We are aware of a security incident regarding spoofed phishing emails that were sent to some of our contacts recently.
An unauthorized third party is distributing fraudulent communications in the name of C Capital personnel. While these emails display the name of our colleague, they originate from external, non-company domain addresses (e.g., DocSend <no-reply@docsend.com> or @c-capital.co).
Recommended Actions:
Do not engage: Please do not click any hyperlinks or open attachments within communications claiming to be from C Capital or our personnel unless you have verified that the sender's address ends strictly in @c.capital.
Verify sensitive requests: Please note that we will never request changes to banking details, request fund transfers, or ask for sensitive credentials via unverified email correspondence. Should you receive any payment or administrative request, kindly verify it directly via a trusted telephone call with your primary point of contact.
Report suspicious emails: If you receive a suspicious email purporting to be from our organization, please forward it to info@c.capital and delete it immediately.
Our IT and cybersecurity specialists are actively investigating this matter alongside external advisers and taking appropriate measures to protect our stakeholders and mitigate any potential risks.
Should you have any immediate queries, please do not hesitate to contact us at ir@c.capital.
