Last Christmas, I gave you my heart, my bank codes and my online identity

It’s the most wonderful time of the year, not just for families getting gifts for their loved ones, but also for cybercriminals aiming to take advantage of stressed employees and the global pandemic who may not be as alert to cyberthreats. 

Here are a few ways cybercriminals will want to steal your attention, and your money.

Fake Mis-delivery Notifications

With 75% of users planning to increase their online shopping spend this year, cybercriminals are using the escalated activity to try to attain personal information or get people to click/open email attachments. Many phishing emails often appear to come from well known retailers like Amazon or shipping companies like UPS, DHL and FedEx, that hope to lure you into clicking a link. 

It’s important that if you receive an email that seems suspicious or includes a sense of urgency such as your delivery not arriving in time, always check the sender and do not open any linked attachments. If you’re ever in doubt about a package delivery, you can enter the tracking number directly on the courier’s website without engaging with the fraudulent email.

Gift Card Purchases/CEO Fraud

The holidays are also a time where loved ones send gift cards to each other and this year may see more people opt to send digital versions of them due to contact restrictions. Unfortunately, this can present a great opportunity for cybercriminals to impersonate your CEO, asking you to buy gift cards for their loved ones on their behalf due to company engagements at the end of the year. 

Again, any email which includes a sense of urgency or strange request should always be checked thoroughly before engaging. We always recommend phoning the sender if you’re ever unsure, to check the request directly. It’s always better to be on the cautious side and safe, rather than rush things and potentially be liable for your actions.

Seasonal/Topical Scams

In 2019, the Proofpoint Threat Insight team analyzed a malicious global email campaign which leveraged a number of topical lures into a single email that attempted to deliver the well-known malware Emotet. This campaign used multiple themes such as Swedish environmental activist Greta Thunberg, the holiday season, environmental awareness and activism, to target a larger audience. The emails had a .doc attachment which looked like instructions of how people could join a campaign march.

However if people opened the document, it instead led to the deployment of a banking trojan on the victim’s computer, causing their systems to shut down and become unusable.

All these cyberattacks by cybercriminals could have been thwarted by two main actions from users: 

  • Think before you click 
  • Be sure to double-check any suspicious requests in person

Cybercriminals never stop, and the holiday season often sees an especially high level of malware targeting the good-hearted nature of humans. Make sure you follow our simple steps to stay protected during this season of joy and hope.

PUBLISHED BY

Faisal Misle

22 Dec. 2020

SHARE ARTICLE:

Recent Posts

VIEW ALL
Product Release

Red Sift’s Quarterly Product Release, Fall 2025

Francesca Rünger-Field

This Fall marks a major expansion of Red Sift Brand Trust with the launch of Social Media Monitoring, a new add-on that helps organizations detect and respond to fraudulent company and executive profiles across platforms such as Facebook, Instagram, LinkedIn, TikTok, and X. By extending protection beyond domains, Brand Trust now gives security teams…

Read more
AI

Red Sift’s AI Agent, Part III: Performance in action

Phong Nguyen

This is the third article in our AI Agent series. In Part 1, we introduced Red Sift’s AI Agent for lookalike classification – an intelligent solution for handling the ambiguous cases that rule-based automation can’t confidently resolve, offering analyst-grade triage autonomously. In Part 2, we took readers behind the scenes to explore the engineering…

Read more
Finance

41% of top Fintech companies are vulnerable to email phishing

Jack Lilley

Only 26% of leading Fintechs enforce DMARC at p=reject, the strongest protection against spoofing by bad actors. Phishing remains a top driver of breaches and fraud. Financial services are a prime target because email moves money, resets passwords, and confirms identity. Verizon’s 2025 Data Breach Investigations Report again lists social engineering and phishing among…

Read more
Certificates

New in Certificates Lite: Active certificate scanning and smarter expiry alerts

Francesca Rünger-Field

A quick recap Earlier this year, we launched Red Sift Certificates Lite, the free TLS certificate expiration monitoring service recommended by Let’s Encrypt. Since launch, thousands of organizations have adopted it to track their certificates and avoid expiry-related outages. What we heard from customers At launch, we had adopted Let’s Encrypt’s approach for consistency…

Read more