12/17/2021
Scammers exploit Omicron fears
Fraudsters take advantage of the emergence of the new variant to dupe unsuspecting victims out of their sensitive data
Sensing another opportunity to take advantage of fears surrounding the COVID-19 pandemic, scammers are deploying a phishing campaign where they attempt to exploit the emergence of the Omicron coronavirus variant to line their pockets.
The fraudsters pose as a national health service and offer potential victims a chance to get a “Free Omicron PCR test” that will help them avoid pandemic-related restrictions. The email also deceptively claims that the new variant isn’t detectable by test kits used for previous COVID-19 variants, and a new test kit has been developed for that purpose.
Multiple versions of the email are doing the rounds, with one containing a link, while in another, the link is accessed by a button. In either scenario, you would be redirected to a faux copycat website that requires you to fill out a form requesting your full name, date of birth, address, mobile, and email address – basically all the information a scammer would need to pull off a pretty convincing case of identity theft and fraud, leaving the victim’s finances in shambles.
Oddly enough, while it does advertise the test as free, the website requests a delivery fee of $1.64. And for good measure, it gives you the option to provide your mother’s maiden name as a security question – an approach still used to help users secure their online accounts. If victims do get duped and fill out the form, they have effectively provided the scammers with a blueprint to committing identity theft and fraud.
Scammers eagerly switch to the topic du jour in a quest for people’s sensitive data and hard-earned money, so the fact that they’re taking advantage of the latest developments in the COVID-19 crisis is no surprise.
To avoid falling victim to similar scams, consider following these steps:
• If you received an email that claims to be from an official organization, check the organization’s website and contact them using their official contact information to confirm whether they sent that message.
• Don’t click on links or download files you received in an unsolicited email from a source you don’t know and cannot independently verify.
• Use two-factor authentication (2FA) at least on your most important online accounts, as well as reputable multi-layered security software with anti-phishing protection.