Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business Mail Email Security Education: Cybercriminals Capitalizing on Coronavirus and Work from Home Measures 
Mail

Email Security Education: Cybercriminals Capitalizing on Coronavirus and Work from Home Measures 

By Mia Thompson
27 April, 2020

Please note: The identity of the hacked accounts in the examples below have been changed or hidden for privacy reasons.

For most of your customers, it’s probably safe to say life looks a lot different now than it did a few short months ago. If they’ve continued operations, their employees are likely working from home—and those employees are adjusting to this new reality and the stresses it brings. If they have children, they’re trying to work and home school at the same time. In the midst of it all, cybercriminals are increasingly trying to take advantage of weak points in your customers’ defenses. 

Under these new conditions, users may not have the same security mindset they did when working under more normal conditions. If users let their guards down a well-timed email might be all it takes for one of your customers to fall victim to a scam. 

CTA Image

SolarWinds Mail Assure

Advanced Threat Protection for Inbound and Outbound Email.

Try It Free Learn More

 SolarWinds® Mail Assure has observed a significant uptick in new phishing campaigns since the coronavirus outbreak, with these now accounting for over an 80% increase in phishing attacks.i 

There are numerous phishing campaigns circulating on health and safety measures that appear to be from medical professionals, health organizations, and governments. With a major increase in the use of online platforms, tools, and video conferencing apps, these campaigns are not only crafted around the coronavirus topic itself, they’re also targeting people using online tools to communicate and maintain business continuity. 

Education and communication are key to help ensure customers and employees are aware of security challenges during this time. Today, we’re going to look at some popular phishing attacks that are making the rounds—and what to look for to prevent your company and customers from falling victim.

The example below shows the header information of a phishing campaign where the hackers disguised themselves as the World Health Organization trying to get users to donate via Bitcoin. 

If you look at the sender, it seems to be the World Health Organization—but if you take a closer look, there are obvious indicators it’s not from the World Health Organization. First, the subject line of the email, “COVID-19 Solidarity Response Fund for WHO - DONATE NOW,” creates an unreal sense of urgency. Second, the display name is spoofed. Finally, the “From” address ends in “@example.com” and the IP address is [1.2.3.4]. These clearly have nothing to do with the World Health Organization.

 

Received: from [1.2.3.4] (helo=example.com)by XXXXX.XXXXXX.XXX with esmtps

 (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92)

 (envelope-from <[email protected]>) id 1jGoHM-0003JI-MJ

 for [email protected]; Tue, 24 Mar 2020 19:27:58 +0100

From: "World Health Organization" <[email protected]>

To: <[email protected]>

Subject: COVID-19 Solidarity Response Fund for WHO - DONATE NOW

Message-ID: <[email protected]>

Date: Tue, 24 Mar 2020 19:27:52 +0100

 

 

​

 

In the next example, the hackers masquerade as a pharmacy. Again, if you look at the “From” address, you’ll see the domain name isn’t associated with a legitimate sender. The email leads users to believe they’re clicking on a link that will take them to the pharmacy’s website. However, hovering over the link shows it’s not a secure URL and will take users to the phisher’s landing page instead. 

In our final example, the hackers use the urgency of maintaining business continuity to get users to purchase a Wi-Fi booster. Again, the domain in the “From” field is spoofed and the link is unsecured. Clicking on the link will take users to a landing page that may look like a legitimate site. As users enter their personal data—like their credit card information—bad actors gain access to their personal data, enabling them to inflict more damage. 

 

Some of the recent top phishing subjects include:ii 

  • Avoid contamination and take a fast accurate temperture without
  • Stay Safe and take a temperture
  • USA: Anti-Virus & Flu Face Mask Flying Off Shelves
  • Don’t Go To Public Places Without This Face Mask
  • High Quality Face Mask Everyone in The USA is Talking About
  • Can Wearing a Face Mask Protect You From Catching a Virus?

A few tips for users to help verify the legitimacy of emails:  

  • Always check the domain name in the email “From” field. Is it coming from the organization or recipient it says?
  • When hovering over links in emails, verify it directs to secured URLs (“https”—not “http”). Jumbled text in the links is an indication of an unsecure link. 
  • Review the content. Is it creating a sense of urgency for you to act? Are there spelling mistakes or incorrect grammar like in the examples above?
  • Finally, look out for malicious email attachments. Check the file first by saving it to your downloads folder. If you’re using Windows, set your folder options to “show known file types” so you can view the file extension (e.g. the three letters at the end of the file name). Unzip the .zip file from your downloads and view the file extension. If it contains any of the following: .JS, .EXE, .COM, .PIF, .SCR, .HTA, .vbs, .wsf, .jse, or .jar at the end of the file name it’s malicious. You should not click on it or try to open it.  

True protection comes with practicing a combination of strong security programs and awareness. Maintaining a culture of security and educating users on the different types of attacks and their damaging consequences should be a key part of your overall security strategy. 

 

Mia Thompson is product marketing manager, Mail Assure at SolarWinds MSP.

 

Sources:

i SolarWinds Mail Assure logging data report (Published March 2020) 

ii SolarWinds Mail Assure Top Phishing Subjects Report (Published March 2020) (Spelling and grammar mistakes were intentionally left incorrect to reflect original phishing email subject lines)

 

Additional reading

Keep Your Customers Safe on Office 365 
Email Security Education: Top Two Trends 
How to Protect Your Company from Spear Phishing in 2020
You might also like...
Mail

How Email Archiving Can Help Move You Toward SOX Compliance

Mail

How a Secure Email Gateway (SEG) Can Protect Your Business

Mail

How to Effectively Use an Email Spam Filter Service

Mail

6 Cybersecurity Tips for Business Email

Mail

Partnering for Growth: Strong Defenses, Solid MSP Partnerships

Mail

What Is DMARC Email Security and How Do You Implement It?

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
  • TAP Blog Series: Maximizing Your Service Delivery Opportunity
  • Why Do MSPs Choose SolarWinds Backup? IT Central Station Finds Out
  • Seven Features Remote Assistance Software Should Have
  • TAP Blog Series: Creating Your Automation Strategy—Three Key Components You Must Have in Place
Categories:
  • Security (229)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (82)
  • Business Growth (75)
  • The Head Nerds (74)
  • IT Support (41)
  • Business (39)
  • Cybersecurity (37)
  • Automation (36)
  • Operations (33)
  • Mail (33)
  • Remote Management (27)
  • ITSM (25)
  • Data (21)
  • Cloud Computing (21)
  • Networking (21)
  • Marketing (14)
  • Product (11)
  • PSA (10)
  • Services & Support (4)
  • Mobile (4)
  • Risk Intelligence (4)
  • Service Desk (4)
  • Internet of Things (3)
  • Customer Service (3)
  • GDPR (2)
  • Research & Trends (2)
  • Training (2)
  • Business Risk (1)
  • LOGICcards (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.