Join our Newsletter — 33% off our NHI Course

Why do pandemic scams create such a high risk of account compromise and financial loss?

Pandemic scams work because they combine urgency, fear, and familiar branding to lower scrutiny. Attackers impersonate trusted organisations, push victims toward malicious links or fake marketplaces, and request credentials or unusual payments. That mix increases the chance of phishing, malware infection, stolen accounts, and fraudulent transactions before people pause to validate the source.

Why pandemic scams are so effective at driving compromise

Pandemic scams succeed because they compress decision time. The attacker’s goal is not only to trick someone once, but to get the person to act before checking whether the message, marketplace, or payment request is legitimate. Once that happens, credential theft, malware delivery, or fraudulent payment becomes much easier.

The psychology matters as much as the lure. Fear, urgency, and uncertainty reduce normal scepticism, especially when the scam borrows the look and language of public health bodies, employers, banks, delivery firms, or well-known retailers.

How attackers turn trust into account takeover or fraud

Pandemic scams usually begin with a believable pretext, then move the target into a channel the attacker controls. That can mean a fake login page, a malicious attachment, a counterfeit shop, or an invoice that looks routine enough to approve without much review.

The most dangerous step is often credential capture. If a victim reuses a password, approves a login prompt, or enters one-time codes into a fake site, the attacker can reuse that access quickly. In many cases the compromise is paired with payment redirection, so the same scam creates both account exposure and direct financial loss.

Attackers also benefit from the fact that pandemic themes normalize exception handling. People are more willing to overlook odd wording, rushed requests, or unusual payment channels when they believe they are responding to an emergency or a health-related update.

Why the damage can spread beyond the first victim

Once an account is compromised, the attacker can use it as a trusted stepping stone. Email, collaboration, and customer-facing accounts are especially valuable because they can be used to reset passwords, impersonate the owner, or lure other victims with messages that appear authentic.

Financial loss is not limited to card theft or a single transfer. It can include unauthorized marketplace purchases, account recovery abuse, business email compromise, refund redirection, and follow-on fraud using the stolen identity of the victim or the compromised organisation.

When scams exploit familiar branding, the blast radius can widen quickly. A false message that appears to come from a reputable source can lower scrutiny across an entire team or customer base, which is why socially engineered compromise often becomes a repeatable campaign rather than an isolated incident. For a broader view of the breach patterns that follow stolen credentials and impersonation, see The 52 NHI Breaches Report.

Risk and Threat Considerations

Pandemic scams create a high risk profile because they combine a believable story with a fast-moving payoff path: the victim is pushed to authenticate, pay, or download before validating the request. That makes them effective not just for phishing, but for any attack that depends on urgency and reduced scrutiny.

Failure mechanism: The scam succeeds when fear and time pressure override normal verification, allowing the attacker to capture credentials, intercept payment, or deliver malware through a trusted-looking channel.

Impact: The result can be account takeover, unauthorized purchases, fraudulent transfers, mailbox or session abuse, and secondary compromise of other users who trust messages sent from the stolen account.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Pandemic scams rely on phishing-style lure delivery and credential capture.
T1586 — Compromise Accounts The question centers on account compromise as the attacker’s objective and outcome.
Recommendation — Hunt for phishing indicators and block message paths that deliver fraudulent login or payment requests. Detect account takeover signals and rotate access when suspicious authentication or recovery activity appears.
NIST SP 800-53 Rev 5 SI-3 — Malicious Code Protection Pandemic scams often weaponize attachments or links to deliver malware.
IA-5 — Authenticator Management The scam’s payoff often depends on stolen passwords, tokens, or one-time codes.
SC-23 — Session Authenticity Fake pages and lookalike flows exploit trust in login sessions and recovery flows.
Recommendation — Apply malware protections to email and download paths that can carry scam payloads. Enforce strong authenticator lifecycle controls and revoke exposed credentials quickly. Verify session authenticity before accepting sensitive logins or payment approvals.
CIS Controls v8 CIS-9 — Email and Web Browser Protections Pandemic scams commonly arrive through email and web links that mimic trusted brands.
Recommendation — Harden email and browser controls against malicious links, attachments, and lookalike sites.

Practitioner Guidance

What to prioritise: Treat any pandemic-themed request that asks for credentials, payment, or document upload as high risk until the sender and destination are independently verified. The key judgement is whether the request forces action before verification.

What to verify: Check the true domain, payment destination, and account recovery path before trusting the message. If the request changes the normal payment process or login flow, assume the attacker is trying to move the victim onto a controlled channel.

Practitioner takeaway: The strongest defence is not simply “be careful”, it is to make urgent requests expensive for attackers by forcing verification steps that cannot be bypassed by a convincing brand or a time-limited message.