As so many of us are now experiencing, the spread of COVID19 is very real and our daily lives are being disrupted on an unprecedented level. Social distancing has become a key weapon in the fight against the disease and this has necessitated many people to work from home.
Here are some thoughts on ways that staff and employers can maintain their cyber security integrity.
Know the risks!
Attackers are exploiting the opportunity to hit digital infrastructures and so it is essential that both staff and employers know the risks and safely share relevant and verified advice to try to prevent data breaches, malware and ransomware. Phishing emails and scams have risen dramatically since the outbreak, with hackers targeting vulnerable companies and employees, fraudulently offering support for businesses in difficulty and employees who have lost their jobs.
- If you receive an email that asks you to verify or renew your personal online credentials when you haven’t asked for this assistance, then DO NOT ACT.
- If you receive emails from people you don’t know, then be suspicious. Do not click any links that they may include in their emails, regardless of how compelling their message might be. Phishing scams typically ask the recipient to ‘urgently respond’
- If a business or individual that you know sends you requests to do things that they wouldn’t normally do, then make sure you think twice.
- Always double check the detail of the email – who is it from, does their email address make sense, is the language being used make sense… it’s good to be cautious!
Here’s some examples of scams that are going on right now.
(Thanks to Lauri Tankler for compiling details of these scams)
Fake emails pretending to be from the World Health Organisation, this is a trend widely observed by many countries.
An e-mail originating from an actor disguised as the World Health Organisation, evidently with a bogus e-mail address. To go even further, would the WHO truly call coronavirus the “wuhan-virus”? Nevertheless, clicking on the “Safety measures” would direct to a fake WHO website, which requires entering personal data.

Fake Working from Home help
A number of Estonians have also received phone calls from foreign numbers (in English language), with offers for VPN solutions. The actual aim of those calls have been compromising the computers of the targeted persons, using the method of scareware.

Health Board fake email scam
A malware campaign was launched a few days after the National Health Board sent out a rare e-mail through the state portal ([email protected]) e-mail server, notifying about the general provisions regarding the COVID-19 outbreak. The letter below tried to replicate the original e-mail, however originating from the e-mail of a pharmacy and containing major orthographical mistakes already in the title. The letter invites reading the more concrete measures, supposedly in the attached file and which in fact contained malware, designed to steal user passwords and financial information.

Suggestions for companies
- It’s essential that companies ensure that the devices and software that staff are using at home are secure and it is vital that companies use a VPN that is robust and if you have a number of employees, can sustain all of them at one time.
- If you can provide your staff with laptops, this is preferable to Bring Your Own Device (BYOD), as it’s easier to ensure that the systems being used are secure. If staff need to use their own device, the company will need to check that it has an appropriate amount of security and will not compromise your company’s systems.
- Make sure that all corporate business applications, such as finance and project management applications are accessed through secure, encrypted communications channels such as Https and VPN, using Two Factor Authentication.
- If you’re communicating via video conferencing with staff and clients, make sure that the applications you’re using are secure and up to date. Don’t share the meeting ID to anyone that you don’t want to see it.
- Policies are essential – set clear parameters for staff on how they should use company devices and software, share the policy with staff and ask them to confirm that they understand the policy implications.
- Support staff with technical expertise where available, this will help them to rectify issues quickly and with as little disruption as possible.
Suggestions for staff
- Where possible, make sure your company provides a secure device, but where they can’t, make sure that your device is secure and that you’re using appropriate software to conduct your work.
- If you have to use Public Wifi – make sure you log in using VPN.
- Make sure you have antivirus software installed and update it when asked by a verified source.
- Be really careful about emails that reference the COVID19 pandemic. If you receive one, don’t click on any links and if you have a company security officer, report it to them.
- If you have any local drives, you need to ensure that they are encrypted.
- When you’re participating in a video conference, resist the temptation to share pictures on Social Media, you might give away the meeting ID as well as disclosing important, private company information.
Working from home can be a great opportunity to build resilient and robust teams; it builds trust and is supporting the global effort to combat COVID19.
Be aware of the scams that are emerging, be secure and be suspicious! If it looks too good to be true, when it comes to cyber security it nearly always is.




