Phishing Attacks Rose by 220% At Pandemic Peak Amid Global COVID-Related Fears

Stu Sjouwerman | Nov 20, 2020

Phishing Attack Pandemic Peak At a time when the last thing we need is more phishing attacks, new data shows that cybercriminals have been stepping up their game, taking full advantage of the pandemic.

In F5 Lab’s 2020 Phishing and Fraud Report, their security analysts characterize the nature of cyberattacks in 2020 as not “a revolution in the attackers’ methods but an evolution.”

The pandemic has empowered cybercriminals with all the ammunition they need to successfully get the attention of a potential victim. As with any phishing attack, it’s necessary to get the emotional attachment of the recipient and create a sense of urgency; what better way than with a seemingly out of control global virus?

According to the report, the overall growth over 12 months is only 15%, but mid-pandemic (if there is such a thing…) F5 Labs found a massive 2x spike in the amount of phishing attacks related to COVID. Also noted were some specifics around the attacks:

  • 55% of phishing sites had some form of brand impersonation in their URLs
  • 72% of all phishing sites secure their site with SSL/TLS
  • Nearly 15K SSL certificates were created with the words “covid” or “corona” in them

It’s evident that scammers believe they shouldn’t let a perfectly good pandemic go to waste.

The interesting part of this report is found in a chart that outlines the steps of a phishing attack:

www.f5.comcontentdamf5-labs-v2articlearticlesthreats22--2020-oct-dec20201110_2020_phishing_reportfigStepsInAPhishingAttack

 

Note right in the middle under “Execution” that one of two steps must be taken – both, of which, involve your users to act. That’s the secret; if you can educate your users via Security Awareness Training to NOT act, the attack chain stops right there and goes no further.

Topics: Phishing COVID-19

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.