Last Christmas, I gave you my heart, my bank codes and my online identity

It’s the most wonderful time of the year, not just for families getting gifts for their loved ones, but also for cybercriminals aiming to take advantage of stressed employees and the global pandemic who may not be as alert to cyberthreats. 

Here are a few ways cybercriminals will want to steal your attention, and your money.

Fake Mis-delivery Notifications

With 75% of users planning to increase their online shopping spend this year, cybercriminals are using the escalated activity to try to attain personal information or get people to click/open email attachments. Many phishing emails often appear to come from well known retailers like Amazon or shipping companies like UPS, DHL and FedEx, that hope to lure you into clicking a link. 

It’s important that if you receive an email that seems suspicious or includes a sense of urgency such as your delivery not arriving in time, always check the sender and do not open any linked attachments. If you’re ever in doubt about a package delivery, you can enter the tracking number directly on the courier’s website without engaging with the fraudulent email.

Gift Card Purchases/CEO Fraud

The holidays are also a time where loved ones send gift cards to each other and this year may see more people opt to send digital versions of them due to contact restrictions. Unfortunately, this can present a great opportunity for cybercriminals to impersonate your CEO, asking you to buy gift cards for their loved ones on their behalf due to company engagements at the end of the year. 

Again, any email which includes a sense of urgency or strange request should always be checked thoroughly before engaging. We always recommend phoning the sender if you’re ever unsure, to check the request directly. It’s always better to be on the cautious side and safe, rather than rush things and potentially be liable for your actions.

Seasonal/Topical Scams

In 2019, the Proofpoint Threat Insight team analyzed a malicious global email campaign which leveraged a number of topical lures into a single email that attempted to deliver the well-known malware Emotet. This campaign used multiple themes such as Swedish environmental activist Greta Thunberg, the holiday season, environmental awareness and activism, to target a larger audience. The emails had a .doc attachment which looked like instructions of how people could join a campaign march.

However if people opened the document, it instead led to the deployment of a banking trojan on the victim’s computer, causing their systems to shut down and become unusable.

All these cyberattacks by cybercriminals could have been thwarted by two main actions from users: 

  • Think before you click 
  • Be sure to double-check any suspicious requests in person

Cybercriminals never stop, and the holiday season often sees an especially high level of malware targeting the good-hearted nature of humans. Make sure you follow our simple steps to stay protected during this season of joy and hope.

PUBLISHED BY

Faisal Misle

22 Dec. 2020

SHARE ARTICLE:

Recent Posts

VIEW ALL
DMARC

74% of US credit unions vulnerable to email spoofing: Is your organization…

Stuart Rogers

Email remains a heavy lifter for credit unions, whether it’s member notices, statements, loan workflows, or vendor coordination. That’s exactly why impersonation keeps paying, with the National Credit Union Association (NCUA) warning that all credit unions and vendors are active targets for phishing and social engineering, and urges rapid incident reporting when attacks hit.…

Read more
DKIM

La Poste annonce de nouvelles exigences d’authentification des e-mails pour tous les…

Jack Lilley

La Poste (laposte.net) a annoncé aujourd’hui des changements importants à ses exigences d’authentification des e-mails qui entreront en vigueur en septembre 2025. Ces nouvelles exigences changeront fondamentalement la façon dont les e-mails sont traités et livrés aux adresses e-mail de La Poste. Qu’est-ce qui change ? À partir de septembre, La Poste mettra en…

Read more
DMARC

La Poste announces new email authentication requirements for all senders

Jack Lilley

La Poste (laposte.net) has today announced significant changes to its email authentication requirements that will take effect in September 2025. These new requirements will fundamentally change how emails are processed and delivered to La Poste email addresses. What’s changing? Starting in September, La Poste will implement strict email authentication protocols that will affect all…

Read more
DMARC

Put your Microsoft Azure commitment (MACC) to work with Red Sift OnDMARC

Francesca Rünger-Field

When organizations sign commercial agreements with Microsoft, they often include a Microsoft Azure Consumption Commitment (MACC). In simple terms, this is a pledge to spend a set amount on Azure over one to three years. It ensures predictable cloud spend for Microsoft and, in return, can unlock better pricing and incentives for the customer.…

Read more