Cyber threats are continually evolving in complexity and volume, but the pandemic presents new opportunities for cyber criminals. In addition to identity theft, phishing, charity scams, and investment schemes, these scammers will use everything from COVID-19 vaccines and fake coronavirus cures to stimulus checks and PPE loans in efforts to trick you, your company, and your employees.
Defending Against COVID-19 Cyber Scams
The Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about increased cybercriminal activity brought on by the coronavirus pandemic.
The CISA alert warns the nation to safeguard against cyber actors and malicious cyber activity within email attachments, links, fraudulent websites, and social media content. A cyber crook's goal often includes gaining access to networks, tricking users into revealing sensitive private information, or donating to fraudulent charities and causes. As this active Alert explains: "Exercise caution in handling any email with a COVID-19-related subject line, attachment, or hyperlink, and be wary of social media pleas, texts, or calls related to COVID-19."
Cyber actors initiate threats within your organization or from outside entities attempting to gain access over the internet. These bad actors include disgruntled employees, terrorist groups, hostile governments, and malicious intruders.
CISA outlines the most common cyber threat sources and reinforces some of the necessary precautions you should be taking to increase your security defense against COVID-19 themed cyber threats:
FBI: Continued Spike in COVID-19 scams
The FBI is also warning the nation about what they call an "unprecedented wave" of cyber-attacks. The three states hit the hardest by coronavirus were the first to get hit with pandemic-inspired cyber-attacks. California, New York, and Washington gave us a first look at the breadth and scope of these attacks, but as the virus surges and the country rolls out vaccines everywhere, cybercriminals have broadened their focus to target the whole country.
In their continued exploitation of the coronavirus pandemic, the FBI also warns hackers are targeting employees working from home. Cybercriminals know that the coronavirus is a hot topic for most Americans, so they will use it to bait and take advantage of unsuspecting individuals and businesses.
CISA Insights So You Can Respond to COVID-19
If your organization still operates in alternate workplace options due to COVID-19, CISA recommends examining your information technology systems' security. Cybersecurity risk management involves everyone on your teams, so it is important to increase cybersecurity awareness for employees who work remotely. Initiate or increase employee training on phishing scams and other malicious attacks, including examples of malicious emails you receive or relevant attacks in the news.
Be aware of an increase in phishing emails or texts directing you to sign in to your accounts. Be sure to vet incoming messages, emails or phone calls, especially under the guise of an emergency, hoping you won't take the time to verify its authenticity.
Cyber threat actors represent the most significant information security threat to small businesses today. Due to their unknown origins, criminal nature, and a target organization's lack of resource sophistication, internal teams struggle to detect these threats in time.
Small businesses need threat intelligence for improved insight that goes beyond their network boundaries and into advanced threats that target their business data and infrastructure.
Through enhanced visibility, eTrepid increases your cyber threat intelligence to give you clarity on today's threats, the bad actors, and ongoing exploits. Take a proactive step in defense against these threats with an appropriate response.