Categories: Blog

COVID Phishing attacks are already here

Phishing in the time of COVID-19

There has been a sharp rise in malware and phishing attacks over the past few weeks, and attackers are capitalizing on the COVID-19 pandemic and on anxious people seeking out new information. 

It’s never a bad time to brush up on phishing, but Kaspersky Labs just put out a great piece on debunking COVID-19 phishing emails. Kaspersky is a world leader in security research and we highly recommend checking out their article here!

Here’s an example of the type of phishing email examined by them:

The “cdc.gov” link sends you to a website that looks similar to Microsoft Outlook, and asks for your email login and password. It won’t actually log you in anywhere, it’s just a place for attackers to steal your login details.

So what clued them in on the scam?

  • The e-mail address of the sender. If it ends with cdc-gov.org instead of cdc.gov, the e-mail is phishing.

  • The actual URL of the link. If you hover over the link without clicking on it, you’ll see that the real address it leads to is different than the link description. It won’t really bring you to cdc.gov.

  • The design of the phishing page. The official Microsoft Outlook website actually looks completely different. Of course, no website other than Microsoft’s should ask for your Outlook credentials. If you see such a request, know that it’s phishing and ignore it.

Many of the tips Kaspersky gives in their post are catch-all phishing precautions, so here’s a quick refresher on the basics:

If you receive any kind of message that’s unsolicited or from an unknown sender:

  1. Don’t share your personal information
  2. Avoid clicking links
  3. Don’t download files

Clicking links or downloading files from mysterious emails could infect your computer with malware, or bait you towards websites (like the one mentioned above) where your information may be phished. Rule number 1 is special though: 

Legitimate services will never ask you for personal information over email! Security questions like “What is the name of the street you grew up on?” exist specifically so that services can identify you as the account-holder without asking for your username and password. 

Get an email from the bank saying you have unauthorized activity on your account? Don’t click the links in that email! Instead, type in your bank’s website yourself, log in, and see if they actually have notifications for you there. Attackers prey on your emotion—they want to cloud your judgement by making you think something is at stake, using tactics like:

  • Accusations of being overdue
  • Informing you of critical public health updates
  • Requiring urgent action from you

Thankfully, most phishing emails and scam websites can be spotted using visual clues alone. 

  • Look at the wording
  • Look at the sender (or the URL, if you think you might be on an scam website)
  • Look at the images/logos

Put your skills to the test

You can take those learnings another step forward with this rock-solid phishing quiz that Google released last year:

If you have any other questions about phishing, or other security-related projects, drop us a line at info@newmindgroup.com!

Subscribe and get monthly updates like this

Join Newmind’s Scan for Updates newsletter, and every month you’ll receive curated updates, from headlines grabbing our attention, to remarkable technology news from Southwest Michigan.
Garrett Wenger

Garrett Wenger is a storyteller and marketer at Newmind Group, and a native to Kalamazoo, MI. He received his BFA in English Literature from Western Michigan University, and has heritage in Southwest Michigan’s creative writing community. He published his first book of poetry in late 2013, and he has been featured in numerous literary journals.

Recent Posts

These 7 AI Trends Are Sweeping the Cybersecurity Realm

Relentless digital innovation has defined the last few years. The symbiotic relationship between AI and…

1 month ago

Online Security: Addressing the Dangers of Browser Extensions

Browser extensions have become as common as mobile apps. People tend to download many and…

1 month ago

How Small Businesses Are Unlocking Growth With Generative AI

Staying ahead in business often means embracing cutting-edge technologies. New tools can unlock new avenues…

2 months ago

Examples of How a Data Breach Can Cost Your Business for Years

In the digital age, data is the lifeblood of businesses. It fuels operations, decision-making, and…

2 months ago

Are Your Smart Home Devices Spying On You? (Experts Say, Yes!)

The integration of smart home devices has become synonymous with modern living. They offer convenience,…

2 months ago

5 Ways to Leverage Microsoft 365’s New AI Innovations

Microsoft 365 has a powerful suite of cloud-based productivity tools. They can help you work…

2 months ago