It’s the most wonderful time of the year, not just for families getting gifts for their loved ones, but also for cybercriminals aiming to take advantage of stressed employees and the global pandemic who may not be as alert to cyberthreats.
Here are a few ways cybercriminals will want to steal your attention, and your money.
Fake Mis-delivery Notifications
With 75% of users planning to increase their online shopping spend this year, cybercriminals are using the escalated activity to try to attain personal information or get people to click/open email attachments. Many phishing emails often appear to come from well known retailers like Amazon or shipping companies like UPS, DHL and FedEx, that hope to lure you into clicking a link.
It’s important that if you receive an email that seems suspicious or includes a sense of urgency such as your delivery not arriving in time, always check the sender and do not open any linked attachments. If you’re ever in doubt about a package delivery, you can enter the tracking number directly on the courier’s website without engaging with the fraudulent email.
Gift Card Purchases/CEO Fraud
The holidays are also a time where loved ones send gift cards to each other and this year may see more people opt to send digital versions of them due to contact restrictions. Unfortunately, this can present a great opportunity for cybercriminals to impersonate your CEO, asking you to buy gift cards for their loved ones on their behalf due to company engagements at the end of the year.
Again, any email which includes a sense of urgency or strange request should always be checked thoroughly before engaging. We always recommend phoning the sender if you’re ever unsure, to check the request directly. It’s always better to be on the cautious side and safe, rather than rush things and potentially be liable for your actions. Automated threat detection solutions such as OnINBOX are also available to give assistance to people within their email inboxes.
In 2019, the Proofpoint Threat Insight team analyzed a malicious global email campaign which leveraged a number of topical lures into a single email that attempted to deliver the well-known malware Emotet. This campaign used multiple themes such as Swedish environmental activist Greta Thunberg, the holiday season, environmental awareness and activism, to target a larger audience. The emails had a .doc attachment which looked like instructions of how people could join a campaign march.
However if people opened the document, it instead led to the deployment of a banking trojan on the victim’s computer, causing their systems to shut down and become unusable.
All these cyberattacks by cybercriminals could have been thwarted by two main actions from users:
- Think before you click
- Be sure to double-check any suspicious requests in person
Cybercriminals never stop, and the holiday season often sees an especially high level of malware targeting the good-hearted nature of humans. Make sure you follow our simple steps to stay protected during this season of joy and hope.