How to Combat Coronavirus Phishing Scams

Table of Contents

[fusion_builder_container type=”flex” hundred_percent=”no” equal_height_columns=”no” menu_anchor=”” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” class=”” id=”” background_color=”” background_image=”” background_position=”center center” background_repeat=”no-repeat” fade=”no” background_parallax=”none” parallax_speed=”0.3″ video_mp4=”” video_webm=”” video_ogv=”” video_url=”” video_aspect_ratio=”16:9″ video_loop=”yes” video_mute=”yes” overlay_color=”” video_preview_image=”” border_color=”” border_style=”solid” padding_top=”” padding_bottom=”” padding_left=”” padding_right=””][fusion_builder_row][fusion_builder_column type=”1_1″ layout=”1_1″ background_position=”left top” background_color=”” border_color=”” border_style=”solid” border_position=”all” spacing=”yes” background_image=”” background_repeat=”no-repeat” padding_top=”” padding_right=”” padding_bottom=”” padding_left=”” margin_top=”0px” margin_bottom=”0px” class=”” id=”” animation_type=”” animation_speed=”0.3″ animation_direction=”left” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” center_content=”no” last=”true” min_height=”” hover_type=”none” link=”” border_sizes_top=”” border_sizes_bottom=”” border_sizes_left=”” border_sizes_right=”” first=”true”][fusion_text columns=”” column_min_width=”” column_spacing=”” rule_style=”default” rule_size=”” rule_color=”” content_alignment_medium=”” content_alignment_small=”” content_alignment=”” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” sticky_display=”normal,sticky” class=”” id=”” margin_top=”” margin_right=”” margin_bottom=”” margin_left=”” font_size=”” fusion_font_family_text_font=”” fusion_font_variant_text_font=”” line_height=”” letter_spacing=”” text_transform=”none” text_color=”” animation_type=”” animation_direction=”left” animation_speed=”0.3″ animation_offset=””]Coronavirus (COVID-19) is beginning to cause increased disruption for people and businesses across the UK. However, misinformation continues to spread just as quickly as the virus itself, generating fear and irrational behaviour.

Naturally, this state of panic is where cyber criminals thrive.

Always eager to find new and innovative ways of stealing personal information, cyber criminals are now taking advantage of the Coronavirus panic.

In fact, on the internet, you even need to be wary of coronavirus-related malware. Around 4000 coronavirus-related website domains have been registered since January, and it’s approximated that they’re 50% more likely to contain malware payloads.In response to this, the NHS has unveiled its approach to tackling the so-called Coronavirus ‘fake news’ pandemic online.

At Neuways, we’ve witnessed a range of phishing scam attempts, with one even attempting to impersonate World Health Organisation (WHO) officials.

This is just one example of many, but it follows a common trend. Hackers are claiming to offer ‘advice’ on the prevention of infection, typically spoofing authoritative bodies such as the CDC, WHO, or UK Government.

Spotting a Coronavirus Phishing Scam

Whilst phishing attempts are getting more sophisticated, you will be able spot a coronavirus phishing scam if you’re vigilant.

They’re actually very similar to regular phishing, insofar as emails will be riddled with spelling mistakes, poorly formatted, and be worded in a vague manner.WHO Coronavirus Phishing Scam

For example, let’s take a look at the World Health Organisation phishing scam (right) that is currently in circulation.

Titled ‘SAFTY CORONA VIRUS AWARENESS WHO’ – a pretty strong indicator of a phishing email – it begins ‘Dear Sir’… but ‘Sir’ could be anybody.

This lack of personalisation indicates a spam email pushed out to as many people as possible.

The first paragraph simply begins with a command – ‘Go through the attached document’. No background information, no recognition of a previous correspondence, and no real context for the email. It’s brief because the hacker just wants you to click.

If you’ve read carefully, you’ll also notice the spelling error ‘corona virus’ (as opposed to coronavirus).Spelling errors, again, indicate a hastily assembled email designed to be pushed out to as many potential victims as possible. You can read more about this on our Phishing Awareness page.
Spelling errors, again, indicate a hastily assembled email designed to be pushed out to as many potential victims as possible. You can read more about this on our Phishing Awareness page.

This call to action is repeated in the following paragraph, asking the recipient ‘Click on the button below to download,’ with a big blue button entitled ‘Safety measures’. The cyber criminal really wants you to open the attachment!

The email is rounded out with a series of spelling and grammar errors, reading ‘Symptoms common symptoms include fever, cough
shortness of breath and breathing difficulties’. If it was not apparent to you that this is a phishing email, it should be obvious by now.

And then the email just ends. That’s it.

A couple of direct commands and semi-literate prose. But unfortunately, 1/10 people do fall for these types of scams.

Preventing a Coronavirus Phishing Scam

At first glance, the email may have appeared legitimate. After all, it does have the official logo. But logos can be imitated. Therefore you need to look beyond the surface information of an email.

Ultimately, this is the reason you need to be extra careful. The biggest enabler of any type of coronavirus phishing scam is human nature. We’re all quite curious, so if an email comes in offering ‘safety measures’ or so-called facts and stats, people are naturally inclined to click.

It’s essential that you inform your staff to not do this in any circumstances.In the heightened state of panic, it’s also important to remember that this type of phishing scam is no more dangerous than any other type – a phishing scam only works if you, the potential victim, interact with the email.

So, if you’re ever in doubt, take a minute and read carefully before you click – even if the email is from a trusted contact. If you’re unsure whether it’s a legitimate email, give the sender a quick call to verify the correspondence.

Guarding Against Misinformation

In addition to opportunistic phishing scams, misinformation (or ‘fake news’) about coronavirus is being circulated online at an astonishing rate. Follow these tips to remain informed and free of bogus information.

Whether it’s claims that the beer brand Corona had seen drops in demand because of associations with the virus, or ‘proof’ that author Dean Koontz predicted the Coronavirus outbreak in one of his books, there are plenty of false claims in both the traditional and social media channels.

You may have also seen Apps claiming to offer ‘facts’ on the illness, or even statistics of the growing pandemic. Beware of these 3rd party Apps – very few of them have been verified by healthcare professionals. Both Google and Apple are reviewing Apps relating to coronavirus on their respective Google Play and App Store storefronts, in order to stem the tide of misinformation.

The only places you should be getting your information from is the 111 telephone service, the NHS’s Coronavirus (COVID-19) advisory page and, for the latest travelling information, the Foreign Office’s website.

Fake Coronavirus ‘Case Maps’

Cyber criminals are also weaponising people’s interest in the number of cases by producing fake COVID-19 case maps. Highly interactive, people are opening them only to be hit by a Trojan Horse.

This specific Trojan targets bank accounts specifically.

Please do not use these websites. Public Health England produced a UK-based case map, which you can access here. This is safe, informative, and will prevent you from taking any risks online.

WiseCleaner ‘CoronaVirus’ Ransomware

Another scam to look out for is a particularly nasty ransomware package, disguised as ‘WiseCleaner’ – a genuine Windows system software product.

Aptly titled ‘CoronaVirus,’ this ransomware injection is distributed via an infected website that claims to be advertising WiseCleaner. Clicking anywhere on this site will result in your device becoming infected with the Khalesi or Kpot trojan virus.

This ransomware is designed to steal a variety of sensitive data from your device, including data from your web browser, email, instant messengers, VPN, cryptocurrency, RDP, FTP, gaming software, and account information.

We recently put together a Pandemic Preparedness Plan for business continuity purposes. If you have any questions about this, or your own, please get in touch on 01283 753 333 or hello@neuways.com.

[/fusion_text][/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]

Want to keep up with our blog?

Get our most valuable tips right inside your inbox every Friday!

Latest IT News & Insights
VPN
SonicWall VPNs under attack: What businesses need to know  
Cybercriminals are always adapting, and the latest surge in activity from the Akira ransomware group...
Read More
Ransomware on the rise
Ransomware on the rise: Meet Akira & Lynx 
Ransomware continues to be one of the most disruptive cyber threats facing businesses today. As defences...
Read More
What is Ransomware
Ransomware: What is it and how to stay protected 
You’ve probably seen the term “ransomware” pop up in the news more often over the past few years, and...
Read More
ring-doorbell
What to know about the supposed Ring doorbell security breach in May 2025
In July 2025, Ring users across social media platforms raised alarm bells after spotting what appeared...
Read More
Heading-12
Windows 10 support ends in 2025: What your business needs to know
Microsoft has officially announced that support for Windows 10 will end on 14th October 2025. If your...
Read More
browser
The hidden danger of browser extensions: Are your staff putting your business at risk?
Browser extensions represent a serious business risk Browser extensions are often seen as harmless add-ons,...
Read More
Legacy systems
Legacy systems: The silent security liability
When thinking about cyber security, it’s easy to focus on the latest threats: phishing, ransomware, or...
Read More
Captchas
CAPTCHAs: A security tool that can be used against you
We’re all used to CAPTCHAs, those little tests that make you pick out traffic lights or type in squiggly...
Read More
Neuways logo

Frequently Asked Questions

As a leading IT and technology provider, we offer three core services, all of which have additional add-ons. We offer Managed IT Support, Business Central implementation and consultation, as well as Managed Cyber Security. Call us on 01283 753333 if you are interested in any of our services.

Contact us

Support: 01283 753300

Business Development: 01283 753333

Purchasing: 01283 753322

Admin and Accounts: 01283 753311

Email: hello@neuways.com

Managed IT support is a comprehensive solution where an expert IT provider, like Neuways, handles your technology infrastructure. This includes proactive monitoring, maintenance, cyber security, and support.

Yes we do. Your business needs Cyber Security due to the increasing number of cyber threats that are affecting businesses in all industries. If your business has data and technology systems implemented, you will need Managed Cyber Security.

We can help you conduct Cyber Audits to assess whether your business would gain Cyber Essentials and Cyber Essentials Plus Certification. Our dedicated departments work with your team to assess how much work is required before you gain Cyber Essentials Plus certification. We will then provide advice and consultation on what aspects you need to change within your business before providing a quote on how we can assist your company become Cybersafe.

Yes we can. We have our own dedicated Microsoft Dynamics 365 Business Central teams who work to ensure that we can implement the right systems and solutions into your website that are absolute right for you. Our experienced business consultants have worked all over the world for organisations operating on a global scale. 

Exclaimer Pro is a dynamic email signature that helps clients to switch and change around email signatures so that clients are able to advertise different offers and brands to a variety of email recipients. Administrators can also manage user emails internally, meaning the user does not have to touch their own email signature.

We offer Managed Security Training to help employees spot email phishing attacks, spear phishing attacks and vishing attacks. We also help train clients on how to use the various pieces of software we provide to clients, like Exclaimer Pro, Business Central and Cybersafe software.

We are a Managed IT Support provider based in Derby, East Midlands. However, we cover so many areas including the whole of the UK, Europe, and America. We are always willing to travel and send our expert technicians to ensure you have the best experience. 

Got a question?

Reach out
& Connect

Name