Since the escalation of COVID-19 cases, malicious activity from cybercriminals is also on the rise.
Hackers are taking advantage of the coronavirus fear to carry out attacks. This is done by creating websites that claim to have cures for the virus or by spreading emails that contain links to malware.
Consider this research by Check Point, where they found an increase in coronavirus domain name registration. Most of these scam websites allege to be selling vaccines against the virus.
At the beginning of this year, one of the reported cases was the Emotet malware that was used in a coronavirus-themed campaign in Japan. Phishing victims received an email purporting to report locations where the infection was spreading. Because the email appeared to be an official communication from the government, victims were likely to open it to find out more about the information. However, an attempt to open a .docx document will download the Emotet malware to the victim’s computer.
Apart from a .docx, the attachment could be a .pdf or an .mp4 claiming to have instructions on how to protect against the virus or other related updates.
The case in Japan is among the first attacks on the public domain that came with the rise of the COVID-19. Since then as the coronavirus continued to spread, more data breach cases have been reported. According to Malwarebytes Labs director Jerome Segura, there is an increase in campaigns that use the coronavirus situation to trick victims. Segura reports that in March alone, there was a 26 percent increase in online credit card skimming as people did online shopping from the safety of their homes.
Even the World Health Organization has not been spared, as they recently reported a fivefold increase in cyberattacks. The attacks have increased such that there was a joint alert sent out by the United States Department of Homeland Security, the Cybersecurity and Infrastructure Security Agency, and the United Kingdom’s National Cyber Security Centre.
Unfortunately, the fact is it won’t get any better as more cybersecurity firms report an increase in attacks relating to the coronavirus outbreak. This is because attacks that are based on important events or occurrences such as the COVID-19 pandemic become effective as they leverage on the public’s need to know.
In matters of life and death, people tend to be less careful; and in an attempt to stay informed, they end up becoming victims of cybercriminals.
Apart from malware, there are fears that work-at-home directives also have led to an increase in data breaches. If you have a business, you probably have policies to help guard against cyberattacks. However, since the work-at-home situation was largely unplanned and employees are having to work from home, data can be easily leaked from the devices they use to connect to the office network.
It’s important to keep in mind that hackers love to take advantage of current events to trick their victims. Because of this, it’s expected that these attacks will increase in frequency – and this calls for users to be vigilant.
Although security systems might already be in place, none of them have the ability to deal with ever-increasing threats that have grown in sophistication. Email security remains one of the hardest challenges for employers. However, taking precautionary measures will help reduce the possibility of successful attacks.
Here are 10 ways to keep safe:
Avoid clicking on promotional links in emails.
Be careful when you receive emails with subject lines that include coronavirus or COVID-19 and have a call to action.
Be careful when clicking on pages with special offers, especially pages claiming to sell or know about the cure for the coronavirus.
Check domain names to verify their validity.
Be careful about clicking on links found on SMS that claim to come from institutions such as your credit company or bank; such links could activate the malware.
Make sure to use a virtual private network (VPN) – especially when working with sensitive data.
If you have a business and your employees are using corporate devices, enable remote wipe in case devices to get compromised or lost.
Limit the number of times you enter your credit card details online and confirm that the domain where you enter personal information is legitimate.
Hackers will continue to adjust their tactics; therefore, use trusted resources such as the Centers for Disease Control and Prevention for information on the coronavirus.
Use strong passwords.
Carion Doty LLP
Heightened Hacking as Corona Pandemic Worsens; How to Avoid Being a Victim
May 1, 2020 · Blog, What's New in Technology
Since the escalation of COVID-19 cases, malicious activity from cybercriminals is also on the rise.
Hackers are taking advantage of the coronavirus fear to carry out attacks. This is done by creating websites that claim to have cures for the virus or by spreading emails that contain links to malware.
Consider this research by Check Point, where they found an increase in coronavirus domain name registration. Most of these scam websites allege to be selling vaccines against the virus.
At the beginning of this year, one of the reported cases was the Emotet malware that was used in a coronavirus-themed campaign in Japan. Phishing victims received an email purporting to report locations where the infection was spreading. Because the email appeared to be an official communication from the government, victims were likely to open it to find out more about the information. However, an attempt to open a .docx document will download the Emotet malware to the victim’s computer.
Apart from a .docx, the attachment could be a .pdf or an .mp4 claiming to have instructions on how to protect against the virus or other related updates.
The case in Japan is among the first attacks on the public domain that came with the rise of the COVID-19. Since then as the coronavirus continued to spread, more data breach cases have been reported. According to Malwarebytes Labs director Jerome Segura, there is an increase in campaigns that use the coronavirus situation to trick victims. Segura reports that in March alone, there was a 26 percent increase in online credit card skimming as people did online shopping from the safety of their homes.
Even the World Health Organization has not been spared, as they recently reported a fivefold increase in cyberattacks. The attacks have increased such that there was a joint alert sent out by the United States Department of Homeland Security, the Cybersecurity and Infrastructure Security Agency, and the United Kingdom’s National Cyber Security Centre.
Unfortunately, the fact is it won’t get any better as more cybersecurity firms report an increase in attacks relating to the coronavirus outbreak. This is because attacks that are based on important events or occurrences such as the COVID-19 pandemic become effective as they leverage on the public’s need to know.
In matters of life and death, people tend to be less careful; and in an attempt to stay informed, they end up becoming victims of cybercriminals.
Apart from malware, there are fears that work-at-home directives also have led to an increase in data breaches. If you have a business, you probably have policies to help guard against cyberattacks. However, since the work-at-home situation was largely unplanned and employees are having to work from home, data can be easily leaked from the devices they use to connect to the office network.
It’s important to keep in mind that hackers love to take advantage of current events to trick their victims. Because of this, it’s expected that these attacks will increase in frequency – and this calls for users to be vigilant.
Although security systems might already be in place, none of them have the ability to deal with ever-increasing threats that have grown in sophistication. Email security remains one of the hardest challenges for employers. However, taking precautionary measures will help reduce the possibility of successful attacks.
Here are 10 ways to keep safe:
Avoid clicking on promotional links in emails.
Be careful when you receive emails with subject lines that include coronavirus or COVID-19 and have a call to action.
Be careful when clicking on pages with special offers, especially pages claiming to sell or know about the cure for the coronavirus.
Check domain names to verify their validity.
Be careful about clicking on links found on SMS that claim to come from institutions such as your credit company or bank; such links could activate the malware.
Make sure to use a virtual private network (VPN) – especially when working with sensitive data.
If you have a business and your employees are using corporate devices, enable remote wipe in case devices to get compromised or lost.
Limit the number of times you enter your credit card details online and confirm that the domain where you enter personal information is legitimate.
Hackers will continue to adjust their tactics; therefore, use trusted resources such as the Centers for Disease Control and Prevention for information on the coronavirus.
Use strong passwords.
Disclaimer
These articles provide general information on tax, accounting, and financial topics for small businesses and individuals. They are educational in nature and are not specific legal, accounting, financial, tax, or other professional advice, and should not be relied upon as such. This content was prepared by Service2Client and may have been reviewed or edited by the website owner for accuracy and compliance. Look for a trust mark below for verification details. No representation is made that any approach described will achieve a particular result, and no regulatory or professional body has reviewed or endorsed this content. Because each situation is different, readers should consult a qualified professional about their specific circumstances before acting. Images accompanying these articles are protected by copyright and may not be copied or reused.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.