COVID-19: Cyber Fraud on the Rise
The COVID-19 crisis is having a widespread impact on our society and is fundamentally changing the way in which businesses operate. Following recent government advice, many businesses find themselves operating predominately remotely which has in turn resulted in a rapid increase in the number of cyber-attacks being conducted against businesses and individuals, a number which is only expected to increase further in the coming weeks and months. There has been a marked increase in attempts at fraudulent activity with COVID-19 related scams often used to distribute specifically tailored and engineered malware, leading to substantial losses for businesses and individuals, as criminals seek to capitalise on the global pandemic.
A common example of this is where a cyber-criminal poses as a trusted organisation, such as a bank, or as a trusted individual within such an organisation such as a co-worker or IT administrator, in the hope that victims will mistake their malicious emails for legitimate ones.
One of the most prevalent scams to be aware of at the moment are ‘Business Email Compromise’ (“BEC”) scams, which are designed to trick victims into transferring funds or sensitive data, particularly corporate data, to an account used by the cyber-criminal. BEC campaigns are targeting manufacturing, finance, pharmaceuticals, healthcare and transportation companies in particular. These emails typically include attachments that contain malware designed to harvest sensitive data, or harmful ransomware that could disrupt availability and access to information systems. The emails also aim to steal employee credentials in order to infiltrate organisations and compromise information systems, in particular corporate payment systems, as well as the disruption of services. Once a footing has been established in the system it opens the channels for cyber-criminals to proceed with more fraud.
Many scams also include COVID-19 themed ‘phishing’ emails designed to trick users to click a link or download an attachment. Once a system is compromised, details such as usernames and passwords for email accounts and bank accounts are extracted and can further infect devices with malware software. Cyber-criminals often use a variety of different platforms in order to access victims data, including via email, text, phone and social media and often by posing as organisations such as banks and government bodies in order to get victims to disclose personal or financial information.
In recent weeks there has been a particular increase in phishing and BEC scams being distributed, usually disguised as government announcements from bodies such as the World Health Organisation. There has also been a reported increase in fraudulent COVID-19 related websites which purport to sell protective equipment such as masks and hand sanitiser, which are in fact vehicles of fraud. It is unlikely that these cyber-attacks, such as phishing campaigns, will cease to be a concern in the coming months, as more and more organisations may be impersonated in fraudulent attacks.
It is important that businesses are aware of the risks of cyber-crime and have suitable procedures in place to deal with cyber-security threats. As employees are a business’s first line of defense, it is important that businesses protect themselves by increasing employees’ awareness of Covid-19 related cyber-scams. Employers should take steps to implement procedures to help reduce their risk such as educating employees of the risks and encouraging them to be skeptical of emails from unfamiliar sources. It is also critically important that employees are asked to report any events where they may have been targeted by cyber-criminals.
Many businesses will need to be prepared for increased demand for access to organisational resources from personal devices with an increase of employees working remotely, which increases the risk of unsecured network access and strain on IT systems which leaves them more open to receiving potentially fraudulent traffic.
How we can help
If you have any queries or concerns, or would like to discuss the above in further detail, please feel free to contact Joe McVeigh or Lee Taren in our Privacy & Data Security Team.
This article is for general information purposes. Legal advice must be obtained for individual circumstances. Whilst every effort has been made to ensure the accuracy of this article, no liability is accepted by the author for any inaccuracies.