State officials in Hawaiʻi have issued a cybersecurity warning about an ongoing phishing campaign where fraudulent websites are impersonating official Hawaiʻi government departments. These fake sites are designed to trick users into divulging sensitive personal information, login details, or other credentials.
Cybercriminals are using a deceptive domain — “codify[.]inc” — to make URLs look like legitimate government web addresses by including believable subdomains.
How the Scam Works
The attackers create URLs such as:
dlir.hi.usa[.]codify.inc— posing as the Department of Labor and Industrial Relationshidoe.hi.usa[.]codify.inc— posing as the Department of Educationhealth.hi.usa[.]codify.inc— posing as the Department of Health- Many more similar URLs target departments like Transportation, Public Safety, Taxation, Human Services, Commerce & Consumer Affairs, Budget & Finance, etc.
These sites may look convincing and sometimes use AI-powered interfaces or services as bait to get visitors to enter their credentials.
How to Protect Yourself
1. Check the URL carefully:
Official Hawaiʻi government sites always end in .gov. If a domain uses .inc, .co, or anything other than .gov, it is not legitimate.
2. Avoid clicking links in unsolicited messages:
Do not trust links in unexpected emails or texts — even if they reference government services. Instead, type trusted government URLs directly into your browser.
3. Report suspicious sites:
If you encounter a suspected phishing page, report it to [email protected] or the appropriate state cybersecurity office.
4. Be wary of login prompts:
Never enter usernames, passwords, Social Security details, or other sensitive info unless you are absolutely sure the site is secure and legitimate.
What Officials Are Saying
State releases emphasize that these fake domains are not government sites and that multiple agencies are currently being spoofed. Federal partners and cybersecurity teams are also monitoring and attempting takedowns through service providers where possible.
