Popular Types Of Phishing Emails

In early 2020,  cloud security expert, Wandera, revealed in its Mobile Threat Landscape Report that a new phishing campaig is launched every 20 seconds. That means three additional phishing sites designed to target users in every minute. 

However, this number no longer applies during COVID-19 times. Phishing has seen a rapid increase starting from when the pandemic went global during the first quarter of 2020. According to security firm Barracuda Networks, there was a 667% spike in email phishing attacks in March 2020 due to coronavirus fears. This new data reveals how cybercriminals are taking advantage of the people’s concerns due to the pandemic. 

This increase in phishing scams is not unique to corona-related attacks alone. There has also been an increase in invoice scams and credential theft as the whole world switches to work-from-home arrangements. 

The best way to guard against phishing scams is early detection. Being able to determine a phishing email from a legitimate email helps a lot in preventing the nasty consequences of phishing campaigns, including data theft, malware infection, money theft, and others. Protecting your privacy by using a VPN also minimizes your chance of being targeted by phishing attacks. 

To understand more about the enemy, we’ve gathered the latest and most widely-used phishing tactics in 2020. We’ve listed their characteristics and how to recognize each of them. 

Scam #1: Corona-related phishing attacks

As mentioned above, the most popular phishing strategy right now piggybacks on the public’s fear of the coronavirus. In March alone, Barracuda has detected 9,116 COVID-19-related attacks, which represents 2% of the total 467,825 spear-phishing email attacks detected for that month alone. 

There are three main types of attacks that use the coronavirus as the hook: scamming, brand impersonation, and business email compromise. Some of the scams you need to watch out for include fake corona cures, face masks, donation requests for companies that claim to be developing vaccines, and fake charities. Some scams even claim to be from the World Health Organization, asking for donations through Bitcoin. 

Aside from scams, attackers also deploy malware through phishing emails. Some of the well-known malware related to COVID-19 are Emotet, a popular banking Trojan, the Ursnif banking Trojan, the Fareit information stealer, the COVID-19 ransomware, Azorult, NetWalker, Nanocore RAT, and the Hancitor trojan.

Scam #2: Invoice phishing scams

With so many people forced to work at home because of the pandemic, most of the business transactions are done online, including financial processes such as payroll and invoicing. As a result, attackers who specialize in invoice phishing scams have more victims to target. This type of phishing involves sending a payment reminder to a vendor, brand, and even individuals, letting the receiver know that an important invoice is attached. Clicking the invoice could either redirect the user to a phishing website where he or she is directed to pay the invoice or a malware/ransomware could be downloaded to the victim’s computer. 

Scam #3: Update payment alerts

Aside from invoice phishing, update payment alerts are also common nowadays. No one would want to suffer from a service outage, especially during this crisis. This is what makes update payment scams so effective. Imagine getting an email about your internet company terminating your connection if you’re not updated with your payments or receiving an email from Netflix temporarily restricting your account until your balance has been paid off. In the time of the COVID-19 pandemic, nothing could be scarier than having no internet or Netflix. 

And hackers are feeding on the people’s dependence on these services to gain money. They usually send an email stating that there is a problem with your credit card or there is an issue with your payment, asking you to log in and update your payment details. Some attackers go as far as hacking the company and identify the employee responsible for managing accounts like these. 

Scam #4: Security Alerts

This type of phishing scam never gets olds. In fact, it is a daily occurrence. But getting security alerts from banks, email providers, and cloud services companies can be troubling, especially since the emails are becoming more sophisticated in their imitation of legitimate companies. These phishing emails actually look very real and something that users have seen before. Common security alerts include expiring password warnings, suspicious activity detected, suspicious logins, and others. When the user clicks the link, the victims are actually compromising their privacy instead of protecting it.

How to Protect Against Phishing Scams

Your first defense against scams like these is to be aware that they exist. By being aware, you’ll be more vigilant when you open your emails. Here are some ways to determine the authenticity of the emails you receive:

  • Check the sender’s email. Compare the email address with the previous emails you received from that business or company. If the domain extension is different, then that’s probably a scam. 
  • Use a reliable VPN to help you stay anonymous online. This will minimize the personal information that hackers can collect from you that can be used for phishing. Check out VPN review sites, such as VPN Watch, where you can find a top security solution for your needs.
  • Don’t click on links or attachments without verifying the authenticity of the email. If you have other contact details of the sender, confirm with him or her about the email you received. 
  • Check the grammar. Professional emails from businesses and companies undergo proofreading to make sure that it looks and sounds professional. If it sounds like it was churned out by a translating machine, then be suspicious. 
  • Do not log into your account by clicking on the link. Open a separate browser and visit your account from there to verify if there have been any changes. 

And what do you do if you get a phishing email? Delete them. 

By April Reyes 

You Might Also Read: 

All Employees Need This Effective New Training Tool:

 

 

« Five Ways Automation Can Help Fix The Cybersecurity Skills Shortage
Attacks On Anti-Racism Sites Surge »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

DoD Cyber Crime Center (DC3)

DoD Cyber Crime Center (DC3)

DC3 is a US Department of Defense (DoD) center of excellence for Digital and Multimedia forensics.

QNAP Systems

QNAP Systems

QNAP Systems, Inc. delivers world class network attached storage (NAS) and network video recorder (NVR) solutions.

Gigasoft

Gigasoft

Gigasoft provide secure online data backup & cloud backup services for the education sector and businesses.

Allgress

Allgress

Allgress solutions converge disparate risk silos across enterprise networks and automate governance, risk and compliance management processes.

Bundesdruckerei

Bundesdruckerei

Bundesdruckerei specializes in secure identity technologies and services for protecting sensitive data, communications and infrastructures.

SERMA Safety & Security (S3)

SERMA Safety & Security (S3)

SERMA Safety & Security provides a comprehensive cybersecurity offering incorporating Expertise, Evaluation, Consultancy and Training, covering hardware, software and information systems.

GreyCortex

GreyCortex

GreyCortex uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

YL Ventures

YL Ventures

YL Ventures funds and supports brilliant Israeli tech entrepreneurs from seed to lead.

Thridwayv

Thridwayv

Thirdwayv helps your enterprise realize the full potential of loT connectivity. All while neutralizing security threats that can run ruin the customer experience - and your reputation.

PQShield

PQShield

PQShield are specialists in Post-Quantum Cryptography. We provide quantum-secure cryptographic solutions for software, software/hardware co-design and data in transit.

cleverDome

cleverDome

cleverDome has created the first community built and proven model that redefines the standards for protecting the most confidential data and information of consumers in the cloud.

1Kosmos

1Kosmos

1Kosmos provide Digital Identity and Passwordless Authentication for workforce and customers. Powered by advanced biometrics and blockchain technology.

World Cyber Security Summit

World Cyber Security Summit

World Cyber Security Summit, by Trescon, is a thought-leadership driven platform for CISOs who are looking to explore new-age threats and the technologies/strategies that can help mitigate them.

International College For Security Studies (ICSS)

International College For Security Studies (ICSS)

ICSS India offers technical education to students, clients and partners in IT Industry by our well qualified, certified and experienced trainers.

Clarabot Nano

Clarabot Nano

Nano is the secure file sharing tool to improve content search, data access and collaboration between multiple parties.

Acumenis

Acumenis

At Acumenis, we help organisations of all sizes to manage information security effectively. Our key services are penetration testing, ISO 27001 implementations, and security