{"id":14667,"date":"2018-01-03T16:40:57","date_gmt":"2018-01-03T16:40:57","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/"},"modified":"2026-08-08T04:37:21","modified_gmt":"2026-08-08T04:37:21","slug":"report-most-agencies-vulnerable-to-phishing","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/","title":{"rendered":"Report: Most agencies vulnerable to phishing"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Nearly half of federal agency email domains have adopted policies to collect data on unauthorized emails, a move mandated by the Department of Homeland Security in October, according to <a href=\"https:\/\/www.agari.com\/wp-content\/uploads\/2017\/08\/Agari_DMARC_Adoption_Report_Federal_12_2017.pdf\" title=\"\" class=\"\" target=\"_blank\">a report<\/a> by cybersecurity company Agari.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The new policies do not block malicious emails or prevent employees from receiving phishing emails, but instead allow email domain owners, such as CIOs, to receive reports on unauthorized messages sent through their domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.federaltimes.com\/2017\/10\/16\/dhs-issues-mandate-for-agencies-to-beef-up-their-email-web-security\/\" title=\"\" class=\"\" target=\"_blank\">DHS mandate <\/a>requires that all federal agencies adopt the Domain-based Message Authentication, Reporting and Conformance or DMARC monitoring policy at a level of \u201cp=none\u201d by Jan. 15. According to the DMARC.org frequently asked questions, a policy of \u201cp=none\u201d means that email domain owners receive reports on messages sent through their domain, but recipients still see the potentially malicious emails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the Agari report, 151 domains established a DMARC policy for the first time between Nov. 18 and Dec. 18. This brings the total of agency domains meeting the DHS requirement to 47 percent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The remaining 53 percent of domains, however, have less than two weeks to fulfill that requirement by the deadline. And even if adoption continues at the rate found by Agari, hundreds of federal domains will fail to meet the Jan. 2018 deadline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe analysis in this paper has shown that while federal agencies are making progress in the wake of the specific timelines set forth in [the DHS directive], most remain unprotected against phishing,\u201d the Agari report said. \u201cAlmost 53% of federal agencies\u2019 domains currently do not have a DMARC policy. For those that do, the majority still maintain a monitor-only \u2018p=none\u2019 policy that doesn\u2019t protect their constituents. These agencies and their email recipients remain vulnerable to domain spoofing and phishing attacks.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The (p=none) policy does nothing to block malicious emails, however, and agencies must implement a stricter policy to prevent employees from receiving phishing emails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The DHS directives requires all agency domains to eventually move to a \u201cp=reject\u201d policy within a year of the mandate\u2019s publication, which automatically rejects email messages that fail authentication. According to the Agari report, 15 percent of agency domains have already implemented this policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The mandate is designed to reduce the number of successful phishing campaigns conducted against federal employees \u2014 in which a malicious actor pretends to be a boss, coworker or other authority figure in order to steal money or information from their target \u2014 by preventing those emails from ever reaching the employee in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recently, <a href=\"\/TEMP-LINK-TEMP\/\" title=\"\" class=\"selected-link\">the IRS issued a warning to taxpayers and HR departments <\/a>that phishing scams pretending to be from the agency or company executives were targeting W-2 forms to steal information and identities. Such phishing scams could be prevented or mitigated by DMARC implementation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the Agari report, 8 percent of total federal email volume monitored by the company was malicious or failing authentication, and 90 percent of those email domains were targeted by domain abuse, meaning a domain registered for phishing, botnets or spam.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cClearly, some agencies are aware of the threat of digital deception and have taken appropriate countermeasures,\u201d the report read. \u201cA few federal agencies, including the U.S. Department of Health and Human Services, have taken the initiative by enabling DMARC. Moreover, they have configured it in the most strict \u2018reject\u2019 mode so that email service providers can automatically reject phishing emails impersonating their agency. However, among other early adopters, a significant number of their deployments are \u2018p=none,\u2019 which does nothing to prevent these attacks. DMARC adoption is of little use unless organizations move to a Quarantine or Reject policy.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.<\/p>\n","protected":false},"author":7,"featured_media":16554,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":3574,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[106,29,32],"tags":[],"coauthors":[2869],"class_list":["post-14667","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-newsletters"],"acf":{"subheadline":"","legacy_arc_id":"UZQHMMLYZRFRNJORBDMUXZ2FF4","arc_canonical_url":"\/cyber\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Report: Most agencies vulnerable to phishing - C4ISRNet<\/title>\n<meta name=\"description\" content=\"Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/federaltimes\/cyber\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Report: Most agencies vulnerable to phishing\" \/>\n<meta property=\"og:description\" content=\"Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2018-01-03T16:40:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T04:37:21+00:00\" \/>\n<meta name=\"author\" content=\"Jessie Bur\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jessie Bur\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Report: Most agencies vulnerable to phishing\",\n\t            \"datePublished\": \"2018-01-03T16:40:57+00:00\",\n\t            \"dateModified\": \"2026-08-08T04:37:21+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/\"\n\t            },\n\t            \"wordCount\": 596,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/636059963373924506-ap-1603082029051420jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Newsletters\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/\",\n\t            \"name\": \"Report: Most agencies vulnerable to phishing - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/636059963373924506-ap-1603082029051420jpg.jpg\",\n\t            \"datePublished\": \"2018-01-03T16:40:57+00:00\",\n\t            \"dateModified\": \"2026-08-08T04:37:21+00:00\",\n\t            \"description\": \"Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/636059963373924506-ap-1603082029051420jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/636059963373924506-ap-1603082029051420jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2018\\\/01\\\/03\\\/report-most-agencies-vulnerable-to-phishing\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Klas\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/advertiser\\\/klas\\\/\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Report: Most agencies vulnerable to phishing\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Report: Most agencies vulnerable to phishing - C4ISRNet","description":"Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/federaltimes\/cyber\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/","og_locale":"en_US","og_type":"article","og_title":"Report: Most agencies vulnerable to phishing","og_description":"Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/","og_site_name":"C4ISRNet","article_published_time":"2018-01-03T16:40:57+00:00","article_modified_time":"2026-08-08T04:37:21+00:00","author":"Jessie Bur","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jessie Bur","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Report: Most agencies vulnerable to phishing","datePublished":"2018-01-03T16:40:57+00:00","dateModified":"2026-08-08T04:37:21+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/"},"wordCount":596,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/636059963373924506-ap-1603082029051420jpg.jpg","articleSection":["Daily Brief","Home","Newsletters"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/","name":"Report: Most agencies vulnerable to phishing - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/636059963373924506-ap-1603082029051420jpg.jpg","datePublished":"2018-01-03T16:40:57+00:00","dateModified":"2026-08-08T04:37:21+00:00","description":"Nearly half of agency email domains have adopted policies to collect data on unauthorized emails as mandated by an Oct. 16, 2017, Department of Homeland Security directive.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/636059963373924506-ap-1603082029051420jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/636059963373924506-ap-1603082029051420jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2018\/01\/03\/report-most-agencies-vulnerable-to-phishing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Klas","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/advertiser\/klas\/"},{"@type":"ListItem","position":3,"name":"Report: Most agencies vulnerable to phishing"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/636059963373924506-ap-1603082029051420jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/14667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=14667"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/14667\/revisions"}],"predecessor-version":[{"id":14669,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/14667\/revisions\/14669"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=14667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=14667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=14667"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=14667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}