OpenEFA has been tracking a recurring U.S. Social Security Administration (SSA) impersonation campaign since May 2026. Victims receive a professional-looking email — "Your Retirement Estimate is now available" or "Social Security Administration Statement" — with a button to download their "statement." The download is a Windows malware lure, not a document.
The newest wave, analyzed today, marks a significant escalation: the mail is injected through the
compromised mail server of a national government ministry (Argentina's Ministry of Foreign
Affairs, mrecic.gov.ar). Because the phishing leaves that server exactly like legitimate ministry
mail does, it passes SPF, DKIM, and DMARC — every authentication check — and major mailbox
providers delivered it straight to the inbox.
↓ Download the full technical report (PDF) — complete header forensics, infrastructure attribution, campaign timeline, and IOC set.
ssa.gov, and a real SSA policy
reference (POMS RS 02205.225) in the subject line for authenticity.ssagv[.]com ("ssa.gov" squeezed into one word). Every other link in the email is dead.The campaign rotates sending infrastructure roughly monthly — we have intercepted four distinct waves since May across OpenEFA-protected domains, every one caught by content, intent, and infrastructure analysis at scores far above quarantine thresholds.
This is the fourth distinct Argentine government mail system we have observed abused by
spammers and phishers in the last 90 days — municipal governments, a provincial tax agency, and now a federal
ministry. That cadence suggests systematic credential theft or underground resale of access to
.gov.ar mail infrastructure.
Notably, the ministry's own spam filter scored the phishing message below its tagging threshold — including a whitelist bonus for being internal mail. Compromised infrastructure doesn't just relay abuse; it vouches for it.
ssa.gov into your browser yourself and sign in to my Social Security.
Defanged. Defenders are welcome to use these freely.
| Indicator | Type | Notes |
|---|---|---|
ssagv[.]com | Domain | SSA lookalike, registered 2026-07-21 (NICENIC) |
estatement.ssagv[.]com | Hostname | Phishing / payload landing host |
hxxps://estatement.ssagv[.]com/statement | URL | Windows payload download page |
102.220.160[.]197 | IPv4 | Landing host (AS197769, leased AFRINIC space) |
102.220.160[.]0/22 | CIDR | Hosting range with prior webshell/botnet listings |
| Subject: "Social Security Administration Statement RS 02205.225" | Lure | Also: "Your Retirement Estimate is now available" |
Do not block: mrecic.gov.ar and its mail servers are compromised
victim infrastructure, not attacker assets.
Email authentication tells you a message came from where it claims to come from. It cannot tell you the sender's infrastructure hasn't been stolen. In our telemetry, a majority of confirmed spam now passes full authentication — and campaigns like this one show attackers deliberately acquiring authenticated infrastructure because they know reputation-based filters trust it.
Filtering has to judge what a message is trying to do, not just who signed it. That intent-first philosophy is the core of how OpenEFA caught every prior wave of this campaign — and why this wave was blocked across the EFA Collective within hours of analysis.
Report EFACI-TI-2026-0804-01 (PDF) — complete technical analysis: full header and authentication forensics, infrastructure attribution, campaign timeline since May 2026, the complete IOC set, and defender recommendations.
Enter your details below and we'll provide the download instantly. You'll also be registered to receive future OpenEFA threat-intelligence advisories by email.
Questions about this alert? Contact support@openefa.com.