Skip to main content
ThreatPhishing & impersonation

Fake CISA Known Exploited Vulnerabilities (KEV) catalog mandatory patch directive from non-official sender targeting IT/security staff — impersonates CISA BOD 22-01 with "patch within X days or face non-compliance penalty / federal mandate" urgency to harvest credentials or deploy malware

cisa-kev-mandate-phish

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Fake CISA Known Exploited Vulnerabilities (KEV) catalog mandatory patch compliance directive from a non-official sender, targeting IT and security staff. CISA's BOD 22-01 (Binding Operational Directive) requires US federal agencies to remediate KEV catalog entries on a fixed timeline. Attackers impersonate CISA or US-CERT with fake "mandatory patch deadline" emails — "your systems are listed in the CISA KEV catalog — patch within 14 days or face non-compliance penalties under federal mandate." The goal is credential harvest (fake CISA portal login), malware delivery (malicious patch link), or intelligence gathering. Legitimate CISA advisories are published on cisa.gov and never arrive as unsolicited emails demanding credentials or immediate patch confirmation by reply. The signal fires when: (1) body references CISA, KEV catalog, BOD 22-01, or Binding Operational Directive AND (2) mandatory patch / compliance deadline / non-compliance penalty urgency is present AND (3) sender is NOT cisa.gov, us-cert.gov, dhs.gov, or nist.gov AND (4) no List-Unsubscribe or In-Reply-To. Source: GC1 R15 council #1; CISA advisory on spoofed CISA communications 2024; Mandiant KEV-phishing campaign report Q1 2026.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started