What happened?
On 20 March 2020, the FBI’s Internet Crime Complaint Center issued a public service announcement with a message nobody wanted to hear mid-pandemic: criminals were retooling their entire playbooks around COVID-19, and citizens would face a surge of phishing, fake cures, counterfeit supplies, and malicious apps. The advisory landed as part of a coordinated wave – CISA and the UK’s NCSC had published joint guidance days earlier, and the FTC was separately warning of stimulus-payment scams. The IC3 announcement documented how quickly threat actors pivot to a crisis: within weeks of the outbreak going global, pandemic-themed lures dominated criminal telemetry, and complaint centers braced for volume. What made this PSA different from ordinary scam warnings was its timing and breadth – it acknowledged that a scared, remote, transaction-heavy population was about to become the largest attack surface in history, and that awareness was the vaccine available that month. This is how law enforcement tried to patch human nature at pandemic speed.
Quick Answer: On 20 March 2020, the FBI IC3 issued a public service announcement warning of COVID-19-themed cybercrime: phishing emails impersonating health authorities, fake cures and medical supplies, counterfeit treatments, malicious apps imitating infection-tracking dashboards, and investment scams tied to pandemic stocks. The warning was part of a coordinated guidance wave with CISA and the UK NCSC, and it instructed citizens to verify senders, avoid attachments, use trusted sources for health information, and report fraud to ic3.gov. Complaint data later confirmed the predicted surge across BEC, phishing, and fraud categories.
The PSA’s catalog read like a fraud ecosystem rapid-prototype session. Phishing kits re-skinned with CDC and WHO branding within days; fake shops selling masks and sanitizers that never shipped; miracle cures and vaccine lotteries harvesting cards and identities; malicious mobile apps dressed as dashboards delivering infostealers; BEC attacks re-costed around remote-work wire transfers and stimulus payments. The IC3’s role is complaint intake and public warning, and both functions scaled: its 2020 annual report later documented a record volume of complaints – over 791,000, with reported losses around 4.2 billion dollars – with phishing/spoofing the top category, driven substantially by pandemic themes. The March PSA was the flag planted at the surge’s start, and its categories held: every fraud family it named metastasized through 2020 exactly as outlined.
The paper trail
| Date | Event |
|---|---|
| 2020-03-06 | FTC and FDA begin issuing warnings on fraudulent COVID-19 cures and test kits as scam volume climbs |
| 2020-03-20 | FBI IC3 publishes its COVID-19 public service announcement covering phishing, counterfeit goods, fake cures, and malicious apps |
| 2020-04 | CISA-NCSC joint alert on pandemic phishing and malware is amplified; ic3.gov complaint intake surges with pandemic-theme reports |
| 2021-03 | IC3 annual report documents 791,000+ complaints and ~4.2 billion dollars in reported losses for 2020, with phishing the leading category |
Why pandemic lures outperformed everything
The effectiveness formula is unhappily simple: urgency times fear times novelty times necessity. A lure that says your exposure notification is ready, your stimulus payment needs confirmation, or your workplace policy changed today defeats the skepticism that a normal marketing email cannot. Add remote onboarding chaos – millions of workers newly on home networks, outside corporate controls, drowning in novel legitimate notifications from HR, government, and vendors – and the signal-to-noise defense people rely on collapsed. Criminals A/B-tested at population scale: template kits with pandemic branding circulated in forums, and successful templates iterated weekly. Vendor telemetry through spring 2020 showed COVID-themed phishing rising from zero to dominant-lure status in roughly a month, a faster thematic takeover than any prior event. The IC3 warning’s core advice – verify the sender, go to the source directly, be suspicious of urgency – was the correct countermeasure, and remains the only defense that scales with human psychology under stress.
The app and dashboard threat
Among the PSA’s categories, malicious apps deserve their own memory because they fused information hunger with malware distribution model that only a pandemic could enable. Citizens urgently wanted case counts, and criminals supplied dashboards – Android packages and shady sites imitating the universities and agencies publishing real trackers, some carrying ransomware or banking trojans, some harvesting permissions wholesale. Domain registrars and researchers documented thousands of COVID-themed registrations within weeks, a meaningful fraction abusable. The episode forced a defensive doctrine that later hardened during the vaccine era: official information channels must be not only authoritative but easiest to find, because the attention economy fills any vacuum with predation. Governments responded by publishing canonical dashboards, registrars and browser vendors built takedown and warning pipelines, and app stores tightened pandemic-themed review – infrastructure that outlived the crisis and now activates for every large public event.
- Crisis attention is criminal inventory: pandemic lures outperformed because fear and urgency bypass skepticism; verification habits are the control that travels.
- Advice channels must outrun the scams: the IC3-CISA-NCSC guidance wave showed coordination works; pre-positioned warnings limit the surge’s yield.
- Every new channel inherits the threat: dashboards, stimulus portals, and remote-work tools each spawned their own scam families within weeks.
- Complaint data closes the loop: ic3.gov reporting converts victimhood into intelligence; the 2020 record volume itself became a policy argument for consumer cyber defense.
FAQ
What did the FBI IC3 warn about in March 2020?
The public service announcement of 20 March 2020 warned that cyber criminals were exploiting COVID-19 through phishing emails impersonating health authorities and employers, fake cures and counterfeit medical supplies, fraudulent charities, malicious apps imitating pandemic dashboards, and investment scams tied to the crisis. It urged verification of senders, avoidance of attachments and links from unknown sources, and reporting to ic3.gov.
Was there really a measurable surge in cybercrime during the pandemic?
Yes. IC3’s annual report for 2020 logged a record 791,000-plus complaints with reported losses near 4.2 billion dollars, with phishing and spoofing the top complaint category – categories the March PSA had flagged. Vendor telemetry independently showed pandemic-themed lures becoming the dominant phishing theme within weeks of the outbreak.
How were malicious apps involved?
Fake COVID-19 tracker and information apps – particularly outside curated app stores – carried ransomware, infostealers, and aggressive permission harvesting while imitating legitimate dashboards from agencies and universities. The IC3 and partner agencies advised using only official app stores and government websites for pandemic information.
What should citizens actually do against such surges?
Go directly to official sources instead of clicking emailed links, verify sender addresses, distrust urgency and payment demands, keep devices updated, use unique passwords with multi-factor authentication on key accounts, and report fraud to ic3.gov – the intake that feeds law-enforcement intelligence and takedowns.
Did the warnings make a difference?
Coordination set a template still used: rapid joint advisories, canonical information channels, registrar and platform takedowns, and app-store review tightening all trace their crisis playbook to spring 2020. The surge still happened – complaint records prove it – but the response infrastructure built then now activates for every subsequent mass-attention event.
Coordination as the new playbook
What distinguished March 2020 from prior fraud surges was the response choreography. Within a single week, the FBI IC3 issued its public service announcement, CISA and the UK NCSC published their joint alert on pandemic-themed phishing and malware, and consumer-protection agencies fired parallel warnings on fake treatments and stimulus fraud. The alignment was not accidental – it reflected information-sharing pipelines built during the preceding decade, now stress-tested at pandemic tempo. Agencies cross-referenced each other’s guidance, vendors translated advisories into product detections, and media carried the warnings to audiences that security messaging had never previously reached. The result was a public-awareness layer operating as infrastructure: consistent advice, multiple redundant channels, and a reporting loop through ic3.gov that turned complaints into takedown actions and indictments. Later events – vaccine-rollout scams, disaster-relief fraud, election-season phishing – reused this exact choreography, confirming that the 2020 wave’s most durable artifact was not any single warning but the demonstrated ability to synchronize the entire warning apparatus within days of a threat emerging.
Legacy: awareness as infrastructure
The March 2020 IC3 announcement endures less for its content – scam catalogs age fast – than for what it operationalized. It demonstrated that public-warning infrastructure could move at crisis speed and coordinate across agencies and borders, a capability subsequently exercised for vaccine scams, election-season fraud, and disaster-relief phishing. It validated the complaint-intake loop as strategic data: the 2020 numbers became the citation for consumer-cybersecurity budgets and for treating phishing as the leading cyber threat to ordinary people, a reframing with years of policy tail. And it left a sober lesson about the demand side: fraud follows attention with near-zero lag, so the arbitrage window between a news event and its criminal exploitation has collapsed to days. The PSA’s closing advice has not aged: verify, slow down, report. The machinery that receives those reports is the announcement’s real legacy – a standing institution that treats the citizenry as attack surface worth defending, and awareness as the patch that ships fastest.
