Tis the Season for Holiday Scams: Beware of Phishing

You can’t stop the flood: the pandemic made online shopping jump to incredible heights, and so did cybercrime. According to the FBI, in 2023, cyber attacks during the holiday season resulted in significant financial losses, with victims losing over $700 million in the US alone. The 2024 holiday season is expected to see similar trends.

With remote and hybrid work settings becoming the norm, holiday shopping may cross the boundaries between home and work computers. It means that attackers now have even more opportunities to get their hands on corporate data. The Better Business Bureau (BBB) has issued warnings about online shopping scams and fraudulent advertisements, advising consumers to check the legitimacy of stores and offers to avoid falling victim to potential scams.

With all these reasons, one can see why holiday scams are a motivation for companies to offer cybersecurity training and awareness to their employees.

Cybersecurity training and awareness to avoid holiday phishing emails

How to keep your shopping pace without compromising corporate data?

According to the latest research from Global Workplace Analytics, by 2024, it’s estimated that 30% of the workforce will be working remotely multiple days a week, with hybrid work becoming a standard model for many companies. This shift reflects a growing preference among employees for flexibility, with 55% stating they would prefer to work remotely at least three days a week. As hybrid work environments become more prevalent, companies face new challenges in securing corporate data, especially during the holiday season when the risk of phishing scams increases significantly.

However, there are several security risks involved in a hybrid working environment. On the top of the list is putting corporate data at the risk of being attacked. Between March and July 2024, companies experienced a notable increase in data breaches and security incidents, particularly during periods of remote work. Phishing scams were a primary vector, with reports indicating that 65% of all phishing attempts during this time were conducted via email.

Additionally, ransomware attacks surged by 58% compared to the previous year, often delivered through phishing emails, vishing (voice phishing), and whaling attacks targeting high-profile individuals. This trend underscores the heightened cybersecurity risks associated with remote working environments.

With the holiday season coming in, the companies are ready to expect a dramatic increase in cyberattacks, especially holiday phishing scams. Therefore, companies must educate and train their employees using customized holiday phishing simulations. This exercise will enable the users to recognize and report phishing emails, decreasing the chances of employees becoming victims and putting the corporate data at risk.

From November to January, people are preoccupied with holiday activities, one of which is online shopping. Therefore, it’s easy to fall for holiday scams. With hybrid work, phishing scams rise because employees are likely to use work computers for holiday shopping. In the holiday season, people are used to receiving more emails, including shipping notices, promotion emails, order receipts, etc. Combining all these factors increases the likelihood of cyberattacks by putting corporate data at risk of exposure.

Cybercriminals spoof these seasonal emails and insert their malicious links and attachments. Because employees frequently check personal email while at work, these holiday scams pose a greater risk to business networks. They could also be receiving scams sent directly to their work email, posing as a business purchase.

During the holiday season, consumers should be aware of common holiday scams, which often target shoppers and charities. Vigilance and education are crucial to help individuals protect themselves from becoming victims of these scams.

Consider the following types of phishing scams that you and your employees risk seeing this holiday season.

Understanding Holiday Phishing Scams

The holiday season is a prime time for cybercriminals to launch phishing scams, preying on the increased online shopping activity and the general busyness of consumers. Holiday phishing scams typically involve fake emails, texts, or social media messages that appear to be from legitimate companies or organizations. These deceptive communications aim to trick you into providing personal or financial information, such as login credentials, credit card numbers, or bank account details.

Phishing scams can be particularly effective during the holiday season because people are often distracted and in a rush, making them more susceptible to these tactics. The influx of holiday-related emails, such as shipping notices and promotional offers, can make it challenging to distinguish between genuine and fake messages.

To protect yourself from falling victim to these scams, it’s crucial to be vigilant when receiving unsolicited emails or messages. Look for warning signs of a phishing scam, such as spelling or grammar mistakes, generic greetings, or requests for sensitive information. Always verify the legitimacy of the communication before providing any personal or financial information. By staying alert and cautious, you can enjoy the holiday season without compromising your security.

Warning Signs of a Fake Order Receipt

Phishing scammers will send fake order receipt emails that appear to be from well-known retailers during the holidays. The order link will usually direct the user to a fake sign-in form designed to steal login credentials or a malware-infected website. 

The goal of this phishing scam is to elicit an emotional response from someone who either didn’t place the order and is angry and wants to correct the error or is curious and wants to see what they may have ordered.

Spoofed Shipment Tracking

People receive order tracking notices at a higher rate during the holidays than during the rest of the year. Scammers use social media ads to promote fake tracking links that lead to malicious websites. Cybercriminals take advantage of this by sending holiday phishing emails that appear to be from a legitimate company, such as Amazon, Microsoft, etc. These emails redirect the user to a malicious website to download ransomware, spyware, or other malware, corrupting their systems.

Charitable Contribution Scam

Charities frequently take advantage of the holiday season’s giving spirit to expand their outreach efforts. But unfortunately, fake charities exploit this generosity by sending out fake donation requests with heartfelt images to get people to provide them with money and credit card information.

If employees or businesses want to donate and not fall for this holiday scam, they should do so through a reputable organization. It is imperative to make it a habit and always visit the website directly whether you wish to purchase something or make a donation.

Gift Card Phishing Scam: Common Gift Card Scams

One of the more sophisticated holiday scams involves impersonating an employee in a position of authority. This employee is most likely to be a part of your company, such as a manager or a supervisor. Scammers can quickly obtain this information by visiting a company’s website or a social networking site such as LinkedIn. Then, they send an email to a lower-level employee that appears to be from the manager.

To avoid falling victim to scams, it is crucial to purchase gift cards from reputable retailers. This ensures that you are not misled into buying counterfeit or empty gift cards at attractive prices.

These scammers aim to take advantage of an employee’s desire to please the boss. This scam uses the unreachable ruse to discourage the recipient from calling to ask any questions. If an unusual request like this comes in, employees should always contact the person using the contact information they have on file for them.

Fake Holiday Sales & Promotions from Fake Online Stores

It’s difficult to resist checking out a rock-bottom price on a new iPhone 16 or another gadget you’ve been eyeing to see if it’s legitimate. Unfortunately, deeply discounted prices are a major red flag for fake holiday sales and promotions, often leading people to click on holiday phishing emails, directing them to sites that perform malware drive-by downloads.

During the holiday season, it’s critical to be extra vigilant and avoid clicking links in emails whenever possible. If the sale is from a reputable retailer, going to their website directly should yield the same results and is safer than clicking a link.

Safe Online Shopping Practices

As the holiday season approaches, it’s essential to adopt safe online shopping practices to protect yourself from phishing scams and other cyber threats. Here are some best practices to keep in mind:

  • Use reputable retailers: Stick to well-known and reputable retailers when making online purchases. Avoid shopping on unfamiliar websites that may not be trustworthy.

  • Look for security indicators: Ensure the website is secure by looking for security indicators such as a lock icon in the address bar or a “https” prefix. These signs indicate that the website uses encryption to protect your data.

  • Use strong passwords: Create strong and unique passwords for all your online accounts. Avoid using the same password for multiple accounts to reduce the risk of a security breach.

  • Monitor your accounts: Regularly check your financial accounts and credit card statements for any suspicious activity. Report any unauthorized transactions immediately to your bank or credit card company.

  • Avoid using public Wi-Fi: Public Wi-Fi networks can be unsecured and vulnerable to hacking. Avoid using them for online purchases or accessing sensitive information.

By being aware of the warning signs of a scam and following these safe online shopping practices, you can help protect yourself from holiday phishing scams and enjoy a secure shopping experience during the holiday season. Stay vigilant and prioritize your online security to ensure a joyful and scam-free holiday season.

Protect Your Employees Using Holiday-Themed Phishing Simulations

On this 2022 holiday season, cybercriminals will undoubtedly take advantage of the increase in online shopping and travel. The holiday season brings many cybersecurity challenges and an increase in travel and online shopping. Do your users have the skills to recognize phony shipping notifications, malicious links in travel scams, and other phishing scams?

With the holiday season approaching, it’s crucial to prepare your workforce to combat evolving cybersecurity threats. Our comprehensive Human Risk Management (HRM) platform, combined with end-to-end phishing solutions, equips your team to recognize, report, and stop phishing scams before they cause harm.

Whether your organization operates remotely, in-office, or in a hybrid model, our solutions are designed to adapt to your needs. By focusing on proactive education, real-time interventions, and advanced phishing defense mechanisms, we ensure your workforce is always prepared. Together, HRM and our phishing solutions create a unified defense system, transforming your employees into a resilient shield against cyber threats.

Request a demo today to see how our solutions can safeguard your organization from the growing threat of phishing scams.

Experience AI-Driven Human Risk Management

Talk to our team and get a personalized demo to address your challenges and expectations.

Book Now