Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

General Dynamics Phishing Attack Compromised 37 Employee Benefits Accounts

By TheFinanceBase Team4 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

General Dynamics reported that a phishing campaign gave attackers access to 37 employees’ Fidelity NetBenefits accounts. The incident involved fraudulent online advertising and a fake login page—not a confirmed intrusion into General Dynamics’ corporate network, defense programs, or classified systems. The company said some accounts had banking information changed and offered affected people two years of credit monitoring.

The incident was reported by SecurityWeek on December 26, 2024, based on the company’s disclosure and a filing with the Maine Attorney General’s Office.

How the General Dynamics attack worked

  1. Attackers ran a fraudulent advertising campaign.
  2. The ads sent General Dynamics employees to a phishing website designed to resemble a legitimate login page.
  3. Some employees entered usernames and passwords.
  4. Attackers used those credentials to access Fidelity NetBenefits accounts through General Dynamics’ Employee Self Service portal.
  5. In some cases, they changed banking information in the accounts.

The available report does not identify the attacker, advertising platform, phishing domain, malware, or whether multifactor authentication was enabled or bypassed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was General Dynamics’ corporate network breached?

That has not been established. General Dynamics told the Maine Attorney General’s Office that the unauthorized access was authenticated through the third-party service and not directly through General Dynamics business units. Based on the available reporting, this is best described as a compromise of employee benefits accounts, not a confirmed breach of General Dynamics’ core corporate systems.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

That distinction does not make the incident harmless. Benefits portals can hold identity, banking, employment and health-related information even when they are separated from an employer’s main network. However, no broader compromise of General Dynamics’ corporate network, defense programs or classified information was identified in the reporting available through August 18, 2026.

How many people were affected?

The reported total is 37 individuals. “Dozens of employees” is less precise; the company’s reported figure is 37.

What information was involved?

The compromised accounts contained categories including:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Names
  • Dates of birth
  • Government-issued identification numbers
  • Social Security numbers
  • Bank-account information
  • Disability status

The source does not establish that every affected person had every category exposed. It does report that banking information was changed in some cases.

Was money stolen?

There is no public confirmation in the cited report of completed fraudulent payments, the number of accounts affected by banking changes, the dollar value of any loss, or reimbursement by General Dynamics or Fidelity. A changed bank account is an unauthorized account action and a financial-fraud risk; it is not proof that money was stolen.

Incident timeline

Date What happened
October 1, 2024 Unauthorized access to employee accounts began, according to the company’s report.
October 10, 2024 General Dynamics discovered the activity. Some account owners began receiving notice that day.
After discovery Access to the affected service was suspended.
December 2024 Written notification letters began going to other impacted individuals.
December 26, 2024 SecurityWeek published its report.

The date the phishing advertising campaign began was not disclosed.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

General Dynamics’ response

Reported measures included suspending access to the affected service, notifying account owners, mailing letters to impacted individuals, providing two years of free credit monitoring, and advising recipients to reset their Fidelity credentials and avoid reusing old passwords elsewhere. The available reporting does not document a company-wide password reset, a specific MFA rollout, phishing-site takedown, or an outside forensic investigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What affected individuals should do

The company specifically advised credential resets and avoiding password reuse. The following are additional standard protective steps:

  1. Reset the Fidelity password immediately using the legitimate NetBenefits site or a trusted contact method, not a link in an unexpected message.
  2. Change reused or similar passwords on email, banking, retirement, payroll and other accounts.
  3. Turn on multifactor authentication wherever available, preferably with a passkey or FIDO2 security key.
  4. Review bank and retirement-account activity, including recently added or changed payment instructions.
  5. Call your financial institution through the number on an official statement or card if banking details were altered.
  6. Enroll in the offered credit monitoring. Monitoring can alert you to certain credit-file activity but does not stop account takeover.
  7. Consider a credit freeze or fraud alert with the major U.S. credit bureaus if Social Security or government-identification information may have been exposed.
  8. Watch for follow-on scams impersonating General Dynamics, Fidelity, a benefits administrator or the credit-monitoring provider. Do not disclose codes or credentials to unsolicited callers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Lessons for employers and benefits administrators

This case shows why an organization’s attack surface includes employee-facing benefits and SaaS portals, not only email, VPNs and production networks. Useful controls include:

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Phishing-resistant MFA, such as passkeys or FIDO2 keys, for benefits applications.
  • Unique passwords supported by an enterprise password manager.
  • Conditional-access and device-risk checks where the portal supports them.
  • Alerts and out-of-band confirmation for changes to bank details or profile data.
  • Centralized logging and rapid session revocation for third-party applications.
  • Monitoring for look-alike domains, malicious search ads and brand impersonation, with a takedown process.
  • Clear employee reporting channels and vendor-risk reviews covering benefits providers.

Email-security and awareness tools can help, but a lure delivered through advertising and a third-party login page requires identity and application controls as well. Training alone cannot prevent every convincing fake-login attack.

What remains unknown

The public account does not identify the threat actor, phishing infrastructure, number of advertisements or messages, MFA status, confirmed financial losses, or forensic findings. It also does not establish that Fidelity’s core systems or General Dynamics’ internal network were compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

General Dynamics said it found no evidence of ongoing harm or risk to affected employees. That is the company’s assessment, not a guarantee that identity-theft or fraud risk is zero; exposed credentials and identity data should still be treated cautiously.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.