Check Point Says to Expect More Shipping and Delivery Phishing Emails This Season

Stu Sjouwerman | Dec 11, 2020

Shipping and Delivery PhishingWith in-person shopping still considered “high risk”, online shopping with home delivery and the need to meet delivery deadlines creates the perfect scenario for scammers.

U.S. consumers are projected to spend more this year online than ever before. And that means more prospective phishing victims as well. According to Check Point’s security researchers, there has been a 427% increase in shipping-themed phishing emails across the U.S. in November alone.

The breakdown of shipping vendors impersonated includes:

  • DHL (56%)
  • Amazon (37%)
  • Fedex (7%)

The emails, of course, use the story of some sort of delivery issue requiring the attention of the potential victim.

DHL Screenshot
Source: DHL
 

Many of these scams either direct the victim to a malicious attachment that likely uses the same tactic we saw in a recent scam pretending to be Windows Defender to enable malicious content. Other scams take victims to fake shipping vendor websites to trick victims out of personal information and, potentially, credit card details.

DHL Screenshot
Source: DHL
 

While most of these appear to be consumer-focused, it’s completely within the realm of possibility for these same scams to be sent to corporate email accounts, as organizations are still sending and receiving packages. Users need to be educated on this scam ASAP. Ideally, leveraging continual Security Awareness Training will better prepare users for phishing attacks using any themed scam.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.