ZeroFox Intelligence Flash Report - Threat Actors Seeking to Exploit California Wildfire Recovery Funds
|by Alpha Team

ZeroFox Intelligence Flash Report - Threat Actors Seeking to Exploit California Wildfire Recovery Funds
Product Serial: F-2025-01-24a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on discussions taking place in a dark web forum, surrounding the interest and methodologies of exploiting California wildfire recovery funds for financial gain.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- ZeroFox has identified threat actors actively discussing methodologies to exploit California wildfire recovery funds for financial gain on the dark web.
- In a thread identified on the Dread forum, threat actors discussed methodologies for successful scams, stating that this is “free money”, as well as the importance of exercising patience to avoid early scrutiny during the verification process.
- Based on previous behavior and attitudes towards disaster relief funds, it is very likely that a broader array of threat actors are interested in exploiting these funds than those identified to date.
- Although ZeroFox has identified no evidence that threat actors are actively—and successfully—leveraging wildfire recovery funds in financial scams, such activity could result in financial and reputational damage for state or local government authorities and reduce the availability of relief funds for those legitimately affected by the wildfires, as well as perpetuate the idea that these funds are a viable attack vector.
Tags: tlp:clear, dark web, us/canada, threat actor