Connecticut Secretary of State Stephanie Thomas is warning businesses across the state about a phishing email impersonating the Connecticut Business Registry, designed to steal sensitive information.
Thomas said the “malicious email” appears to come from the Connecticut Business Registry and includes a DottedSign link prompting recipients to view and sign a digital document.
The link can trick users into revealing sensitive information, including sharing their login credentials, transferring money, or downloading malware onto their devices, officials said.

“Cybercriminals are getting more sophisticated, and it’s critical that businesses stay alert,” Thomas said. “Our office will never send unsolicited documents for signature. If something feels off, trust your instincts and verify before you click.”
The Office of the Secretary of the State said official emails will always come from a @ct.gov email address. However, the office cautioned that scammers often use lookalike domains that closely resemble legitimate government email addresses, such as @cct.gov or @ct-gov.org.
The office is urging businesses to:
- Avoid clicking links or responding to any emails that you think may be suspicious.
- Go directly to business.ct.gov to complete business filings instead of using links sent in emails. “While the Business Services Division may include quick links for convenience, it is never necessary to click a link to make a business filing,” the office said.
- Never share your business.ct.gov login credentials.
- Enable multi-factor authentication (MFA) for added security.
Anyone who receives a suspicious email claiming to be from the Office of the Secretary of the State can contact the Business Services Division at bsd@ct.gov to verify whether the communication is legitimate.






