Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In October 2012, scam emails used 1.usa.gov links to make work-from-home fraud look as though it came through a government website. The links exploited an open redirect on government-hosted pages to send visitors elsewhere. Dark Reading reported that the campaign was curtailed after the General Services Administration (GSA) posted warning pages; the incident shows why a government-looking short URL alone cannot establish that its final destination is safe.

How the 1.usa.gov links led to scam pages

In its October 24, 2012 report, Dark Reading summarized findings from Dell SecureWorks researchers. Scam emails included 1.usa.gov shortened links associated with legitimate government pages. But the government-hosted URLs used an open redirect in DotNetNuke’s LinkClick.aspx: the page accepted a destination outside the government site and forwarded visitors there.

The resulting scam pages reportedly copied CNBC content and promoted work-from-home offers. The report characterized the spam as relatively unsophisticated and said it did not contain malware. The primary risk described was fraud, with the government-associated short link lending the offer credibility.

What the reports said about the campaign’s scale and end

Dark Reading attributed an estimate of approximately 20,000 clicks to Dell SecureWorks for scam links between October 12 and October 16, 2012. The report also described a larger surge on October 18, but did not give a comparable click total for that surge. These are figures from the contemporary report, not independently verified measurements or a measure of losses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecureWorks alerted GSA. According to the report, GSA put up warning pages, and the scam was derailed by October 19. A researcher quoted in the article described the distinctive tactic as combining open redirects with .gov sites so links appeared to point to government destinations while actually leading to the scammers’ site.

Why a government-looking short link was not a guarantee

A short link can obscure the destination, and an open redirect can make a legitimate site’s URL forward a visitor to an unrelated external page. In this incident, the trust signal came from the government-associated link, not from the safety of the final website. A .gov-looking address at the start of a redirect chain therefore was not proof that the offer at the end was legitimate.

The 2012 report also mentioned a researcher’s hypothetical concern that attackers might use a similar technique for IRS-themed phishing. That was a warning about a possible scenario, not a reported result of this campaign.

What users and organizations can take from the incident

For anyone receiving a shortened link

  • Be cautious when an unexpected email uses a shortened link to promote a job, income opportunity, or request for personal or financial information.
  • Do not treat a familiar government domain in the visible link as evidence about the final destination. If the destination cannot be checked safely, avoid opening the link and navigate to the relevant agency or organization independently.
  • Report suspected scam messages through the relevant organization’s official reporting channel. Do not provide information or money merely because a link appears government-related.

For agencies and site operators

  • Validate redirect destinations so that redirect endpoints cannot be used to forward visitors to arbitrary external sites.
  • Monitor short-link activity and investigate unusual traffic or spam reports; the cited incident account describes the redirect abuse and GSA warning pages, but does not compare the effectiveness of specific controls.
  • Where a link may lead outside an agency site, consider making that transition clear to visitors. A historical Department of Energy social-media security document recommended considering a dedicated federal URL shortener with appropriate logging and security; it is a recommendation, not evidence of a particular service’s present configuration or availability.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Government shorteners and domain policy: useful context, not proof of safety

Oklahoma’s Office of Management and Enterprise Services describes Go.USA.gov as a free shortener for government URLs. Its page says registration is limited to people with verifiable U.S. federal, state, or local government email addresses, that the service tracks clicks, and that destinations are limited to government domains. The same page records an October 22, 2012 security notice discouraging agencies from using Bitly amid increased spam involving .gov URLs. This is state-agency context, not the original investigation of the 1.usa.gov incident: Oklahoma OMES: Go.USA.gov.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Later federal guidance says executive branch agencies are required to use .gov or .mil domains for official communications, information, and services, subject to stated exceptions for some third-party services. Digital.gov explains that government domains help the public identify official information. This later policy context helps explain the trust associated with government domains, but it did not cause or resolve the 2012 incident: Digital.gov: Domain Guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.