Coronavirus-Related Spear Phishing Attacks See a Massive 667% Increases in March

Stu Sjouwerman | Apr 15, 2020

COVID-19-POST3Attackers are taking advantage of the pandemic, looking for every way possible to achieve their malicious goals via targeted phishing campaigns of every kind.

Researchers at security vendor Barracuda report an unsettling uptick in the number of attacks seen last month. Over 9000 phishing attack campaigns were detected in March, versus just over 1100 in February and only 137 in January.

These phishing attacks are pulling out the stops and are taking on all forms – impersonation, business email compromise, scams, and even blackmailing, as shown below.

threat-spotlight_covid-19-types

Source: Barracuda

The potential to get users to react to emails is high – especially with the COVID-19 theming. The need for N95 masks, the desire to help raise funds for various groups of displaced individuals, investment opportunities, and more all are kindle to the phishing flames.

Organizations need to ensure their users remain vigilant to these kinds of phishing email attacks. Because they are classified by Barracuda as spear phishing attacks, it’s believed that the cybercriminals are tailoring attack social engineering to match their potential victims, making it even harder to distinguish a valid email from a phish.

Users undergoing continual Security Awareness Training are better prepared to identify these kinds of emails well-before they are able to do any damage. Despite the emotional connection to the pandemic, users receiving emails themed around COVID-19 remain able to discern when an email looks suspicious, avoiding the scam completely.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.