Image via ID 217843758 © Melinda Nagy | Dreamstime.com
Cybercriminals, like other kinds of grifters, aim to take advantage of fear. As the COVID-19 Delta variant surges across the nation, it seems that pandemic-related phishing scams are on the rise, too.
Researchers at Proofpoint, a security firm, found that pandemic-related phishing attempts increased by 33% in June, a large increase from this Spring, when the virus appeared to be it on its way out. Notably, the number of phishing scams spiked at the same time
Google searches did for “delta variant.”
Phishing, for the unfamiliar, is a type of scam where cybercriminals send fake emails in an attempt to trick recipients into clicking on a link or attachment. Through that, the grifters can then access recipients’ information, including personal or credit details.
Now, as most of the country returns to work, and employers are requiring submission of paperwork such as test results and proof of vaccination, scammers have more ways of disguising their phishing attempts.
“That almost makes it easier for the bad actors because people are getting used to: ‘Upload your negative test here, go download this COVID form, fill it out,’” Sherrod DeGrippo, Vice-President of Threat Research and Detection at Proofpoint, told
The Washington Post.
Recently, the firm uncovered phishing scams posing as human resource departments, asking for recipients to submit proof of vaccination.
If you receive a similar email, be sure to take the time to verify that it’s come directly from the organization you work for. One’s vaccination card contains useful information such as birthdates or full names, which hackers could target.
Other phishing scams to look out for are ones coming from “health organizations,” which could ask for sensitive information such as a recipient’s social security number and vaccination card. While the hackers may not use the information collected immediately, they could sell them on
the dark web to other bad actors.
One should also look out for messages disguised as work-related pandemic measure updates. Scammers often include figures about COVID-19 infections in the “office” or outline new precautions employees are supposedly required to take, compelling recipients to click on the attached file.
Proofpoint’s research has shown that emails telling employees they’ve lost their jobs due to COVID-19 are also on the rise. “It quite literally is clickbait,” DeGrippo said.
“They need you to click on them, so in order to get the person to take the action, you’ve got to escalate their emotional state to one that has them emotional, instead of intellectual,” he explained.
And what better way to do that than tell someone they’ve been fired?
As a general rule,
The Washington Post suggests a few tips for spotting phishing emails. Key giveaways are altered domain names, or mistakes such as misspelled company titles or sender addresses. If you receive an email from HR you’re unsure of, it’s best to check directly with the department to ensure the link or attachment is genuine.
And if an email seems to make you particularly angry, worried, or curious – it’s best to pause for a moment before you click.
[via
The Washington Post, cover image via
ID 217843758 © Melinda Nagy | Dreamstime.com]