Quick Contact

Talk to our team

Social

fb-footer
instagram-footer
Twiiter
youtube-footer
linkedin-footer
Blog --------

Phishing Scams: A Side Effect of the Coronavirus

Share
PHISHING SCAMS A SIDE EFFECT OF THE CORONAVIRUS

Keep yourself and your employees safe!

The world is going through some trying times right now, with the coronavirus affecting the economy and the lives of people in an unprecedented way. 

Among all this chaos, there are a few people who want to take advantage of this situation for their own selfish malicious needs, which come under the cybercrimes in the pandemic. This is carried out most commonly by phishing techniques, and it’s something to keep an eye out for, as it could possibly lead to large-scale data breaches. 

As an individual and as a company, it is important to understand the harm phishing can do.

Phishing is a serious cybercrime in which an individual pretends to be a legitimate institution and requests users for sensitive data such as passwords, credit card numbers or account details. This is usually carried out by email, telephone, SMS, or other social media websites. 

Being a victim of a phishing attack can cost you sensitive data, loss of productivity, and a black mark on your brand image. The information stolen from you can then be sold to the highest bidder in black markets and the dark web. 

The most important factor to consider about phishing attacks is the scale of the attack. These scams aren’t usually targeted at a single individual or a small group of people; they are carried out on a very large scale, affecting hundreds of thousands of people, out of which a good percentage may be gullible to the attack and leak-sensitive information. 

These attacks are most effective when carried out in times of economic crisis, such as now, as people are always looking forward to a helping hand to get them through these tough times. Little do they know that they’re facing the devil in disguise.

The most popular phishing scam in India right now is – using fake emails posing as the Indian government claiming to provide free COVID-19 tests and other resources. Eventually, they end up stealing personal and financial information from innocent citizens. They can also convince you to download malicious files which could cause permanent damage to your systems. 

According to the Indian Computer Emergency Response Team (CERT-In), the attack is being carried out by the North Korean hacker group Lazarus, and they have close to two million individual email ids of citizens from major cities like Delhi, Mumbai, Hyderabad, Chennai, and Ahmedabad to launch the attack on. 

The World Health Organization has also warned us about an international phishing scam targeted at an extremely large scale audience via fraudulent emails and WhatsApp messages, in which the attackers claim to be representatives of the WHO and ask for details like passwords and bank account details, and trick you into downloading attachments and opening malicious links.

Now that we know how phishing attacks can cause harm on a large scale,

Read More About the Arogya setu Dilemma

How to differentiate phishing emails from genuine ones.

  1. The easiest way to identify a phishing email is by checking the spelling of the sender

            For example, a malicious email can pretend to be the Bank of America by spelling it as “Bank of Arnerica”. Notice that the ‘m’ in America is replaced with an ‘r’ and an ‘n’. 

  1. Another indicator of a phishing email is that if you feel like it’s too good to be true, it probably is. If you receive an email from the WHO stating that the cure to the coronavirus has been found, but you don’t see anything on the news, you can confidently classify it as a scam. 
  1. If you receive an attachment when you weren’t expecting one, there is a high chance it could be malware. Make sure you have a virus checker to verify it for you. If the file is too large, double-check the sender and don’t download it unless you’re sure it’s absolutely necessary for you. 
  1. The same rule applies to hyperlinks. You can usually see the page a hyperlink redirects to when you hover over it. Make sure it’s not a malicious website. Some signs of malicious websites are misspelled URLs, URLs with random alphabets and numbers, the absence of an SSL certificate, and multiple redirections and pop-ups. 
  1. Also, closely examine the content of any email you receive. Generic greetings like “Dear Sir/Ma’am” which don’t include your name, and instructions to take some urgent action like clicking on a link or downloading an attachment could be indicators of a phishing scam.

Read More About the Cybersecurity courses and certifications of this COVID Times

The best way to avoid being a victim of phishing scams is really just good observational skills and common sense

Always read emails carefully and watch out for any of the phishing indicators listed above. A phishing email can usually be distinguished from a genuine one quite easily. Don’t rely entirely on the information you receive via emails, especially health data. Refer to legitimate websites like the official website of the World Health Organization for updates and information regarding the pandemic. 

Always remember that organizations such as banks will never ask you for your account details via email or phone; so there’s no need to reveal any of that information online. Be careful about the websites you visit and don’t feel obliged to reveal sensitive information. 

The internet is just a virtual world after all. 

Be smart, and be safe!

Join 15,000+ Cybersecurity Innovators

Protect. Comply. Lead.

Secure your stack, stay compliant, and outpace threats with concise, field‑tested guidance on VAPT, cloud security, and regional privacy laws delivered by Wattlecorp’s
trusted advisors across the globe.

Leave a Comment

Your email address will not be published. Required fields are marked *

Compromise Assessment for UAE   Compromise Assessment for UAE Enterprises: How to Find Out If You Have Already Been Breached 

Key Takeaways: Compromise Assessment for UAE enterprises is an evidence-based investigation that determines whether attackers have already accessed your systems, replacing assumptions with documented proof of what happened in your infrastructure. Hidden compromise costs more to remediate the longer it remains undetected, making early investigation critical for minimizing financial impact, regulatory exposure, and customer trust […]

Read more >>
SOC 2 Type II for SaaS companies Why Indian SaaS Companies Are Losing US Enterprise Deals Without SOC 2 Type II

Key Takeaways: Type I is a starting point. Type II is the deal-maker. US enterprise procurement teams do not settle for a point-in-time audit when vendor risk is on the line. Operational evidence is non-negotiable. Continuous controls, not just documented policies, are what Fortune 500 legal and compliance teams demand before signing contracts. SOC 2 […]

Read more >>
Continuous Penetration Testing for UAE Continuous Penetration Testing for UAE Enterprises: Moving Beyond Annual VAPT   

Key Takeaways: Continuous Penetration Testing helps reduce high-risk testing gaps by providing recurring vulnerability validation after application, cloud, API, and infrastructure changes. Organizations implementing continuous penetration testing services in the UAE can identify and validate vulnerabilities faster, allowing internal teams to prioritize remediation within hours or days instead of waiting months for the next annual […]

Read more >>
dpdp act vs gdpr DPDP Act vs GDPR: Key Differences Every CTO in India Must Know

Key Takeaways: GDPR compliance provides a baseline, but DPDP introduces India-specific obligations that require additional operational and technical implementation. Simplified notices, grievance redressal, and children’s data controls are India-specific obligations that most GDPR programs simply do not cover. The DPDP Act and GDPR are built differently and the GDPR gives organizations six legal grounds to […]

Read more >>
CISO cyber security AI-Powered Cyberattacks in India 2026: What CISOs Need to Know Now

Key Takeaways: Generative AI has sharply accelerated the attacker’s advantage by making phishing, reconnaissance, and exploit preparation faster and easier to scale. Being a CISO in 2026 means making real-time threat decisions at board level, that’s a different job from what most security leaders are trained for, and the skill gap is already showing. CERT-In’s […]

Read more >>
ISO 27001 internal audit Saudi Arabia ISO 27001 Internal Audit for Saudi Companies: Preparing Evidence Before Certification 

Key Takeaways: An ISO 27001 internal audit helps Saudi companies validate whether their Information Security Management System is implemented, not just documented. Certification auditors do not only review policies. They check risk registers, control ownership, access reviews, incident records, supplier reviews, audit trails, management review minutes, and corrective action evidence. For Saudi companies, ISO 27001 […]

Read more >>