That Email from President Trump? Yeah, That’s a Phishing Scam

Stu Sjouwerman | May 14, 2020

New phishing scams impersonating President Trump and Vice President Pence are designed to install malware or be the start of an extortion scam.

Nothing beats taking advantage of a pandemic to start yet another phishing scam. This time, according to anti-phishing vendor Inky, new scams purporting to come from the White House are being seen in the wild.

At a time when most Americans have both experienced and accepted the emergency alert system that allows texts from the President to be sent to every mobile phone, seeing an email from the President or Vice President doesn’t entirely seem to far-fetched.

According to Inky, new phishing scams are using the pandemic to trick victims into clicking on malicious links. As shown in the example below, emails contain “Coronavirus Guidelines for America.” Sounds important enough that some will fall for this scam.

5-14-20 Image

Oddly enough, scammers are attempting to extort money from organizations using an email pretending to be VP Mike Pence:

pence-email

Source: Bleeping Computer

I can’t fathom how anyone would think Mike Pence would bother to send a poorly-written email (e.g., “The Vice President of the united states”), but people are gullible and often don’t pay attention to telltale signs like this that indicate it’s a scam.

Individuals and organizations alike need to be mindful that scams use any opportunity to establish credibility (in this case, using the White House) as a means to convince you the email is legitimate, its contents read, and its attachments or links clicked. Organizations can protect themselves using Security Awareness Training to change user’s thinking about how they approach email and web content with a vigilant mindset that has just a bit of suspicion always in place. This vigilant state helps users spot obvious signs such as the poor writing and incorrect email address and know it’s a scam before they fall for it.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.