Large mailings, such as newsletters and invitations, are increasingly sent via specialized platforms like Flexmail or Mailchimp. While these tools are convenient and efficient for high volumes, they also present a potential security risk. They often provide direct access to the contact details of thousands of an organization's contacts.
When such a platform is hacked, attackers can send phishing emails from an official e-mail address. This makes the communication more credible to the target audience, as it appears to come from a trusted source. A recent incident involving the hacking of the e-mail sending system of the Flemish Department of Mobility and Public Works exemplifies this. Phishing emails were widely distributed from an official address.
This incident highlights that cyber risks do not stop at an organization's own boundaries. External service providers can also be a weak link in the digital chain. Local governments, police zones, schools, and other organizations working with external digital services must be aware of this. These platforms can hold vast amounts of contact data, registration details, mailing lists, and communication history.
To enhance cybersecurity, it is crucial to inventory all external platforms used by an organization and to know where data is stored. Extra securing of accounts with multi-factor authentication (MFA) and limiting administrator rights are important steps. Furthermore, it is essential to verify the security measures of suppliers and establish clear procedures for incident response.
The European Cybersecurity Month in October, now in its tenth year, emphasizes the importance of online safety for citizens, businesses, and administrations. Mapping external digital platforms and their associated risks is a first step towards better security.




