Hacker doesn’t sleep, hacker takes advantage of opportunities. A calendar year provides at least 365 opportunities for an online fraudster to attack. The cybercriminal will take advantage of the upcoming holidays, vacations, holidays and seasonal sales. He will do it because he knows that we are accompanied by absent-mindedness, inattention, lack of concentration, and he puts us in the right context of our thoughts and actions. Even seemingly simple manipulation tricks end with the hacker winning.
Types of phishing
When shopping online, it is easy to fall into the trap of cyber fraudsters, especially when we see new “promotions” all the time. Before holidays and during sales periods, we observe an increased number of emails informing about special offers, discounts, order confirmations, shipping, price reductions, shipping surcharges, and bank notifications. Some of them are phishing, which contains links to fake login pages to banks and stores, some messages have malware attachments or links to download infected files. Victims of hackers are not only private individuals, but also company employees who sometimes check their private email on work devices or phishing with social engineering regarding the private sphere is deliberately delivered to a business email.
So what should you do to avoid falling victim to cybercriminals? What to pay attention to? First of all, it is worth knowing the methods and goals of hacker attacks, the types of phishing messages they send, and being familiar with the social engineering traps used by criminals.
How to recognize phishing? Learn 8 tips that will help you with this!
Order confirmation
During the Christmas period, cyber fraudsters send email messages with false order confirmation. At first glance, they look like they come from well-known sellers and a quick click (without paying attention to the actual sender’s address and the address of the target website) will redirect you to the fake login form. This allows an internet fraudster can steal your login details, which can then be used, for example, to steal your identity or, depending on the scenario, attack phishing, to obtain credit card details.
Why does it work? The hacker uses sophisticated social engineering methods – it is based on emotions, causing surprise, anger and curiosity. Someone who didn’t order at all will click to explain the situation or glance to remember what they bought.
Shipment tracking
More online shopping that we do before the holidays means more opportunities for hackers to impersonate well-known companies and send links to websites where you can track your parcel, attachments with the status of the parcel, text messages about the need to pay a small amount for the parcel. If the manipulation is successful and, for example, you download the file, it is very likely that you willinfect your device’s system with malware (ransomware, spyware) or instead of paying an additional 1.67, you will confirm the payment to 4231.67.
You can read more about ransomware in the article “What is ransomware and why it should not be downplayed?”
Dangerous e-cards
Be careful when an e-card arrives in your email box. It does not necessarily have to be a manifestation of sympathy and memory. In fact, it can turn out to be an unpleasant and expensive experience. Before opening the message, make sure that the sender’s details are visible and identical to those of the person you know. If it is necessary to enter detailed personal data to unlock access to the content, it is almost certain that it is a phishing attack.
Charity fraud
We have been involved in charity events for a long time – many people ask for our help. This phenomenon increases even more in the periods before Christmas or Easter, when charity collections are conducted for excluded social groups. Unfortunately, hackers profit from this and exploit our good hearts without blinking an eye, impersonating aid organizations and desperate parents trying to save the lives of their beloved children. In this way, they extort money from us for transfers, donations, credit card details or bank logins. The case also applies to companies that are asked for support.
Therefore, if you want to make a donation, please check the case carefully or act through official, verified aid organizations and associations. Do not click on links sent by email, even if the message includes photos of people in need and the story described looks very credible.
Sales and promotions
When a message about a “mega deal” or “holiday sale” arrives in your email box, it’s hard to resist checking the offer, right? Unfortunately, these are often phishing messages that will redirect you to a fake website, or at best it will be clickbait. Don’t click on links. Check the promotions on the official website of a given store and enter the address yourself.
How to protect employees against phishing?
Companies are particularly vulnerable to the phishing attacks discussed above. Each period brings many cybersecurity challenges as hackers use any excuse to attack a company, and the most common tool they choose is phishing. What determines whether the attack will be successful?
Somewhat stubborn and determined by hackers, but many attacks can be repelled by well-prepared and attentive employees. Practical defense training, education and awareness of cyber threats can prepare your employees to resist most attacks. We encourage you to use a proven tool – Practical Anti-Phishing Training.

