Lessons from a phishing scam posing as SEC information gathering

After tracking a phishing campaign impersonating the SEC, SEC3 Compliance share what they have learned so far and offer tips on how to avoid being scammed.

At SEC3 Compliance, we’re tracking a phishing campaign impersonating the SEC to target smaller firms. Since June 23, 2025, several SEC‑registered investment advisers, small hedge funds, and private equity firms have received phishing emails claiming to be from David Bottom, the SEC’s Chief Information Officer. The sender’s email includes sec.gov.virumail.com –

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in