Join our Newsletter — 33% off our NHI Course

Pandemic Fraud

Fraud that adapts to a major public health or social disruption, using uncertainty, urgency, and changed behaviour to increase success rates. In practice, it includes scams tied directly to the event and wider fraud patterns that accelerate because more activity moves online.

Pandemic Fraud as a Crime Pattern

Pandemic fraud is not a single scam type, but a fraud pattern that tracks a major disruption. Criminals exploit uncertainty, shifting rules, and rapidly changing public behaviour to make deception feel timely, credible, and urgent.

That adaptability is what makes the term useful. The fraud itself may look like phishing, impersonation, charity scams, investment fraud, invoice diversion, counterfeit goods, or benefit abuse, but the event gives it a stronger social cover and a larger target pool.

Common Forms and Why They Scale

During a public health crisis or other broad disruption, fraud often moves faster than normal control changes. People are less certain about legitimate processes, organisations redesign workflows quickly, and more activity shifts online, which expands opportunities for impersonation and payment redirection.

Fraudsters also reuse the same disruption for multiple schemes. A vaccine-related scam, a fake relief payment page, and a business email compromise campaign can all rely on the same underlying theme: a believable story tied to the event and a short decision window.

Because the disruption affects consumers, employees, suppliers, and public agencies at the same time, pandemic fraud is often a volume problem as much as a sophistication problem. A low-effort scam can work at scale when attention is fragmented and verification habits weaken.

Indicators and Control Weaknesses

The practical warning signs are less about the topic of the message and more about the manipulation pattern. Look for pressure to act quickly, requests to bypass normal payment or verification steps, unfamiliar domains, changed beneficiary details, and messages that borrow public-health language to create trust.

The control weakness is usually not one broken safeguard, but a temporary gap between the new operating environment and the older fraud model. Verification procedures, approval chains, and customer awareness often lag behind the new scam narrative, which gives the fraud a window of opportunity.

For organisations, the biggest exposure is where disruption alters who can approve payments, authenticate requests, or validate identity. For individuals, the main exposure is emotional urgency combined with a believable public-interest theme.

How to Interpret the Term

Pandemic fraud is best understood as a situational fraud category. The word “pandemic” identifies the trigger condition, while “fraud” identifies the criminal objective, which is to obtain money, credentials, personal data, or other value by exploiting the moment.

That means the term belongs in fraud analysis, consumer protection, and operational resilience discussions, not only in health-security commentary. The same pattern can appear whenever a major disruption changes normal behaviour, creates public anxiety, or forces rapid digitisation.

In practice, the term is most useful when comparing scams that emerged during the COVID-19 period with other event-driven fraud waves, such as disaster scams or crisis-themed impersonation campaigns.

Risk and Threat Considerations

Pandemic fraud matters because major disruptions lower the cost of deception. Attackers benefit from fear, confusion, and rushed decision-making, while defenders often have to change processes at the same time they are trying to keep services running.

Failure mechanism: the scam succeeds when the event creates a believable pretext, suppresses normal verification, or redirects people into untrusted channels before they notice the inconsistency.

Impact: victims can lose money, disclose sensitive information, or enable follow-on fraud, while organisations face payment loss, reputational harm, and increased pressure on support and investigation teams.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control Fraud often exploits weak request verification and identity assurance during disruption
DE.CM-09 — Malicious Code and Indicators of Compromise are Detected Event-driven scams are often detected through monitoring of suspicious campaigns and messages
Recommendation — Tighten verification and access controls around payment, login, and approval workflows. Monitor for phishing, impersonation, and fraud indicators across email and web channels.
CIS Controls v8 CIS-6 — Access Control Management Fraud commonly abuses changed approval paths and bypassed controls during disruptions
Recommendation — Enforce approval and access rules that prevent bypassing normal verification.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Fraud investigations depend on reviewing records for abnormal requests and payment changes
IA-2 — Identification and Authentication (Organizational Users) Impersonation scams exploit weak authentication of staff and internal requesters
Recommendation — Review audit records for anomalous transactions, logins, and request changes. Require strong authentication before honoring sensitive requests or approvals.

Practitioner Guidance

What to watch for: treat event-linked urgency as a fraud signal, especially when a message asks for payment, login, or personal information outside normal workflows. The safest response is usually to verify the request through an independent channel that is already trusted by the organisation or individual.

Governance implication: fraud controls need to be resilient to changing business conditions, not just steady-state operations. During a crisis, verification rules, customer messaging, and payment controls should be reviewed as frequently as the threat narrative changes.