Skip to Main Content

An official website of the Commonwealth of Massachusetts

Vendors Beware: New email scam targeting Commonwealth of Massachusetts vendors

The text "Cybersecurity Alert"

Another scam is targeting vendors to the Commonwealth of Massachusetts, in which fraudsters are using publicly available information to identify their targets.

In many of these cases, the fraudster is pretending to be a state agency. An example of a fraudulent email includes: “The Commonwealth of Massachusetts implemented a new Secure Email System on September 24, 2024. If this is the first Email you have received via this new system, you will be required to register before reading your message.”

These emails are phishing attempts. Do not follow any links in these emails, as they may be malicious. To be clear, the Commonwealth has not implemented a change in its email system.

Previous scams purported to represent the Commonwealth of Massachusetts, and requested that vendors submit an Electronic Funds Transfer (EFT) Authorization Form with banking information if they wish payments to continue.

Vendors are reminded that if they receive an unexpected link or attachment, or are asked to submit sensitive information such as banking info:
Pause and do not open any links/attachments, and do not submit the requested information until you have directly contacted a trusted source at the department with whom they are doing business. This should be done via phone, video call, or in person (not by email).

If you have been targeted in this way, please forward that email to [email protected], and the Office of the Comptroller will be in touch.