Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

The future of hacking: COVID-19 shifting the way hackers work and who they target

By Bill DeLisi
SEC1219-cybergap-Feat-slide1_900px
August 14, 2020

Amid COVID-19, hackers are presented opportunity on multiple fronts. They play on people’s concerns about the virus by presenting phishing schemes or malware disguised in fake Centers for Disease Control and Prevention (CDC) alerts that talk about the latest vaccine or treatment developments. Hackers quickly used the pandemic and related anxiety to lure people into phishing schemes and malware attacks. There is also pressure on healthcare companies and researchers to safeguard their vaccine and treatment data. As of mid-July, there have been multiple reports of Russian and Chinese state-sponsored hackers attempting to steal coronavirus vaccine data from various labs.

Over the past few months, millions of workers have turned their homes into their new, remote office, including state government employees, which brought a host of risks through use of unsecured Wi-Fi and poor access controls. This shift toward home as well as the underlying panic brought on by COVID-19 altered hackers’ focus and targets aimed at the remote worker. Chief Information Security Officers (CISO) preparing their companies for this change require time, training for employees and the right technology, as well as increased cooperation between the security teams and IT/network operations groups.

 

Contact tracing issues

Another opportunity for hacking during the pandemic comes with contact tracing. Hackers found contact tracing apps an ideal cover for phishing schemes, by misrepresenting official tracing accounts via email. Legitimate apps themselves are also targets for hackers who see it as a treasure trove of data with individual names and addresses as well as insights from contacts and movements.

For example, for people in high-value positions such as politicians or lawyers on important cases, information about that person’s movements and meetings is valuable to opponents and easily sold by bad actors. Many of these apps lacked encrypted source code, and many did not have intrusion detection when hackers accessed restricted mobile data.

 

Targeting remote workers

The massive shift toward remote work means more networks are accessed by employees on their own devices. Companies without a remote work component were left to scramble as shutdowns started, putting in place a patchwork of security protocols that often afforded little protection. Remote workers are enticing targets for hackers conducting data theft and ransomware.

As the pandemic continues, companies need to move past the initial shock and adopt Bring Your Own Device (BYOD) policies to handle the nature of remote work. This includes standards for data encryption, dual authentication, pass-phrases instead of passwords, and inactivity timeout controls to protect access during idle periods. IT also needs full remote wipe controls for lost devices or employee terminations or voluntary departures.

Security departments also responded to remote work by investing in VPN access, which brought with it the need for firewalls and gateway controls. Some firms took the step of using operations management tools to turn home computers into corporate-controlled machines managed by IT. Without endpoint management in place, the massive number of phones, tablets and computers accessing corporate networks is unmanageable and unsustainable. These issues also present compliance risks in cases where at-home workers access or store PII data, and they’re subsequently duped by a “COVID-19 Cure” phishing email.

Additional safeguards for businesses during COVID-19 and beyond (since working from home is now a long-term trend):

  • Put in place DDoS protections which can impact the entire remote workforce which relies on accessing the company’s cloud platforms. More security focused appliances are also needed in the cloud to support the infrastructure and protect against DDoS.
  • Use multi-factor authentication (MFA) to reduce access points for hackers to intrude home-based networks.
  • Mandate employees to stay off public Wi-Fi networks which provide easy entry points for hackers.
  • Use monitoring tools to spot poor decisions such as clicking on suspect sites, downloading attachments from unverified senders and other detrimental choices.
  • Use a secure search engine and communication platform, such as GOFBA, that shields users from malicious sites and malware.

 

Employees need guidance

On the people side, training is needed to bring at-home employees up to speed on the latest types of attacks and proper defenses that are necessary during this period of enhanced hacker activity. Education is key. They need additional information about spotting fraudulent emails, and guidance to not click on links or download attachments from unfamiliar senders.

Provide guidance to the remote workers about the ways the World Health Organization (WHO) and CDC disseminate information, so they can spot legitimate data sources. Additional training tips for employees include:

  • Mandates about use of VPNs to access company data and platforms.
  • Automatic updating to remove security and patch gaps from manual updating.
  • IT and security should work together to communicate more frequently with remote employees about the latest tech implementations, best practices, and any shift in expectations from corporate.

Hackers unfortunately thrive on misery. They exploit people’s need for information in a crisis and the security holes caused by disruption. COVID-19 presents an unparalleled disruption, and CISO’s and their teams will need continued vigilance in addition to the latest strategies for managing the challenges of remote workforces, protecting their networks and training staff members to do their part.

KEYWORDS: Chief Information Security Officer (CISO) COVID-19 cyber security information security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Bill delisi

Bill DeLisi is an authoritative expert in cybersecurity. He currently serves as the Chief Executive Officer, Chief Technology Officer and a founding member of the Board of Directors for GOFBA, Inc, a secure search engine. DeLisi has over 30 tech certifications including those with Microsoft, Cisco, Super Micro and Sonic Walls.

 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

2026 Women in Security

Security’s 2026 Women in Security

Denise Platon. Image courtesy of Platon

Denise Platon — Women in Security 2026

Women in Security: Julia Stuyt

Julia Stuyt — Women in Security 2026

Glowing AI square

Security Experts Discuss the Hugging Face, OpenAI Incident

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • SEC1218-Cyber-Feat-slide1_900px

    The future of connectivity

    See More
  • Growing and Gaining

    Recruiting the Future of Security: Finding Future CISOs

    See More
  • NCSAM

    The future of connected devices

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

  • The Database Hacker's Handboo

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing