
Account takeover: criminal hackers during the Coronavirus pandemic
Tecninf news archive.
A consumer cyber-defence protocol against attacks that exploited the Covid-19 emergency.
During the Covid-19 pandemic, disinformation travelled through the web, social networks and messaging apps. By observing email, telephone and Internet communication flows, Tecninf detected intense activity by criminal hacker groups known to thrive in times of crisis.
What made the emergency different from previous events was its immediate effect on the cybercrime economy: attackers left no opportunity unexplored. The most widespread attempts included account takeover, phishing, vishing and smishing.
Account takeover
In an account takeover, criminals exploit credentials stolen in earlier data breaches to gain control of online banking, e-commerce and gaming accounts. During school closures, scammers also targeted younger users, seeking access to gaming accounts often linked to their parents' credit cards.
- Warn children and teenagers that deceptive grooming messages may target them.
- Never disclose credentials or payment details in response to unsolicited messages.
- Report suspicious messages to the relevant cybercrime authority and service provider.
Vishing and reverse vishing
In a vishing attack, a victim receives a VoIP call from someone who appears to represent a bank or another organisation. Reverse vishing uses email, online adverts or social posts to persuade victims to call a number controlled by the scammer. During the emergency, messages frequently exploited the financial difficulties caused by Covid-19.
Users should consult the official websites of the organisations involved, ask for the identity of callers and verify contact details independently. Where appropriate, the incident should be reported to law enforcement.
Smishing
Smishing is phishing delivered by SMS. Scammers use messages promising payments, rewards or assistance and request account information to complete the supposed claim. Users should verify the official websites mentioned without following links contained in the message.
