(01) - CybersecurityDMSA-2025-CR-001
Email Authentication Vulnerability in Legislative Assembly of Costa Rica
A vulnerability in the Legislative Assembly of Costa Rica's email servers allows attackers to send fraudulent cryptocurrency-related campaigns from official addresses.
Executive Summary
Dymo identified an email authentication vulnerability in the Legislative Assembly of Costa Rica that enables attackers to send fraudulent emails from official legislative addresses. These emails are being used in cryptocurrency-related fraud campaigns.
Affected Institution
- Organization: Asamblea Legislativa de Costa Rica
- Type: Legislative Branch of Government
- Country: Costa Rica
- Domain: Assembly email infrastructure
Technical Details
Vulnerability Type
Email Spoofing - DMARC/SPF Misconfiguration
Severity
Medium (CVSS 6.8)
Root Causes
- Incomplete DMARC Implementation: No enforcement policy
- Open SPF Records: Excessive IP addresses allowed
- Missing DKIM: No email signing infrastructure
- No Authentication Monitoring: Unable to detect abuse
Attack Scenario
Attackers leverage the vulnerability to:
- Send fake legislative notifications
- Create urgency around fake deadlines
- Request cryptocurrency "donations"
- Distribute phishing links in official-looking emails
Cryptocurrency Fraud Context
Observed campaigns involve:
- Fake legislative initiatives requiring cryptocurrency contributions
- Phony refunds or payments in crypto
- Fraudulent investment opportunities impersonating the Assembly
- Fake job offers with cryptocurrency payment promises
Responsible Disclosure
This finding has been reported to:
- Legislative Assembly IT Department
- Costa Rica's national CERT
- Ministry of Science, Technology and Telecommunications
Recommended Actions
- Deploy strict DMARC policy immediately
- Implement email signing with DKIM
- Set up authentication monitoring
- Create public awareness about official email domains
This vulnerability was discovered through Dymo's automated government sector scanning.