(01) - CybersecurityDMSA-2025-EC-001

Email Authentication Vulnerability in National Police of Ecuador

A flaw in the Ecuadorian National Police email servers allows attackers to send fraudulent emails appearing to come from official government accounts.

14 April 20252 min readCybersecurityReports

Executive Summary

Dymo's automated email security monitoring detected an email authentication vulnerability affecting the National Police of Ecuador (Policía Nacional del Ecuador). Attackers can send emails that appear to originate from official police addresses, enabling phishing campaigns and identity fraud.

Affected Entity

  • Organization: Policía Nacional del Ecuador
  • Country: Ecuador
  • Function: Law enforcement and public security
  • Type: Government email infrastructure

Vulnerability Details

Type

Email Spoofing / Authentication Misconfiguration

Severity

Medium-High (CVSS 7.2)

Technical Root Causes

  1. Missing DMARC: No domain protection against impersonation
  2. Broad SPF Rules: Allows sending from unauthorized servers
  3. No DKIM Signing: Emails cannot be cryptographically verified
  4. Legacy Infrastructure: Older systems without security controls

Attack Applications

Observed malicious activities:

  • Fake arrest warrants demanding payment
  • Phishing emails impersonating police investigations
  • Fake traffic violation notices
  • Fraudulent requests for personal information

Risk Assessment

This vulnerability poses significant risks because:

  • Authority abuse: Police impersonation carries high credibility
  • Fear tactics: Threat of legal action prompts compliance
  • Wide reach: Affects citizens, businesses, and institutions
  • Cross-border targeting: Can target individuals outside Ecuador

Responsible Disclosure

Reported to:

  • National Police IT Department
  • Ecuadorian Cybersecurity Center
  • Ministry of Interior

For the organization:

  1. Deploy DMARC policy (p=quarantine or p=reject)
  2. Implement DKIM signing across all mail servers
  3. Audit and restrict SPF configurations
  4. Establish email authentication monitoring

For citizens:

  1. Verify suspicious emails through official channels
  2. Never send money based on email instructions
  3. Report impersonation to proper authorities

This vulnerability was discovered through Dymo's automated government email security scanning.