Secretary of the State Stephanie Thomas Warns Businesses of Spoofing Email Scam 

9 views
Skip to first unread message

Clyburn, Matthew

unread,
Jun 1, 2026, 5:14:01 PMJun 1
to Clyburn, Matthew
FOR IMMEDIATE RELEASE 
June 1, 2026
Secretary of the State Stephanie Thomas Warns Businesses of Spoofing Email Scam 
HARTFORD — Secretary of the State Stephanie Thomas is warning all Connecticut businesses to avoid a malicious email circulating that claims to be from the Connecticut Business Registry. 
The email contains a malicious Team OpenSign link that prompts the user to review and sign an undisclosed digital document. This type of attack is known as "spoofing," where the sender changes the "from" address to make the email appear to come from a legitimate source—in this case, the Office of the Secretary of the State (SOTS).
This technique tricks users into clicking malicious links and revealing sensitive information to cybercriminals, which can include login credentials, money transfers, or the download of malware.
"Cybercriminals are getting more sophisticated, and it’s critical that businesses stay alert," said Secretary Thomas. "Our office will never send unsolicited documents for signature. If something feels off, trust your instincts and verify before you click."
How to Identify and Prevent Attacks
Unfortunately, our Office cannot prevent these types of attacks. Our best defense is an informed and vigilant public.
  • Official Emails: Emails from the Office of the Secretary of the State will always come from a @ct.gov email address.
  • Verify the Sender: All standard email applications allow recipients to see the real sender by hovering over or clicking on the “from” address. If this process reveals an address that is not @ct.gov, the email does not come from the state and should not be trusted.
  • Be Careful with Lookalike Domains: Hackers are sophisticated. While checking the email address is essential, you must remain suspicious even if the email appears to be official. Criminals can trick you by using a very similar-looking address (like @cct.gov or @ct-gov.org), hoping you won't notice the small difference.
Key Security Reminders
  • Do not respond to or click any links in an email you suspect is malicious.
  • All official business filings can be accomplished by going directly to business.ct.gov and logging in. If you are suspicious of a link, even in an email from @ct.gov, do not click it. While the Business Services Division may include quick links for convenience, it is never necessary to click a link to make a business filing.
  • Never give your business.ct.gov credentials to anyone and turn on Multi-Factor Authentication (MFA) for added security.
Current Alert
A spoof email is currently circulating statewide with a malicious Team OpenSign link. It appears to be sent from the CT SOTS Business Registry. This email is a malicious phishing attempt used to steal your credentials and compromise your devices. DO NOT click on the links. 
Subscribe to Business News for Monthly Resources
If you’d like more information, resources, and alerts like this, click here to sign up for the Secretary of the State’s monthly Business News e-newsletter.
* * *
Contact: Matthew Clyburn
Matthew...@ct.gov
(959) 274-6725

LEGAL NOTICE: Certain communications or records received by or sent from this electronic mail account may be subject to public disclosure pursuant to the Connecticut Freedom of Information Act, Conn. Gen. Stat. § 1-200 et seq. Nothing in this email shall be relied upon as an official opinion of the Office of the Secretary of the State issued pursuant to C.G.S. Sec. 9-3 unless specifically stated as such.

Secretary of the State Stephanie Thomas Warns Businesses of Spoofing Email Scam.pdf

Clyburn, Matthew

unread,
Jul 28, 2026, 10:59:04 AM (yesterday) Jul 28
to Clyburn, Matthew
FOR IMMEDIATE RELEASE   
July 28, 2026 
Secretary Thomas Warns Businesses of Phishing Email Impersonating Connecticut Business Registry   
HARTFORD — Secretary of the State Stephanie Thomas is warning all Connecticut businesses to avoid a malicious email circulating that claims to be from the Connecticut Business Registry. Do not click on the links. 
 
The email contains a malicious DottedSign link that prompts the user to view and sign a digital document. This technique tricks users into revealing sensitive information to cybercriminals, which can include login credentials, money transfers, or the download of malware. 
“Cybercriminals are getting more sophisticated, and it’s critical that businesses stay alert,” said Secretary Thomas. “Our office will never send unsolicited documents for signature. If something feels off, trust your instincts and verify before you click.” 
How to Identify and Prevent Attacks 
Unfortunately, our office cannot prevent these types of attacks. Our best defense is an informed and vigilant public. 
  • Official Emails: Emails from the Office of the Secretary of the State will always come from a @ct.gov email address.  
  • Verify the Sender: All standard email applications allow recipients to see the real sender by hovering over or clicking on the “from” address. If this process reveals an address that is not @ct.gov, the email does not come from the state and should not be trusted.  
  • Be Careful with Lookalike Domains: Hackers are sophisticated. While checking the email address is essential, you must remain suspicious even if the email appears to be official. Criminals can trick you by using a very similar-looking address (like @cct.gov or @ct-gov.org), hoping you won't notice the small difference. 

Key Security Reminders 
  • Do not respond to or click any links in an email you suspect is malicious. 
  • All official business filings can be accomplished by going directly to business.ct.gov and logging in. If you are suspicious of a link, even in an email from @ct.gov, do not click it. While the Business Services Division may include quick links for convenience, it is never necessary to click a link to make a business filing.  
  • Never give your business.ct.gov credentials to anyone and turn on Multi-Factor Authentication (MFA) for added security. 

If something feels off and you need to validate the authenticity of a communication from the Office of the Secretary of the State, contact our Business Services Division at b...@ct.gov
Secretary Thomas Warns Businesses of Phishing Email Impersonating Connecticut Business Registry.pdf
Reply all
Reply to author
Forward
0 new messages