5 Most dangerous Covid-19 phishing scams to look out for

Here are the common forms of phishing scams related to COVID-19 since the start of the outbreak to look out for to protect your data safety and security.

Scammers will seek new ways to exploit a crisis to their advantage, and the Covid-19 outbreak is no exception. Cybercriminals have been leveraging the pandemic to launch all sorts of cyberattacks ranging from ransomware take-overs of data systems in vital industries like hospitals and financial organizations, to private network hacking.

The wake of Covid-19 has brought on a  new breed of phishing attacks that exploit the fear and vulnerability of people in this time: hackers are using human emotion to scare recipients into clicking harmful links or attachments in emails, social media posts, or text messages. By getting unaware recipients to click on a malicious link, hackers get individuals to download malware or relinquish personal information out of fear, anxiety, or even trust.

This form of social engineering takes the form of cybercriminals posing as a trusted friend, an official government agency or a well-known business. Here are the common forms of phishing scams related to COVID-19 since the start of the outbreak to look out for to protect your data safety and security.

 

1. Charity frauds associated with Covid-19

The Federal Bureau of Investigation (FBI) warned that scammers are taking advantage of people of a charitable bent by fraudulently soliciting donations for individuals, groups, and areas affected by Covid-19. Emails from these purported charitable organizations will try to get users to click on links that will then download a virus onto your computer or cellphone. Watch out for charity names that sound identical to well-known charities or email addresses that are not consistent with charities soliciting donations.  

 

2. Fabricated notices from known health organizations

These email correspondences are intentionally made to look identical to messages from reputable organizations such as hospitals or the Center for Disease Control (CDC). Cyber scammers registered tens of thousands of Covid-related spoof web domains in the first year of the pandemic. The United States Justice Department shut down hundreds of these malicious sites, promising access to personal protective equipment (PPE), relief payments, vaccines, or other aide.

 

3. Fake economic relief packages

Fraudsters posing as the Internal Revenue Service (IRS) or other government agencies will instruct you to click a link, pay a fee, or “confirm” your data to trick you into divulging sensitive information like your Social Security Number to secure your stimulus check. The IRS reported that it received an unprecedented number of stimulus scams between June and July of 2021. Fraudsters can also use social media platforms like Facebook to message you with promises of “Covid-19 relief grants”.

 

4. Phony websites containing maps and dashboards 

Malicious websites masquerading as a live map for Covid-19 global cases by Johns Hopkins University that circulated the internet were set up to trick unwitting users to visit. Visiting then infects the users with the AZORult Trojan which is an information-stealing program that can exfiltrate sensitive data.

 

5. Fake public service announcements (PSA)

Fraudulent emails containing information about protecting yourself, your children or your community can contain malicious links or attachments that will infect your system with data stealing programs.

 

Conclusion

Scammers are looking for more convincing and sophisticated ways of using social engineering tactics to gain people’s trust and access to their sensitive data by posing as reputable institutions. These malicious activities vary in style and tactics to exploit the emotional vulnerabilities of people at this time. To stay ahead, organizations must firm up their security awareness training programs for their employees apart from partnering with a trusted security services provider.

Accomplish More With UDT

Get your custom solution in cybersecurity, lifecycle management, digital transformation and managed IT services. Connect with our team today.

More to explore

Crafting a Futureproof 1:1 Device Strategy for School Districts

In the evolving landscape of Education Technology, crafting a futureproof 1:1 device strategy is crucial. This strategy should link every student, teacher, and administrator experience with specific device specifications. The integration of educational apps into the curriculum can significantly enhance the learning environment. These apps, tailored to the needs of students, can provide interactive content, fostering a dynamic learning experience.

Optimizing Your K12 Tech Investments: Funding 1:1 Device Programs

This blog will guide school districts grappling with the financial and resource demands of implementing a successful 1:1 device program amid ongoing challenges of budget constraints and competing priorities. Our guided workbook, created in partnership with Intel, provides further support with personalized roadmap on “Pathways to Innovation: Building a Sustainable Digital Learning Environment”.​

K12 Cybersecurity: How to Secure 1:1 Devices in Your School District

This blog post delves into the importance of security, cybersecurity, and data privacy in school districts implementing 1:1 device initiatives. It offers basic steps for evaluating, planning, and executing a security strategy. Our guided workbook, created in partnership with Intel, provides a personalized roadmap on “Pathways to Innovation: Building a Sustainable Digital Learning Environment”.

Lost & Stolen Devices are a Serious Data Security Threat—Here’s Why

Since the pandemic, remote and hybrid work has become the norm. While mobile devices and remote workstations have empowered great flexibility, it has also led to an increase in data security problems due to lost, misplaced, or stolen devices. Find out how remote and hybrid setups are contributing to this problem and how to protect yourself and your organization.​

Ransomware Gangs Adding Pressure with ‘Swatting’ Attacks—Here’s What You Need to Know

Ransomware gangs are implementing new extortion tactics to encourage victims to pay up. Swatting is becoming an increasingly popular tactic. It involves calling law enforcement to falsely report a serious, in-progress crime triggering an extreme response such as an armed raid from the SWAT team. Explore how cybercriminals are using this tactic and what you can do to prevent it from happening to you.​

Smishing Attacks are on the Rise—Here’s How To Keep Your Data Safe

Smishing attacks are on the rise, posing a significant threat to data security. Originating from a blend of SMS and Phishing, these attacks have seen a drastic increase since 2020. The widespread use of smishing attacks has persisted, with a lack of awareness being a major issue. Many view these as simple spam messages, unaware of the danger they pose. This blog aims to raise awareness about smishing and provide actionable insights to protect yourself and your organization.

Experiencing a security breach?

Get immediate assistance from our security operations center! Take the following recommended actions NOW while we get on the case:

RECOMMENDED IMMEDIATE NEXT ACTIONS

  1. Determine which systems were impacted and immediately isolate them. Take the network offline at the switch level or physically unplug the systems from the wired or wireless network.
  2. Immediately take backups offline to preserve them. Scan backups with anti-virus and malware tools to ensure they’re not infected
  3. Initiate an immediate password reset on affected user accounts with new passwords that are no less than 14 characters in length. Do this for Senior Management accounts as well.

Just one more step

Please fill out the following form,