[Heads-up] Scam Of The Week: Coronavirus Phishing Attacks In The Wild



CoronavirusYup, you can count on it, when there is a worldwide health scare, the bad guys are on it like flies on $#!+. We are seeing a new malicious phishing campaign that is based on the fear of the Coronavirus, and it's the first of many.

The message is obviously not from the CDC and at the time of this writing, there are very very few local cases in America. Let's hope it stays that way.

Here is a sample of the message that is being used. Your users can report this as phishing through the free Phishing Alert Button, delete the message if they receive it, or use your existing reporting mechanisms. There will be many other social engineering attacks using this same scare. This is a screen shot of the real attack:

coronavirus-in-the-wild

We also strongly recommend you send them a simulated phishing template to—pun intended—inoculate them against attacks like this. As an exception (we normally do not show these templates) but here is what your ready-to-send campaign looks like.

coronatemplate-1

I would send your employees, friends and family something like the following. Feel free to copy/paste/edit.

"The worldwide spread of the new Coronavirus is being used by bad guys to scare people into clicking on links, open malicious attachments, or give out confidential information. Be careful with anything related to the Coronavirus: emails, attachments, any social media, texts on your phone, anything. Look out for topics like:

  • Check updated Coronavirus map in your city
  • Coronavirus Infection warning from local school district
  • CDC or World Health Organization emails or social media Coronavirus messaging
  • Keeping your children safe from Coronavirus
  • You might even get a scam phone call to raise funds for "victims".

There will be a number of scams related to this, so  please remember to Think Before You Click

For KnowBe4 Customers, you can find the above simulated phishing template in the Current Events category. I suggest you send to your employees and friends / family more or less immediately. 

Let's stay safe out there.

Warm regards,

Stu Sjouwerman

Founder and CEO, KnowBe4, Inc.

NewStu.png


Free Phish Alert Button

Do your users know what to do when they receive a phishing email? KnowBe4's Phish Alert Button gives your users a safe way to forward email threats to the security team for analysis and deletes the email from the user's inbox to prevent future exposure. All with just one click! Phish Alert benefits: 

home-KnowBe4-Phish-Alert-2Here's how it works:

  • Reinforces your organization’s security culture
  • Users can report suspicious emails with just one click
  • Incident Response gets early phishing alerts from users, creating a network of “sensors”
  • Email is deleted from the user's inbox to prevent future exposure
  • Easy deployment via MSI file for Outlook, Google Workspace deployment for Gmail (Chrome) and manifest install for Microsoft 365

Get Your Phish Alert Button

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/free-phish-alert



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews