Coronavirus Phishing Scams

Health concerns aren't the only thing you need to watch out for in the pandemic. Cybercriminals are taking full advantage of the world's confusion by targeting people and businesses when they're at their most vulnerable. While cybercrime of all kinds is on the rise, phishing has emerged as a current favorite of coronavirus scammers.
 
As of May 1, the U.K. has reported 4,727 coronavirus-related phishing emails, leading to more than £2 million in losses. In the U.S., damages from these emails have surpassed $4 million as of May 11. Many of these scams use similar tactics, so here are a few of the most common ones you may encounter.
 
Impersonating Health Authorities
As you might have predicted, many phishers are sending emails under the guise of official health figures. By pretending to be an authority like the World Health Organization (WHO), cybercriminals fool unsuspecting users into clicking malicious links. Amid all the confusion surrounding the virus, people may let their guard down, desperate for information.
 
These emails impersonate official sources offering updates on the spread of the virus. Since many of these organizations are sending out regular updates, you can see why people may fall for these scams. Since they contain relevant subject lines like "Coronavirus Updates" or "COVID-19 News," email filters may not label them as spam, either.
 
Fraudulent Outbreak Maps
A similar and equally prevalent scheme is to present a malicious link to an outbreak map. This scam is particularly effective because Johns Hopkins University has released an official interactive COVID-19 map. Some phishing attempts link to the Johns Hopkins map but install AzorUlt Trojans in the process.
 
Other similar campaigns involve mimicking the official map but taking users to a fraudulent, malware-infested one instead. Like with phishing scams parading as the WHO, these attempts take advantage of users' desire for information. In their haste to learn more, they may not double-check to see if the source is legitimate or not.
 
Imitating Government Officials
Health organizations aren't the only groups that coronavirus phishers are impersonating. Many governments are providing monetary or informational support to their citizens, which presents cybercriminals with the perfect opportunity. Scammers pretending to represent the U.S. CARES Act or the U.K.'s HMRC are on the rise.
Businesses are especially susceptible to these scams, as many government programs offer tax relief or loan forgiveness for companies. Unfortunately, organizations also have the most to lose, risking both their livelihood and reputation in the event of identity fraud. Global economies are already in decline, making these scams all the more devastating.
 
Tips on Avoiding Coronavirus Phishing
While the pandemic has spurred a rise in phishing, you aren't defenseless against these scams. You and your business can avoid falling prey to coronavirus phishers by maintaining safe internet practices. Amid all the confusion, you mustn't lose sight of basic cybersecurity measures. 
 
Understanding what forms many of these scams take is the first step in preparedness. Know that almost 20% of all phishing emails today include coronavirus-related information or content. You should subject anything containing this type of material to additional scrutiny.
 
The only thing separating these new scams from older ones is their prevalence and the growing public confusion. If you take the time to remember foundational security measures like inspecting links and not clicking on unknown addresses, you'll be safe. Here are some reminders to keep in mind: 
  • Always verify an email's source before clicking any links or opening attachments.
  • Just because an email address looks official doesn't mean it is.
  • Never give personal information away over email.
  • Government agencies will never ask for you for money, especially in cryptocurrency.
  • If anything sounds too good to be true, it probably is.
  • For information regarding COVID-19, check official sources like the WHO's website, not emails. 
Protecting Your Business During COVID-19
If you practiced safe email behavior before the outbreak, you should be safe. Just remember to continue these practices, and double-check everything if you didn't already. These are confusing times for everyone, but you can't afford to let your guard down.
 
Many things are changing in response to the pandemic, but the threat of phishing hasn't. Cybercrime is as prevalent as ever, so make sure you and your business are taking steps to defend against it. The phishing scams of the coronavirus are a growing threat, but you can handle it with robust cybersecurity.
 
Caleb Danziger writes about science and technology at TheByteBeat.com
 
You Might Also Read:
 
Spear Phishing Threats & Trends:
 
 
« CISO's Cant Find The Right People
‘We Hacked Your Website’ Blackmail Scam »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Aviva

Aviva

Aviva provides Cyber Liability cover for small to mid-market customers to help combat the threat of data and privacy breach.

Raz-Lee Security

Raz-Lee Security

Raz-Lee Security is the leading security solution provider for IBM Power i, otherwise known as iSeries or AS/400 servers.

Innovative Solutions (IS)

Innovative Solutions (IS)

Innovative Solutions is a specialized professional services company delivering Information Security products and solutions for Saudi Arabia and the Gulf region.

UPX Technologies

UPX Technologies

UPX Technologies is one of the largest digital security centers in Brazil providing full protection for data, networks and content.

AU10TIX

AU10TIX

AU10TIX’s smart forensic-level ID authentication technology links physical and digital identities, meets compliance mandates, and ensures your customers know their trust and safety come first.

AngelList

AngelList

AngelList champion startups and the people who empower them. Search tech & startup jobs, find new tech products, and invest in startups.

TechForing

TechForing

TechForing Ltd. works for business organization's cyber security and cyber crime incident managements. We help business to secure their business online.

Internet 2.0

Internet 2.0

Internet 2.0 is a Cyber Security technology company with a core focus on developing affordable but sophisticated cyber security solutions.

Fasken

Fasken

Fasken is one of the largest business law firms in Canada and a recognized leader in privacy and cybersecurity law.

BugDazz

BugDazz

BugDazz pentest as a service (PTaaS) platform helps bringing in real-time results, detail coverage, & easy remediation workflows with compliance-ready reports.

RedHunt Labs

RedHunt Labs

RedHunt Labs is a premier Cybersecurity Solutions provider, offering Attack Surface Management solution 'NVADR' and Penetration Testing services.

CyberUSA

CyberUSA

CyberUSA is a collaboration of leaders and states focused on a common mission purpose of enabling innovation, education, workforce development, enhanced cyber readiness and resilience.

Sekur Private Data

Sekur Private Data

Sekur Private Data Ltd. is a Cybersecurity and Internet privacy provider of Swiss hosted solutions for secure communications and secure data management.

SIEM Xpert

SIEM Xpert

SIEM Xpert is a leader in Cyber Security Trainings and services since 2015.

Avanade

Avanade

Avanade is a leading provider of innovative digital, cloud and advisory services, industry solutions and design-led experiences across the Microsoft ecosystem.

PayPal Ventures

PayPal Ventures

PayPal Ventures invests in companies at the forefront of innovation in fintech, payments, commerce enablement, artificial intelligence, blockchain and cryptocurrency, regulatory and cyber technology.