEFA systems and pushed to the EFA Collective threat intelligence network, protecting every participating node. Neither major public feed (PhishTank, URLhaus) knew the domain at analysis time.
Takedown and notification. Same-day abuse reports were accepted by the domain registrar, Argentina's national CERT (CERT.ar), the affected ministry's postmaster, and both parties responsible for the hosting network. The victim organization was given full log-correlation data to find and close the compromised account.
Victim infrastructure protected. The compromised ministry domain and mail server were deliberately excluded from all block contributions — they are victims, and blocking them would punish legitimate government mail once the compromise is cleaned up.

Guidance for Users

The SSA never emails your statement or a download link. To check your Social Security statement, type ssa.gov into your browser yourself and sign in to my Social Security.
"Windows only" documents are a red flag. Any emailed "document" that requires a specific operating system to open is an executable, not a document.
If you clicked and ran a download, treat the machine as compromised: disconnect it from the network and contact your IT team or security provider immediately.

Indicators of Compromise

Defanged. Defenders are welcome to use these freely.

IndicatorTypeNotes
ssagv[.]comDomainSSA lookalike, registered 2026-07-21 (NICENIC)
estatement.ssagv[.]comHostnamePhishing / payload landing host
hxxps://estatement.ssagv[.]com/statementURLWindows payload download page
102.220.160[.]197IPv4Landing host (AS197769, leased AFRINIC space)
102.220.160[.]0/22CIDRHosting range with prior webshell/botnet listings
Subject: "Social Security Administration Statement RS 02205.225"LureAlso: "Your Retirement Estimate is now available"

Do not block: mrecic.gov.ar and its mail servers are compromised victim infrastructure, not attacker assets.

The Takeaway

Email authentication tells you a message came from where it claims to come from. It cannot tell you the sender's infrastructure hasn't been stolen. In our telemetry, a majority of confirmed spam now passes full authentication — and campaigns like this one show attackers deliberately acquiring authenticated infrastructure because they know reputation-based filters trust it.

Filtering has to judge what a message is trying to do, not just who signed it. That intent-first philosophy is the core of how OpenEFA caught every prior wave of this campaign — and why this wave was blocked across the EFA Collective within hours of analysis.

Download the Full Threat Intelligence Report

Report EFACI-TI-2026-0804-01 (PDF) — complete technical analysis: full header and authentication forensics, infrastructure attribution, campaign timeline since May 2026, the complete IOC set, and defender recommendations.

Enter your details below and we'll provide the download instantly. You'll also be registered to receive future OpenEFA threat-intelligence advisories by email.

We respect your privacy. Your information will not be shared with third parties. You can unsubscribe from advisory updates at any time.

Questions about this alert? Contact support@openefa.com.