{"id":120479,"date":"2021-09-11T11:17:40","date_gmt":"2021-09-11T15:17:40","guid":{"rendered":"https:\/\/rbach.net\/?p=120479"},"modified":"2022-03-19T17:09:59","modified_gmt":"2022-03-19T21:09:59","slug":"10-ways-to-catch-a-covid-phish","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/10-ways-to-catch-a-covid-phish\/","title":{"rendered":"10 Ways To Catch A COVID Phish"},"content":{"rendered":"\r\n<p><a href=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/covidphishing-1.png?ssl=1\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-120497\" style=\"font-size: 16px;\" title=\"10 Ways To Catch A COVID Phish\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/covidphishing-1.png?resize=119%2C92&#038;ssl=1\" alt=\"10 Ways To Catch A COVID Phish\" width=\"119\" height=\"92\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/covidphishing-1.png?resize=150%2C116&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/covidphishing-1.png?resize=75%2C58&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/covidphishing-1.png?w=288&amp;ssl=1 288w\" sizes=\"auto, (max-width: 119px) 100vw, 119px\" \/><\/a><\/p>\r\n<p>Cybercriminals, like to take <strong>advantage of fear<\/strong>. They are taking advantage of the <a href=\"https:\/\/www.businessinsider.com\/conservative-radio-hosts-anti-maskers-death-covid-19-2021-9\" target=\"_blank\" rel=\"nofollow noopener\">ignorance-fueled<\/a>\u00a0<strong><a href=\"https:\/\/web.archive.org\/web\/20230203112654\/https:\/\/www.cdc.gov\/coronavirus\/2019-ncov\/variants\/delta-variant.html\" target=\"_blank\" rel=\"nofollow noopener\">COVID-19 Delta variant<\/a><\/strong> <a href=\"https:\/\/www.statista.com\/chart\/24248\/covid-19-case-rate-in-us-states\/\" target=\"_blank\" rel=\"nofollow noopener\">surge<\/a>. Attackers are increasingly using business-looking COVID phish emails to do their dastardly deeds.<\/p>\r\n<p><a href=\"https:\/\/creeksidepartners.com\/evaluating-risk\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-120526\" title=\"return to the office.\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/back2work-2.jpg?resize=115%2C104&#038;ssl=1\" alt=\"return to the office.\" width=\"115\" height=\"104\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/back2work-2.jpg?resize=150%2C135&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/back2work-2.jpg?resize=75%2C68&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/back2work-2.jpg?w=558&amp;ssl=1 558w\" sizes=\"auto, (max-width: 115px) 100vw, 115px\" \/><\/a><a href=\"https:\/\/thehill.com\/homenews\/state-watch\/570562-almost-half-of-manhattan-employers-delaying-return-to-work-plans-due-to\" target=\"_blank\" rel=\"nofollow noopener\">More than half<\/a> of employers are forcing a to <strong>return to the office<\/strong>. <a href=\"https:\/\/federalnewsnetwork.com\/workforce\/2021\/07\/federal-employees-must-attest-to-vaccination-or-submit-to-testing-biden-says\/\" target=\"_blank\" rel=\"nofollow noopener\">Employers are requiring<\/a> the\u00a0<a href=\"https:\/\/record.umich.edu\/articles\/u-m-will-require-covid-19-vaccination-on-all-campuses\/\" target=\"_blank\" rel=\"nofollow noopener\">submission of paperwork<\/a> such as <a href=\"https:\/\/my.clevelandclinic.org\/health\/diagnostics\/21462-covid-19-and-pcr-testing\" target=\"_blank\" rel=\"nofollow noopener\">COVID test<\/a> results and <a href=\"https:\/\/web.archive.org\/web\/20211006094126\/https:\/\/www.goodrx.com\/blog\/how-to-prove-vaccination-for-covid-19\/\" target=\"_blank\" rel=\"nofollow noopener\">proof of vaccination<\/a> to keep your job.\u00a0Hackers know that communication from employers about COVID can <strong>spark an emotional reaction<\/strong> and compel people to click. Researchers at <a href=\"https:\/\/www.proofpoint.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Proofpoint<\/a> found that business looking <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/corporate-news\/pandemic-related-email-scams-are-rise\" target=\"_blank\" rel=\"nofollow noopener\">COVID phish<\/a> attempts have increased by 33%.<\/p>\r\n<p>Cybercriminals are taking advantage of these requirements. The demands for <a href=\"https:\/\/finance.yahoo.com\/news\/workplace-vaccine-mandates-expected-accelerate-131400966.html\" target=\"_blank\" rel=\"nofollow noopener\">COVID paperwork<\/a> give the attackers more ways to disguising their phishing attempts. Sherrod DeGrippo, Vice-President of Threat Research and Detection at Proofpoint, told <a href=\"https:\/\/www.washingtonpost.com\/technology\/2021\/08\/24\/covid-vaccine-proof-scam-email\/\" target=\"_blank\" rel=\"nofollow noopener\">The Washington Post<\/a>. \u201c<em>That almost makes it easier for the bad actors because people are getting used to: \u2018Upload your negative test he<\/em><em>re, go download this COVID form, fill it out.\u2019<\/em>\u201d\u00a0<\/p>\r\n<h3>Fake O365 COVID phish attempts<\/h3>\r\n<p><a href=\"https:\/\/www.proofpoint.com\/us\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-116691\" style=\"font-size: 16px;\" title=\"Proofpoint logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_proofpoint-e1631141155226-150x35.jpg?resize=102%2C24&#038;ssl=1\" alt=\"Proofpoint logo\" width=\"102\" height=\"24\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_proofpoint-e1631141155226.jpg?resize=150%2C35&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_proofpoint-e1631141155226.jpg?resize=75%2C18&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_proofpoint-e1631141155226.jpg?w=377&amp;ssl=1 377w\" sizes=\"auto, (max-width: 102px) 100vw, 102px\" \/><\/a><\/p>\r\n<p>Proofpoint has detected fake Microsoft Office 365 phishing emails from <strong>cybercriminals posing as human resource <\/strong><strong>departments<\/strong>. The attackers ask the recipients to submit proof of vaccination. The attacker&#8217;s goal is to steal your Microsoft 365 sign-in credentials. If you receive such an email, be sure to take the time to verify that it\u2019s come directly from the organization you work for. One\u2019s vaccination card contains useful information such as birthdates or full names, which hackers could target.<\/p>\r\n<p>Proofpoint\u2019s research has found emails telling employees they\u2019ve lost their jobs due to COVID-19 are also on the rise. And what <a href=\"https:\/\/www.bloomberg.com\/news\/features\/2021-06-28\/fired-by-bot-amazon-turns-to-machine-managers-and-workers-are-losing-out\" target=\"_blank\" rel=\"nofollow noopener\">better way to<\/a> do that than tell someone they\u2019ve been fired? Mr. DeGrippo explains \u201c<em>It quite literally is clickbait. They need you to click on them, so in order to get the\u00a0<\/em><em>person to take the action, you\u2019ve got to escalate their emotional state to one that has them emotional, instead of intellectual \u2014 thinking with the smart part of the brain.\u201d<\/em><\/p>\r\n<h3>What if you suspect a phishing email<\/h3>\r\n<ol>\r\n<li><a href=\"https:\/\/www.washingtonpost.com\/technology\/2021\/08\/24\/covid-vaccine-proof-scam-email\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-120495 size-medium\" title=\"Fake O365 COVID phish email\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?resize=150%2C103&#038;ssl=1\" alt=\"Fake O365 COVID phish email\" width=\"150\" height=\"103\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?resize=150%2C103&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?resize=1024%2C704&amp;ssl=1 1024w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?resize=75%2C52&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?resize=768%2C528&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?w=1313&amp;ssl=1 1313w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/FakeCovidEmail.jpg?w=960&amp;ssl=1 960w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><strong>Breathe<\/strong> &#8211; If an email seems to make you particularly angry, worried, or curious \u2013 it\u2019s best to pause for a moment before you click.<\/li>\r\n<li>Altered domain names are a giveaway. Did\u00a0 \u201chumanresources@widgit.com\u201d suddenly become \u201cHR@widgit.com\u201d &#8211; <strong>verify these requests<\/strong> through a second channel \u2014\u00a0 get someone from HR on the phone before opening it.<\/li>\r\n<li>Be skeptical of emails from familiar people (like the CEO) who do not usually communicate directly with you. Don&#8217;t click on links or open attachments from those senders. Always <strong>get someone on the phone<\/strong> before opening it.<\/li>\r\n<li><strong>Hover over the link<\/strong> to expose the associated web addresses in the \u201cto\u201d and \u201cfrom\u201d fields. Your company&#8217;s email is probably not gmail.com.<\/li>\r\n<li><strong style=\"font-size: 16px;\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-120522\" style=\"font-size: 16px; font-weight: 400;\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Man_halt-2.jpg?resize=77%2C110&#038;ssl=1\" alt=\"\" width=\"77\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Man_halt-2.jpg?resize=105%2C150&amp;ssl=1 105w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Man_halt-2.jpg?resize=53%2C75&amp;ssl=1 53w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Man_halt-2.jpg?w=290&amp;ssl=1 290w\" sizes=\"auto, (max-width: 77px) 100vw, 77px\" \/><\/strong>Note <strong>grammatical errors<\/strong> in the text of the email; they\u2019re usually a sure sign of fraud.<\/li>\r\n<li><strong>Use different passwords for your work and personal email<\/strong>. That way, if one gets compromised, hackers can\u2019t break into the other and use it to compromise more accounts. A good password manager tool should help.<\/li>\r\n<li><strong>Don&#8217;t forward <\/strong>suspicious emails to co-workers.<\/li>\r\n<li><strong>Report suspicious emails<\/strong> to the IT security department.<\/li>\r\n<li>Install and keep <strong>up-to-date anti-malware software<\/strong> on all your devices to scan web sessions and emails.<\/li>\r\n<li><strong>Never donate to charities via links<\/strong> included in an email; instead, go directly to the charity website to donate.<\/li>\r\n<\/ol>\r\n<p style=\"text-align: center;\"><em><strong><a href=\"https:\/\/web.archive.org\/web\/20240728154520\/https:\/\/www.cdc.gov\/coronavirus\/2019-ncov\/prevent-getting-sick\/prevention.html?CDC_AA_refVal=https%3A%2F%2Fwww.cdc.gov%2Fcoronavirus%2F2019-ncov%2Fprepare%2Fprevention.html\" target=\"_blank\" rel=\"noopener noreferrer\">Stay safe out there!<\/a><\/strong><\/em><\/p>\r\n<p><strong>Related article<\/strong><\/p>\r\n<ul>\r\n<li><a title=\"What Every Worker Needs to Know About Vaccine Mandates\" href=\"https:\/\/www.aarp.org\/work\/working-at-50-plus\/info-2021\/workers-vaccine-mandates.html\" target=\"_blank\" rel=\"nofollow noopener\">What Every Worker Needs to Know About Vaccine Mandates<\/a>\u00a0(<a title=\"AARP\" href=\"https:\/\/www.aarp.org\/\" target=\"_blank\" rel=\"nofollow noopener\">AARP<\/a>)<\/li>\r\n<\/ul>\r\n<p>&nbsp;<\/p>\r\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a>\u00a0about IT, careers, and anything else that catches his attention since 2005. You can follow him on\u00a0<a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are using the pandemic to continue their attacks, here are 10 ways yo catch a COVID phish email and protect your email and job.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3558,3419,23,1606,612,4],"class_list":["post-120479","post","type-post","status-publish","format-standard","hentry","category-security","tag-3558","tag-covid-19","tag-malware","tag-office-365","tag-phishing","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/120479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=120479"}],"version-history":[{"count":22,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/120479\/revisions"}],"predecessor-version":[{"id":131898,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/120479\/revisions\/131898"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=120479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=120479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=120479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}