During the COVID-19 pandemic, organizations are acting quickly to update HR policies and new security measures in order to protect their employees. Unfortunately, the bad guys work just as fast to use these changes to their advantage.
They are sending emails that appear to be from your HR or IT department, hoping to fool you into trusting them. These phishing emails direct you to review a new policy by downloading a malicious attachment or clicking a link that takes you to a phony login page. Don’t be fooled!
Here’s how to keep your organization safe:
- Whenever you need to log in to an account or online service, always navigate to the login page using your browser, rather than clicking on links in an email.
- Never click on a link or an attachment that you weren’t expecting. Even if it appears to be from someone in your own organization, the sender’s email address could be spoofed.
- When in doubt, reach out to the sender by phone to confirm the legitimacy of the email before clicking.
Stop, Look, and Think. Don’t be fooled.
The KnowBe4 Security Team
KnowBe4.com