Source-linked AI summary

Cyber Security in the Age of COVID-19: A Timeline and Analysis of Cyber-Crime and Cyber-Attacks during the Pandemic

Harjinder Singh Lallie, Lynsay A. Shepherd, Jason R. C. Nurse, Arnau Erola, Gregory Epiphaniou, Carsten Maple, Xavier Bellekens

arXiv:2006.11929v1cs.CRcs.CYcs.HC

TL;DR

The pandemic created distinctive cyber-crime conditions, including scams, attacks on support platforms, PPE fraud, and COVID-19 cure offers, while complicating organisational protection. The paper analyses cyber-attacks alongside pandemic events and identifies phishing-based campaigns that leverage media and governmental announcements, while acknowledging that its timeline is not exhaustive.

  • Problem

    The pandemic created distinctive cyber-security challenges through widespread cyber-attacks, scams, and home working, making appropriate organisational protection and response difficult.

  • Method

    The paper categorises cyber-crime types and constructs a chronological event representation using reported cyber-attacks, article dates, attack dates when available, and pandemic-related events.

  • Results

    The analysis identifies a common campaign pattern in which phishing directs victims to malware-bearing files or URLs, while media and governmental announcements serve as hooks for cyber-attacks.

  • Takeaways & Limitations

    Governments, media, and other institutions should accompany announcements and published stories with disclaimers explaining how related information will be relayed.

  • Takeaways & Limitations

    The timeline is not exhaustive because reporting lacks sufficient quality and coverage across global, targeted, and general-public incidents.

Abstract

from arXiv · show

The COVID-19 pandemic was a remarkable unprecedented event which altered the lives of billions of citizens globally resulting in what became commonly referred to as the new-normal in terms of societal norms and the way we live and work. Aside from the extraordinary impact on society and business as a whole, the pandemic generated a set of unique cyber-crime related circumstances which also affected society and business. The increased anxiety caused by the pandemic heightened the likelihood of cyber-attacks succeeding corresponding with an increase in the number and range of cyber-attacks. This paper analyses the COVID-19 pandemic from a cyber-crime perspective and highlights the range of cyber-attacks experienced globally during the pandemic. Cyber-attacks are analysed and considered within the context of key global events to reveal the modus-operandi of cyber-attack campaigns. The analysis shows how following what appeared to be large gaps between the initial outbreak of the pandemic in China and the first COVID-19 related cyber-attack, attacks steadily became much more prevalent to the point that on some days, 3 or 4 unique cyber-attacks were being reported. The analysis proceeds to utilise the UK as a case study to demonstrate how cyber-criminals leveraged key events and governmental announcements to carefully craft and design cyber-crime campaigns.

I. INTRODUCTION

COVID-19 created conditions for widespread cyber-attacks and cyber-crime, while the fragmented reporting landscape made the pandemic-related threat difficult to assess and address. The paper motivates a timeline-based analysis to examine attack patterns, event connections, and impacts on citizens and organizations.

  • Pandemic cyber-threats: Cyber-attacks affected the public, home workers, support platforms, and critical infrastructure including healthcare services.Reported campaigns included scams, PPE fraud, fake cures, phishing, malware, and communications-platform compromise.
  • Research gap: The state of pandemic-related attacks was highly dispersed, making it difficult for organizations to develop appropriate protection and response measures in a dynamic environment.Reports came from governments, media, security organizations, and incident teams.
  • Research approach: The paper proposes a global timeline that maps cyber-attacks against virus spread, lockdowns, and policy announcements, supplemented by a UK case study and workforce-risk analysis.The analysis examines attack timing, campaign construction, and impact.
  • Conceptual framing: Opportunistic attacks select victims based on susceptibility and exploit hooks such as distraction, panic, time constraints, and major public events.The paper situates COVID-19 attacks within prior crisis-related scams and the crime triangle of victim, motive, and opportunity.
  • Pandemic cyber-threats: Phishing and malware attacks increased sharply during the pandemic, while attackers also targeted high-demand goods, COVID-19 investments, public authorities, and aid programs.Google reportedly blocked 18 million virus-related malware and phishing emails daily during April 2020.

III. TIMELINE OF COVID-19 RELATED CYBER-ATTACKS

The paper develops a methodology for constructing a COVID-19 cyber-attack timeline by gathering, categorizing, and organizing reports of attacks. It presents the timeline as a way to analyze the mechanisms and reach of pandemic-related threats.

  • III. TIMELINE OF COVID-19 RELATED CYBER-ATTACKS: The timeline is intended to support understanding of how pandemic cyber-crime incidents unfold and how their threats propagate and reach populations.The paper frames this understanding as important for analyzing serious risks to safety and the global economy.
  • III. TIMELINE OF COVID-19 RELATED CYBER-ATTACKS: The methodology gathers COVID-19 cyber-attack data using defined search terms, data sources, source types, and attack categories.The authors also acknowledge potential limitations of the work.

1) Nomenclature:

The paper uses COVID-19 as its standardized term for the novel coronavirus despite the virus having several names in English-language usage.

  • 2) Nomenclature:: The paper uses “COVID-19” to refer to the virus, following terminology used by the World Health Organization.Other terms listed include Coronavirus, Covid19, 2019-nCoV, and SARS-CoV-2.

2) Construction of the timeline:

The timeline was constructed by searching multilingual reports, categorizing attacks, and ordering events chronologically. Its records combine attack dates with publication dates when necessary and cover a defined reporting period.

  • 2) Construction of the timeline:: Search results were categorized by attack type and delivery method, ordered by date, and collated for presentation in Figure 2 and Table I.The table provides a baseline for the timeline construction.
  • 2) Construction of the timeline:: The timeline records pandemic milestones, healthcare-related attacks, and country-specific dates for first cases, lockdowns, and first identified attacks.Table I examines a subset of the timeline information.
  • 2) Construction of the timeline:: Sources included reputable news outlets, blog articles, security-company reports, and social-media posts because the research addressed an emerging threat.The authors note that blogs and social-media posts are not academic sources but may provide trend insights.
  • 2) Construction of the timeline:: The review covered reports from mid-March to mid-May 2020, while the timeline limited attacks to those experienced by 31st March after reaching a perceived saturation point.The earliest reported attack was dated 6th January 2020.
  • 2) Construction of the timeline:: Multiple search engines and multilingual keywords were used to locate reports across English, Chinese, Japanese, French, and Italian contexts.The search terms covered both virus names and cyber-attack terminology.
  • 2) Construction of the timeline:: When an attack date was unavailable, the timeline used the publication date to preserve a chronological representation of events.The authors distinguish this from reports that explicitly provide the perpetration date.

3) Types of cyber-attacks :

The paper classifies cyber-crime using the CPS distinction between cyber-dependent and cyber-enabled crimes, then examines attack types and their sequences. The categories support analysis of how attacks exploit human or technical vulnerabilities.

  • CPS categories: The CPS taxonomy divides cyber-crime into cyber-dependent offences requiring ICT and cyber-enabled traditional crimes whose scale or reach is increased by ICT.The paper notes that phishing can lead to fraud or malware installation, which may enable extortion.
  • Attack types: Denial of Service attacks can distract businesses or act as smokescreens during hacking attempts.
  • Attack types: Phishing and social engineering persuade victims to share information or visit websites while posing as legitimate parties, including through SMS or WhatsApp smishing.Pharming is described as similar to phishing but requiring greater access or technical capability.
  • Attack types: Financial fraud deceives individuals or organisations for financial gain, while extortion coerces victims into actions such as releasing finances.
  • Attack types: Hacking compromises system confidentiality or integrity through vulnerabilities, while malware disrupts services, extracts data, or supports other attacks.The paper identifies ransomware as a common type of malware.
  • Analytical use: These attack categories provide the foundation for the timeline analysis and the paper’s later discussion.

4) Limitations of the table:

The table separates publication timing from attack timing to preserve a consistent chronology while acknowledging that attacks may be reported after they occur.

  • Date fields: The table is ordered by Article Date, the date when each reference was initially published, to provide a consistent chronological representation.Web pages may have been updated after their inclusion in the paper.
  • Date fields: Attack Date records the date of execution when the reference specifies it; otherwise, the reported date is used because attacks may surface several days later.

5) Limitations of the timeline:

The timeline is constrained by incomplete and uneven reporting, so it represents the threat landscape without claiming to enumerate every pandemic-related attack.

  • Reporting constraints: Reports either omit the attack date or include the date of perpetration, requiring the timeline to use publication dates when execution dates are unavailable.
  • Scope boundary: The table is not exhaustive because reporting quality, targeted incidents, public-facing incidents, global coverage, and the number of malicious actors limit complete collection.
  • Scope boundary: The authors state that they nevertheless examined all available resources to depict the threat landscape as accurately as possible.

B. The timeline

The timeline maps 43 COVID-19-related cyber-attacks against pandemic milestones, including reported cases and lockdown announcements, while excluding general advisories and broad attack discussions.

  • B. The timeline: Figure 2 presents a temporal chain of key cyber-attacks alongside first reported cases in nine countries and subsequent lockdown announcements.The countries listed are China, Japan, Germany, Singapore, Spain, the UK, France, Italy, and Portugal.
  • B. The timeline: The timeline contains 43 cyber-attacks categorized using the CPS taxonomy and its abbreviated attack-type labels.
  • B. The timeline: Table I organizes incidents by attack date when available, otherwise using the article date, and records target country, methods, and CPS attack type when identified.
  • B. The timeline: The figure and table exclude general advisories, broad discussions and summaries, and detailed explanations of attackers’ techniques.

C. COVID-19 cyber-attacks in the United Kingdom

The UK case study examines COVID-19-related cyber-crime alongside government announcements and other events. It finds a loose relationship in which some campaigns followed announcements, while others circulated before or without a clear event link.

  • Scope: The UK case study focuses on UK-specific COVID-19 cyber-crime incidents rather than global attacks.The analysis excludes numerous global incidents, including scams impersonating reputed organisations.
  • Scale of the problem: Reported losses reached £4.6m by 29-05-20, involving around 11,206 phishing or smishing victims.More than 160,000 suspect emails had been reported to the NCSC by 07-05-20.
  • Event relationships: The UK timeline indicates a direct and inverse correlation between announcements and cyber-crime incidents.Direct correlations involve campaigns apparently configured around policy context; inverse correlations lack a clear event or announcement correlation.
  • Limitations: The reported relationships remain loose because some campaigns circulated before announcements or reflected issues already prominent in public discussion.The paper states that more work is needed to determine whether a predictive model can be built from these data.
  • Event relationships: Examples of linked campaigns include scams following announcements about support schemes, hardship funds, supermarket assistance, home test kits, job retention, and track-and-trace.These announcements occurred between 19-03-20 and 04-05-20.
  • Event relationships: Some scams could not be traced to a single announcement, including fake £250 goodwill payments, NHS donation requests, supermarket vouchers, and charitable donations.The paper describes these cases as examples that do not map easily to one event.

D. Analysis of cyber-attacks and associated risks

The analysis finds that COVID-19 cyber-attacks became increasingly frequent and were dominated by phishing, malware, and financially motivated fraud. Campaigns commonly exploited pandemic-related announcements, trusted institutional identities, and public anxiety, while attacks also targeted healthcare and COVID-19 research.

  • 30 days separated China’s first announced case from the first reported COVID-19-inspired cyber-attack, while the next attack followed after 14 days.From that point, the timeframe between pandemic events and reported cyber-attacks reduced dramatically.
  • 37 (86%) of the analysed global attacks involved phishing and/or smishing, making them the most common attack type.Campaigns impersonated organisations including the WHO, NHS, airlines, supermarkets, and communication technology providers.
  • China and the USA accounted for 39% of reported attacks, which later spread to the UK and other countries before mostly targeting the whole world.Some later campaigns remained country-specific, including tax-rebate and contact-tracing phishing scams.
  • In the UK case study, all 17 analysed attacks included phishing; 16 pursued financial fraud and one pursued extortion.Nine attacks followed p,ph,f, seven followed p,f, and one followed p,e.
  • Pandemic campaigns used fake institutional websites, convincing domains, emotional appeals, and requests for payment or personal information.Examples included fake WHO and NHS materials, COVID-themed domains, vaccine donations, fraudulent cures, investment offers, and extortion emails using breached passwords.

IV. IMPACT ON WORKFORCE

The pandemic disrupted workforce practices, technology resilience, and information governance while increasing pressure on monitoring, access controls, and data-processing safeguards. Rapid epidemiological data use and remote-work arrangements created technical, legal, and operational challenges.

  • Workforce and technology impact: The pandemic and mass quarantine profoundly affected the workforce, technology resilience, socioeconomic structures, and how people live and communicate.Figure 6 presents the workforce impact across eight categories.
  • Risk governance: Risk statements were proposed around threat agents, vulnerabilities, policy or process violations, and overall asset exposure across emerging threat landscapes.These changes relate to how the workforce accesses information assets and performs strategic, tactical, and operational tasks.
  • Data governance: GDPR requires personal data in the UK to be processed for specific, explicit purposes with transparent information about processing activities.The pandemic increased emphasis on personal-data implications within data structures and information-governance frameworks.
  • Data governance: De-identification and urgent epidemiological data processing created challenges involving accuracy, consent, data disposal, policy robustness, and public trust.Lockdowns also made phased business recovery difficult, while prompting rapid cross-organizational research collaboration.
  • Workforce and technology impact: Increased attack frequency and impact further tested monitoring, auditing, access controls, authentication, and verification schemes.The challenge also extended to timely and accurate information sharing across Europe.

V. CONCLUSION AND FUTURE WORK

The paper finds that pandemic-related cyber-attacks often used phishing to deliver malware and pursue financial fraud, with campaigns exploiting media and governmental announcements. It recommends greater awareness around announcement-linked campaigns and calls for further research into whether the observed relationship can support prediction.

  • Conclusion: A loose correlation appeared between announcements or media stories and corresponding cyber-attack campaigns that used those events as hooks.The paper reports that event-linked hooks increased the likelihood of campaign success.
  • Implications: Increased cyber-attacks and cyber-crime, combined with greater online activity, may create implications for policing and law-enforcement capacity.The paper connects changed working and socialization practices with increased time spent online.
  • Conclusion: Pandemic cyber-criminals commonly used phishing to direct victims to files or URLs carrying malware, which could then support financial fraud.The analysis identifies this as a recurring modus operandi during the period.
  • Implications: Governments, media, and other institutions should anticipate associated cyber-attack campaigns when publishing announcements or stories.The paper recommends accompanying events with notes or disclaimers explaining how related information will be relayed.
  • Future work: Further research should test whether predictive models can confirm the loose direct and inverse relationship between events and cyber-attacks.The authors identify abundant global case studies as a basis for wider analysis.
Loading 2006.11929v1…