Phishing Scams: A Side Effect of the Coronavirus

Keep yourself and your employees safe!
The world is going through some trying times right now, with the coronavirus affecting the economy and the lives of people in an unprecedented way.
Among all this chaos, there are a few people who want to take advantage of this situation for their own selfish malicious needs, which come under the cybercrimes in the pandemic. This is carried out most commonly by phishing techniques, and itโs something to keep an eye out for, as it could possibly lead to large-scale data breaches.ย
As an individual and as a company, it is important to understand the harm phishing can do.
Phishing is a serious cybercrime in which an individual pretends to be a legitimate institution and requests users for sensitive data such as passwords, credit card numbers or account details. This is usually carried out by email, telephone, SMS, or other social media websites.ย
Being a victim of a phishing attack can cost you sensitive data, loss of productivity, and a black mark on your brand image. The information stolen from you can then be sold to the highest bidder in black markets and the dark web.ย
The most important factor to consider about phishing attacks is the scale of the attack. These scams arenโt usually targeted at a single individual or a small group of people; they are carried out on a very large scale, affecting hundreds of thousands of people, out of which a good percentage may be gullible to the attack and leak-sensitive information.ย
These attacks are most effective when carried out in times of economic crisis, such as now, as people are always looking forward to a helping hand to get them through these tough times. Little do they know that theyโre facing the devil in disguise.
The most popular phishing scam in India right now is – using fake emails posing as the Indian government claiming to provide free COVID-19 tests and other resources. Eventually, they end up stealing personal and financial information from innocent citizens. They can also convince you to download malicious files which could cause permanent damage to your systems.
According to the Indian Computer Emergency Response Team (CERT-In), the attack is being carried out by the North Korean hacker group Lazarus, and they have close to two million individual email ids of citizens from major cities like Delhi, Mumbai, Hyderabad, Chennai, and Ahmedabad to launch the attack on.ย
The World Health Organization has also warned us about an international phishing scam targeted at an extremely large scale audience via fraudulent emails and WhatsApp messages, in which the attackers claim to be representatives of the WHO and ask for details like passwords and bank account details, and trick you into downloading attachments and opening malicious links.
Now that we know how phishing attacks can cause harm on a large scale,
Read More About the Arogya setu Dilemma
How to differentiate phishing emails from genuine ones.
- The easiest way to identify a phishing email is by checking the spelling of the sender.
For example, a malicious email can pretend to be the Bank of America by spelling it as โBank of Arnericaโ. Notice that the โmโ in America is replaced with an โrโ and an โnโ.
- Another indicator of a phishing email is that if you feel like itโs too good to be true, it probably is. If you receive an email from the WHO stating that the cure to the coronavirus has been found, but you donโt see anything on the news, you can confidently classify it as a scam.ย
- If you receive an attachment when you werenโt expecting one, there is a high chance it could be malware. Make sure you have a virus checker to verify it for you. If the file is too large, double-check the sender and donโt download it unless youโre sure itโs absolutely necessary for you.
- The same rule applies to hyperlinks. You can usually see the page a hyperlink redirects to when you hover over it. Make sure itโs not a malicious website. Some signs of malicious websites are misspelled URLs, URLs with random alphabets and numbers, the absence of an SSL certificate, and multiple redirections and pop-ups.ย
- Also, closely examine the content of any email you receive. Generic greetings like โDear Sir/Maโamโ which donโt include your name, and instructions to take some urgent action like clicking on a link or downloading an attachment could be indicators of a phishing scam.
Read More About the Cybersecurity courses and certifications of this COVID Times
The best way to avoid being a victim of phishing scams is really just good observational skills and common sense.ย
Always read emails carefully and watch out for any of the phishing indicators listed above. A phishing email can usually be distinguished from a genuine one quite easily. Donโt rely entirely on the information you receive via emails, especially health data. Refer to legitimate websites like the official website of the World Health Organization for updates and information regarding the pandemic.ย
Always remember that organizations such as banks will never ask you for your account details via email or phone; so thereโs no need to reveal any of that information online. Be careful about the websites you visit and donโt feel obliged to reveal sensitive information.
The internet is just a virtual world after all.
Be smart, and be safe!
Mobile Application Penetration Testing for Qatar Government Digital Services: NCSA-ย Alignedย Securityย Assuranceย
Key Takeaways: Mobile Application Penetration Testing Qatar must cover the app, device storage, APIs, authentication and third-party components. Qatarโs NCSA assurance environment combines the National Information Assurance (NIA) Standard, the National Information Security Compliance Framework (NISCF) and accredited security assessment services. OWASP MASVS defines mobile security controls, while MASTG supplies practical test methods for Android […]
Qatar Data Protection Law: Implementing PDPPL Data Subject Rights Processes for Businessesย
Key Takeaways: The Qatar Data Protection Law (Law No. 13 of 2016) for Personal Data Privacy Protection, grants individuals specific rights such as right to access, correct, erase, object, withdraw consent, and right to be notified of processing or inaccurate disclosure. Beyond having a privacy policy, businesses or controllers, under Article 11 of Personal Data […]
AI Governance for Indian Enterprises: Building Internal Controls Beforeย Keyย DPDPย Obligationsย Take Effectย
Key Takeaways: The DPDP Act does not contain AI-specific provisions. Its requirements, however, apply in situations when an AI system processes digital personal data within its territorial and material scope. India is working on building a broader governance framework around safety, accountability, transparency and trust via programs like the IndiaAI Mission. Indian organizations should inventory […]
Cloud Security Audit for UAE Government Cloud Migration: NCAP and Security Requirements
Key Takeaways: A cloud security audit UAE helps government entities identify security, governance, configuration, access, data-protection and resilience gaps, before and after shifting critical workloads to the cloud. UAE National Cloud Security Policy has defined cloud governance, data security, data sovereignty, IAM, incident management, resilience, portability and cloud operations requirements. The National Cyber Accreditation Program […]
Data Privacy Consulting UAEย โย Building a PDPL-Compliant Data Governance Program
Key Takeaways: PDPL compliance requires ongoing operational governance that goes beyond policies to demonstrate how personal data is collected, used, protected, transferred, retained, and deleted. Data mapping helps businesses move from reactive compliance to proactive risk management by establishing a comprehensive inventory of the data ecosystem, helping build a mature data privacy and governance program. […]
Saudi Arabia’s Critical Systems Controls: What CSP-Linked Enterprises Must Comply With in 2026
Key Takeaways: The Critical Systems Cybersecurity Controls (CSCC) are more applicable to critical systems than to all IT assets owned or operated by an organization. To be in full compliance or to remain in full compliance with CSCC, organizations must maintain continuous adherence to NCA ECC. CSCC has 32 core controls and 73 sub-controls across […]