Free Phishing Test
CYBER THREATS

The Cybercriminals’ Christmas Harvest

14-dec-2022 6 minutes read

The weeks before Christmas are exceptionally busy for many companies. Reporting, month- and year-end closing, stocktaking, holiday planning and budgeting are just some of the demands competing for attention.

Fake emails

A large part of everyday work and communication takes place over email and cloud applications. They save time and make collaboration easier, but they also create more opportunities for cyberattacks.

Cybercriminals know that December is a “hot” period for businesses. They send messages to employees’ inboxes designed to prompt a click, an attachment opening or the disclosure of data. If the message fits the context of the recipient’s work, the company may quickly find itself in serious trouble.

How to avoid falling into a cybercriminal’s trap

  • Check the sender’s address carefully. If you are unsure whether a message really came from a colleague, call them using a trusted number and verify it.
  • Treat external-sender warnings seriously. They indicate that the message came from outside your corporate domain and should be handled with extra caution.
  • Inspect the signature and formatting. Is the footer current, and does it match the one normally used by the sender?
  • Think before you click. Even an urgent message with a plausible attachment may be a trick. An attacker may know your company’s general business calendar—or specific internal processes.

How to recognize phishing?
8 tips for your team!

Christmas brings increased shopping and a rush to get everything done. As more people buy gifts online, busy stores also create more opportunities for cybercriminals seeking data, passwords and money.

Problems with parcel delivery

December is an exceptionally busy period for couriers. Customers often lose track of how many items they have ordered, and cybercriminals exploit that distraction and the holiday shopping rush.

A parcel locker may be full, or a parcel expected on Monday may arrive on Wednesday. That uncertainty makes it easier for scammers to send thousands of messages claiming that a recipient must take action before a parcel can be delivered.

Two common parcel-delivery scams

In the first, the attacker impersonates an unspecified courier and claims that a parcel is being held because of an underpayment. The recipient is asked to pay a fee or resolve another supposed delivery problem.

The attacker avoids naming the courier because the message is sent to thousands of people and is meant to sound plausible to as many recipients as possible. An email or text contains a link that appears to track the parcel, but actually redirects to a fake payment service. Entering online-banking credentials may give the attacker an opportunity to steal money from the account.

The second common method is impersonating a specific courier brand. The attacker claims that delivery failed and includes a link to track or redirect the parcel.

Clicking the link opens a fake courier website that may ask the user to download and install a malicious app. The attacker can then monitor activity, steal data and drain the victim’s savings.

Mentioning a popular courier does not mean the attacker knows which service you use. Popular brands are chosen because they make the pretext more likely to succeed.

If the recipient does not respond, the scammer may send another message while impersonating a different courier. Other pretexts include an overweight parcel, a changed delivery address or an imminent collection deadline. Each message includes a link that supposedly solves the problem.

How not to become a victim

  • Ignore messages about undelivered parcels. If you are concerned, contact the courier directly through a trusted channel.
  • Use the courier’s official website. Locate the parcel there and check its delivery status.
  • Do not click links in unexpected delivery messages.
  • Do not install an app from a message. Ignore any request to install software to track or recover a parcel.

Fake deals in online stores

The pursuit of holiday bargains can be risky. Cybercriminals exploit our naivety, especially when a product price looks unusually attractive. A tempting discount is one of the most common lures used by online scammers.

Fake websites may ask for:

  • an online-banking username and password;
  • a PIN;
  • a payment-card number and CVV2 code;
  • a PESEL number.

Sharing such information can lead to the loss of savings and expose data that may later be used for further crimes.

Read more about social engineering in Social Engineering: Good or Bad Manipulation?

How to avoid fake websites

  • Assume that extraordinary bargains may be a trap. If something looks too good to be true, verify it carefully.
  • Check the contact page. Look for the company’s NIP, KRS, full address, telephone number and, where relevant, share-capital information. Verify those details independently.
  • Check independent reviews. If you are buying from a seller for the first time, look for reviews on independent services such as Opineo.
  • Check recent activity. Search for the seller’s latest reviews and social-media activity. A store with no activity for months should make you cautious.

Help people in need—not hackers

During the holidays, many of us become more sensitive to other people’s situation. We are happy to support people in need financially and help them have a better Christmas. We donate to large families, single parents, sick children and abandoned animals.

But how can you be sure that the money will reach the intended recipients? Fake charity collections are a common pretext used by cybercriminals, particularly during the holiday season.

How to support legitimate causes

  • Verify that the organization exists. Find its official website and information about its work and collection.
  • Check the collection platform’s verification information. Reputable portals explain how the organizer’s documents were checked.
  • Donate through a reputable, verified platform or when someone you trust can confirm the cause and the recipient.

Last-minute holiday travel

Dreaming of Christmas in the mountains or abroad by a warm sea? Be careful with unusually attractive online offers. A “bargain” from a well-known travel agency, a private listing or a cheap-flight offer can all be a hacker’s trap.

How to avoid the trap

  • Be cautious with bargains. A suspiciously low price is a warning sign.
  • Avoid websites without contact details. No phone number, email address or location should make you close the page.
  • Check the language and branding. A slightly altered logo or errors in the offer are red flags.
  • For a private offer, contact the owner and ask for additional information, photos or a video.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579