[HEADS UP] NHS Issues Warning as UK COVID-19 Vaccine Scams Are Still Running Rampant



NHS Warning of COVID-19 AttackThe National Health Service (NHS) in the UK recently sent a warning that cybercriminals are using social engineering tactics to target people wanting a COVID-19 vaccine email that is indeed, a phishing attack.

While emotions about the pandemic are still running high, it's important that your organisation stays cautious of the different types of attacks. Akamai gives a breakdown of the different types of COVID-19 attacks and the different warning signs your organization should watch out for: 

Shopping

Since the initial lockdown, online shopping has significantly increased. The Internet is also prime hunting ground for cybercriminals. The example below shows how cybercriminals developed and sold COVID-19 related scam sites earlier in the pandemic. 

NHS-COV-19-Vaccine_Scam_publication-FIG1

Source: Akamai

Credential Phishing

Throughout 2020, cybercriminals used COVID-19 to their advantage in almost all of their phishing campaigns. The campaigns use COVID-19 spread and safety information, vaccine development, vaccine testing, and lockdown information to target vulnerable victims. This example below shows a phishing kit that shows various usernames and passwords for multiple email services that would require your email credentials:

NHS-COV-19-Vaccine_Scam_FIG2

Source: Akamai

Vaccines

Now that the vaccine is available, cybercriminals have now focused all of their attention on targeting victims with vaccine phishing emails. The example below shows the most recent phishing landing page: 

NHS-COV-19-Vaccine_Scam_FIG3

Source: Akamai

There are quite a few problems if you really look into this example, with grammatical mistakes. But if you weren't paying enough attention, then you would be easily fooled. "The NHS is performing selections for coronavirus vaccination on the basis of family genetics and medical history. You have been selected to receive a coronavirus vaccination," the landing page explains.

Unfortunately, the pandemic and phishing attacks are not going away anytime soon. Make sure you visit the NHS website for any updates on any scams. Make sure you are frequently testing your users and utilise new-school security awareness training to ensure your users are prepared in their day-to-day job functions. 

Akamai has the full story


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews