[HEADS UP] NHS Issues Warning as UK COVID-19 Vaccine Scams Are Still Running Rampant

Stu Sjouwerman | Feb 11, 2021

NHS Warning of COVID-19 AttackThe National Health Service (NHS) in the UK recently sent a warning that cybercriminals are using social engineering tactics to target people wanting a COVID-19 vaccine email that is indeed, a phishing attack.

While emotions about the pandemic are still running high, it's important that your organisation stays cautious of the different types of attacks. Akamai gives a breakdown of the different types of COVID-19 attacks and the different warning signs your organization should watch out for: 

Shopping

Since the initial lockdown, online shopping has significantly increased. The Internet is also prime hunting ground for cybercriminals. The example below shows how cybercriminals developed and sold COVID-19 related scam sites earlier in the pandemic. 

NHS-COV-19-Vaccine_Scam_publication-FIG1

Source: Akamai

Credential Phishing

Throughout 2020, cybercriminals used COVID-19 to their advantage in almost all of their phishing campaigns. The campaigns use COVID-19 spread and safety information, vaccine development, vaccine testing, and lockdown information to target vulnerable victims. This example below shows a phishing kit that shows various usernames and passwords for multiple email services that would require your email credentials:

NHS-COV-19-Vaccine_Scam_FIG2

Source: Akamai

Vaccines

Now that the vaccine is available, cybercriminals have now focused all of their attention on targeting victims with vaccine phishing emails. The example below shows the most recent phishing landing page: 

NHS-COV-19-Vaccine_Scam_FIG3

Source: Akamai

There are quite a few problems if you really look into this example, with grammatical mistakes. But if you weren't paying enough attention, then you would be easily fooled. "The NHS is performing selections for coronavirus vaccination on the basis of family genetics and medical history. You have been selected to receive a coronavirus vaccination," the landing page explains.

Unfortunately, the pandemic and phishing attacks are not going away anytime soon. Make sure you visit the NHS website for any updates on any scams. Make sure you are frequently testing your users and utilise new-school security awareness training to ensure your users are prepared in their day-to-day job functions. 

Akamai has the full story

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.