The FBI Internet Crime Complaint Center and the Cybersecurity and Infrastructure Security Agency warned corporate security teams Friday that proxy auto-configuration phishing kits are targeting remote workers through fake IT help-desk pages that push malicious PAC files into browser settings before multi-factor authentication completes, a shift investigators tied to 312 complaints logged since August across finance, healthcare, and municipal contractors.
What broke
Attackers email links styled as VPN or password-expiration notices. Victims who approve a “network diagnostics” download install a PAC file that routes traffic for banking, cloud admin, and payroll domains through attacker-controlled HTTPS proxies. Because the proxy sits below the application layer, one-time codes and push approvals still arrive on the victim’s phone while session cookies and form posts are mirrored offshore. Several victims told InfoHandle their endpoints showed green padlocks and unchanged bookmark URLs even as outbound DNS queries shifted to resolver clusters in Eastern Europe.
Legacy remote-access appliances that auto-trust internal PAC distribution made the problem worse: help-desk scripts pushed group-policy updates without code-signing checks, so a single compromised technician account could broadcast the malicious file to thousands of laptops overnight. CISA’s alert notes the kits reuse open-source PAC generators previously seen in ad-fraud campaigns, now paired with residential IP proxies to evade geo-fencing rules.
What agencies confirmed
The FBI said it is coordinating with Secret Service financial crimes units on at least four cases where payroll redirect forms were captured mid-session. CISA confirmed no federal civilian executive branch agency reported successful exfiltration through PAC routing in September, but several state Medicaid processors filed voluntary disclosures after finding anomalous TLS fingerprints on outbound claims traffic. Neither agency named victims; both urged immediate audits of browser proxy settings on managed and BYOD devices enrolled in mobile device management.
Recommended mitigations include blocking user-writable PAC paths, requiring admin elevation to change proxy settings, and deploying phishing-resistant FIDO2 keys for cloud consoles. NIST’s updated digital identity guidelines classify PAC manipulation as a channel attack that bypasses SMS one-time passwords—consistent with the FBI’s push for hardware keys on privileged accounts.
Who has the file
Major U.S. banks told the Financial Services Information Sharing and Analysis Center they are correlating PAC-related fraud with Zelle and wire-desk social engineering, though no bank attributed losses solely to proxy hijacking yet. Microsoft Defender for Endpoint shipped a detection rule Thursday flagging non-corporate PAC URLs; CrowdStrike published a hunting query for unexpected WinHTTP proxy changes on Windows 11 builds.
Managed service providers serving school districts in the Midwest said three clients lost domain-admin credentials after teachers approved “Wi-Fi optimization” prompts on personally owned Chromebooks synced to district Google tenants—a reminder that browser policy on non-corporate hardware still matters when SaaS admin roles are in play.
What is still unknown
Investigators have not published attribution for the August kit surge. It is unclear whether the same affiliates operate business-email-compromise wire fraud or whether PAC phishing is a parallel economy. Total dollar losses remain under FBI seal while cases are open; early IC3 summaries suggest six-figure payroll redirects in two manufacturing firms.
Apple macOS endpoints were hit less often in reported cases, but security vendors caution that Safari and Chrome on Mac accept PAC imports through profile payloads similar to Windows—especially on contractors using personal MacBooks enrolled via lightweight MDM profiles.
What IT shops should do
Security teams should export baseline proxy settings from a golden image and alert when drift occurs. Help desks must stop emailing PAC files; use signed configuration profiles through MDM instead. Remote workers should verify IT callbacks through published numbers, not reply-to addresses on the same email thread.
Incident responders told InfoHandle to preserve browser history and proxy registry keys before reimaging laptops—evidence that PAC URLs existed can accelerate cyber-insurance claims even when session theft is harder to prove. Rotating passwords alone is insufficient if the proxy remains; wipe proxy settings before credential resets.
Insurance and disclosure tail
Directors and officers insurers are asking whether boards documented PAC risks in quarterly cyber attestations. Public companies nearing 10-K season should align SEC cyber disclosure language with material proxy incidents, even when customer data sets were not exfiltrated wholesale—session hijacking on finance consoles may still qualify as material access events under 2023 rules.
The FBI and CISA said they will update the joint alert if new indicators emerge over the holiday hiring season, when temporary workers receive rushed onboarding links. Treat any unsolicited browser configuration step as hostile until verified through an out-of-band IT channel.








