>

When Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

On 24 March 2020, Reuters reported that hackers had stood up a near-identical malicious imitation of the World Health Organization's internal email portal, infrastructure aimed at stealing passwords from staffers coordinating the global pandemic response. The same reporting documented that around 450 active WHO email addresses and passwords, plus thousands more belonging to people working on the COVID-19 response, had been leaked online. It was not an isolated incident but part of a documented surge in targeting of health bodies that spring. This piece reconstructs the verified incidents of March 2020 and the wider lesson that crisis response organizations are priority intelligence targets.

Continue ReadingWhen Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

The FBI’s COVID-19 Warning: IC3 and the Scam Surge of March 2020

On 20 March 2020, the FBI's Internet Crime Complaint Center published a public service announcement warning that cyber criminals were exploiting the COVID-19 pandemic at scale: phishing lures referencing stimulus payments and fake cures, malicious apps, and infrastructure spoofing health authorities. It was one node in a broader wave of official guidance that spring, with CISA and the UK's NCSC issuing joint advice on pandemic-era remote work and video conferencing security, and IC3's later reporting would show complaint volumes surging through 2020. This retrospective explains what the warning said, what the threat landscape actually looked like that spring, and how a global crisis became an attack-surface multiplier.

Continue ReadingThe FBI’s COVID-19 Warning: IC3 and the Scam Surge of March 2020
>