Cyber hackers are an opportune group of people, hunting like predators and shifting their approach as needed. And now, they’re leveraging the concern and — in some cases — hysteria about the coronavirus outbreak to advance their nefarious objectives.
According to multiple cybersecurity experts, hackers are playing on the public’s fear of the coronavirus to steal passwords and spread malware, reports Vice. Using simple phishing techniques, bad actors are targeting individuals with emails that appear to come from an official source, such as the Centers for Disease Control (CDC). The emails purport to share helpful information about the virus and encourage readers to open an attachment which then downloads malware — in this case, the increasingly popular Emotet strain — to infect their computer and gather personal information.
Could healthcare organizations be the next target?
While current reports indicate that only private citizens have been targeted so far, it’s not unreasonable to assume that cyber criminals may soon have businesses and other organizations in their sights.
The healthcare sector, for instance, is particularly at risk. Healthcare workers or administrative staff are low hanging fruit for today’s opportunistic hackers. As they seek answers to important questions in a time of crisis, these employees may be susceptible to a hoax email that appears to come from a trusted government body such as the CDC.
This is hugely problematic for healthcare companies who are already struggling to reduce cybersecurity risk.
Indeed, hospitals, doctors’ networks, insurance companies, and others are prime targets for hackers due to the valuable protected health information (PHI) these organizations store and the vital role they play in our nation’s critical infrastructure. This risk is intensified by the fact that the systems and networks of companies in this sector are highly vulnerable to attack or are already compromised. Indeed, our own study shows that only 50% of healthcare companies have adequate security postures — the other 50% are at a high risk of a breach.
How to mitigate the risk of opportunistic cyber attacks
There are several steps that organizations, in any sector, can take to reduce the risk associated with opportunistic cyber threats such as the one tied to the coronavirus.