Phishing Scams: A Side Effect of the Coronavirus

Keep yourself and your employees safe!
The world is going through some trying times right now, with the coronavirus affecting the economy and the lives of people in an unprecedented way.
Among all this chaos, there are a few people who want to take advantage of this situation for their own selfish malicious needs, which come under the cybercrimes in the pandemic. This is carried out most commonly by phishing techniques, and it’s something to keep an eye out for, as it could possibly lead to large-scale data breaches.
As an individual and as a company, it is important to understand the harm phishing can do.
Phishing is a serious cybercrime in which an individual pretends to be a legitimate institution and requests users for sensitive data such as passwords, credit card numbers or account details. This is usually carried out by email, telephone, SMS, or other social media websites.
Being a victim of a phishing attack can cost you sensitive data, loss of productivity, and a black mark on your brand image. The information stolen from you can then be sold to the highest bidder in black markets and the dark web.
The most important factor to consider about phishing attacks is the scale of the attack. These scams aren’t usually targeted at a single individual or a small group of people; they are carried out on a very large scale, affecting hundreds of thousands of people, out of which a good percentage may be gullible to the attack and leak-sensitive information.
These attacks are most effective when carried out in times of economic crisis, such as now, as people are always looking forward to a helping hand to get them through these tough times. Little do they know that they’re facing the devil in disguise.
The most popular phishing scam in India right now is – using fake emails posing as the Indian government claiming to provide free COVID-19 tests and other resources. Eventually, they end up stealing personal and financial information from innocent citizens. They can also convince you to download malicious files which could cause permanent damage to your systems.
According to the Indian Computer Emergency Response Team (CERT-In), the attack is being carried out by the North Korean hacker group Lazarus, and they have close to two million individual email ids of citizens from major cities like Delhi, Mumbai, Hyderabad, Chennai, and Ahmedabad to launch the attack on.
The World Health Organization has also warned us about an international phishing scam targeted at an extremely large scale audience via fraudulent emails and WhatsApp messages, in which the attackers claim to be representatives of the WHO and ask for details like passwords and bank account details, and trick you into downloading attachments and opening malicious links.
Now that we know how phishing attacks can cause harm on a large scale,
Read More About the Arogya setu Dilemma
How to differentiate phishing emails from genuine ones.
- The easiest way to identify a phishing email is by checking the spelling of the sender.
For example, a malicious email can pretend to be the Bank of America by spelling it as “Bank of Arnerica”. Notice that the ‘m’ in America is replaced with an ‘r’ and an ‘n’.
- Another indicator of a phishing email is that if you feel like it’s too good to be true, it probably is. If you receive an email from the WHO stating that the cure to the coronavirus has been found, but you don’t see anything on the news, you can confidently classify it as a scam.
- If you receive an attachment when you weren’t expecting one, there is a high chance it could be malware. Make sure you have a virus checker to verify it for you. If the file is too large, double-check the sender and don’t download it unless you’re sure it’s absolutely necessary for you.
- The same rule applies to hyperlinks. You can usually see the page a hyperlink redirects to when you hover over it. Make sure it’s not a malicious website. Some signs of malicious websites are misspelled URLs, URLs with random alphabets and numbers, the absence of an SSL certificate, and multiple redirections and pop-ups.
- Also, closely examine the content of any email you receive. Generic greetings like “Dear Sir/Ma’am” which don’t include your name, and instructions to take some urgent action like clicking on a link or downloading an attachment could be indicators of a phishing scam.
Read More About the Cybersecurity courses and certifications of this COVID Times
The best way to avoid being a victim of phishing scams is really just good observational skills and common sense.
Always read emails carefully and watch out for any of the phishing indicators listed above. A phishing email can usually be distinguished from a genuine one quite easily. Don’t rely entirely on the information you receive via emails, especially health data. Refer to legitimate websites like the official website of the World Health Organization for updates and information regarding the pandemic.
Always remember that organizations such as banks will never ask you for your account details via email or phone; so there’s no need to reveal any of that information online. Be careful about the websites you visit and don’t feel obliged to reveal sensitive information.
The internet is just a virtual world after all.
Be smart, and be safe!
Qatar Cybersecurity Boardroom Accountability: Why QCB and NCSA Now Expect Executive Ownership
Key Takeaways: Cybersecurity in Qatar is increasingly becoming an executive governance responsibility, with national cybersecurity initiatives and sector-specific requirements encouraging organizations to establish stronger leadership oversight. QCB and NCSA play important roles in strengthening cybersecurity governance in Qatar, with QCB focusing on financial sector requirements and NCSA supporting national-level cybersecurity coordination and guidance. Executives can’t […]
Data Privacy Consulting for Saudi Enterprises: How to Operationalize PDPL Data Subject Rights in 2026
Key Takeaways: The Saudi data protection law may apply to organizations outside the Kingdom when they process personal data related to individuals in Saudi Arabia, meaning geographic location alone does not automatically exclude an organization from PDPL obligations. PDPL data subject rights span access, correction, deletion, and consent withdrawal, and enterprises are on the hook […]
Third-Party Vendor Security Risk Assessment Under DPDP: A Guide for Indian Enterprises
Key Takeaways: Third-party vendor risk assessment with DPDP practices helps Indian enterprises to verify that external partners handle personal data with adequate safeguards. The Digital Personal Data Protection Act holds data fiduciaries accountable for vendor conduct, which makes due diligence a legal and operational necessity. A structured vendor security questionnaire, covering encryption, access control, and […]
Virtual CISO Services for UAE Free Zone Startups: Affordable Security Leadership for Growing Companies
Key Takeaways: Most startups already hold sensitive data such as customer info, source code, financials, long before they feel big enough to take security seriously, and that’s exactly when the risk starts. A virtual CISO gets you someone who’s done this before, setting up strategy and guiding compliance, without the cost of putting a full-time […]
SOC as a Service for Indian BFSI and FinTech Companies: 24/7 Monitoring for CERT-In Readiness
Key Takeaways: SOC as a Service for BFSI and FinTech India gives banks, NBFCs, insurers and digital lenders continuous security visibility without the cost and hiring effort of building an in-house operations centre. CERT-In directions require regulated entities to report qualifying cyber incidents within six hours of detection, and implementing SOC for BFSI and FinTech […]
SOC as a Service in India: How It Works, Pricing, and Why Businesses Need It
Key Takeaways: SOC as a Service helps Indian businesses to get 24×7 security monitoring without huge cost and complexity of building a full in-house security operations center. A managed SOC check and analyse beyond basic log monitoring, which combining SIEM, threat intelligence, analyst-led alert triage, incident escalation, reporting, and security response support. SOC as a […]