A recently uncovered phishing campaign is spoofing messages from the New York State Department of Labor, claiming to offer $600 as part of a COVID-19 relief program, according to researchers at Abnormal Security. The goal is to harvest personally identifiable information.
This phishing campaign, which appears to have started earlier this month, may have targeted 100,000 Microsoft Office 365 accounts so far, the security firm reports.
“The attackers are taking advantage of the current global health crisis by crafting a scam that revolves around the COVID-19 pandemic and its economic impact,” the researchers note. “So, a recipient of this email may be more likely to believe that the government is offering additional relief as the pandemic continues.”