The Need for Pandemic Financial Relief Spurs a Phishing Attack Impersonating the U.S. Federal Reserve

Stu Sjouwerman | May 4, 2020

iStock-1133604495Scammers use realistic-looking emails and a well-designed website under the guise of the Paycheck Protection Program to trick victims into providing banking credentials.

Everyone in the U.S. who can get some financial assistance during this pandemic is sufficiently motivated to take advantage of legitimate government programs designed to help. But one campaign was identified by anti-phishing vendor Inky that included such a realistic user experience that they even were complimentary about its’ execution.

The scam starts with an email from the “Federal Reserve” promising stimulus payments:

email%20screenshot

Victims who click the link are taken to a website that leverages FEMA and CDC logos to establish credibility.

Phishing-USFedRes-site-INKY

 

Should they click on the “Get Economic Impact Payment” button, they are presented with a list of banks, and a subsequent opportunity to provide their banking credentials. Regardless of the data entered, the victim is told there’s a problem with the credentials provided (and the bad guy gets a copy).

It’s a classic recipe: start with a sense of urgency (financial need), add in an ability to address the issue (receive stimulus money), include some credibility builders (the government logos), and ask for details that seem to be relevant to the process (banking details), and you have yourself a successful phishing scam.

Organizations can help their users with Security Awareness Training that educates them about phishing scams, as this same recipe is used time and time again to scam employees into giving up online credentials, committing fraud, infecting endpoints, and providing sensitive corporate information.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.