Sextortion Email Scams Now Include Threats to Infect Victims with COVID-19

Stu Sjouwerman | Mar 31, 2020

COVID-19-POST3In what may be either a moment of brilliance or desperation, scammers are attempting to use coronavirus infection threats as a means of further convincing victims to pay up.

Since they began in July of 2018, sextortion scams have evolved. They originally started because of exposed credentials as part of earlier data breaches. These credentials were enough to establish credibility that the sender knew something about the recipient. The general scam is to state that the scammer knows the victim has been going on adult sites and will “out” them if they don’t pay up.

In a modern twist, security researchers at Sophos have spotted a variant of this scam where the scammer makes the laughable claim that they can infect the recipient and their whole family!

Sextortion-mail-sample

Source: ExecuteMalware

As with every sextortion scam, they all can safely be deleted and forgotten. What is interesting is the use of homographic characters in the message. These “lookalike” characters allow messages like this to pass inspections by email scanning engines looking for specific phrases and words.

We’ve seen an uptick in corporate users being the target of these kinds of scams – presumably, receiving this at a work email address is intended on creating additional anxiety, as the recipient doesn’t want to lose their job. Organizations need to keep employees educated using Security Awareness Training to prepare them for the day a phishing email may will reach their Inbox and attempt to evoke a response that could put the recipient and the organization at risk.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.