Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› How should people verify whether a COVID-related message…
Cyber Security

How should people verify whether a COVID-related message is legitimate before they act on it?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Cyber Security

Treat any unexpected COVID-related message as untrusted until you verify the sender and the claim through an independent source. Check the email address, avoid opening links or attachments, and confirm with the organisation directly if needed. Legitimate public health bodies and companies do not usually ask for passwords, banking details, or urgent payments by email.

Legitimacy checks work best when you treat the message as a claim to be verified, not as an instruction to follow. The key test is whether the sender, the wording, and the request all make sense if you independently confirm them through a trusted channel rather than through the message itself.

That is why the safest habit is to verify the organisation, then verify the claim, then verify the action requested. A message can look polished and still be fraudulent if it pushes urgency, secrecy, or payment pressure before you have checked the source.

What legitimate public health messages usually look like

Authentic public health communications are usually consistent with the organisation’s normal tone and channel. They may direct you to official websites, published guidance, appointment systems, or documented contact numbers, but they should not depend on you trusting a link, attachment, or reply address at face value.

Be especially cautious if the message asks for credentials, banking details, gift cards, or immediate payment. A real public health body or reputable company will generally not need that kind of information through an unsolicited email or text, and a request that mixes health language with financial pressure is a common warning sign.

If the message claims to come from a known employer, insurer, hospital, or government body, check whether the sender address matches the organisation’s real domain and whether the communication matches what that organisation normally sends. Small mismatches in spelling, formatting, or contact details are often the first clue that the message is not legitimate.

What to do before you click, reply, or share anything

Pause before interacting with the message, because the fastest way to make a bad message harmful is to act on it immediately. If you need to confirm it, use a trusted contact method that you already know, such as the organisation’s official website, published phone number, or a portal you normally use.

Do not use the links or attachments in the message to verify it. If you are checking a website address, type it yourself or navigate from a saved bookmark, then compare the information there with the message you received. If the message asks you to call someone, find the number independently rather than using the one provided in the message.

When the claim affects medical advice, vaccination, testing, travel, employment, or benefits, check whether the same information appears on an official source or from a direct organisational announcement. If it does not, treat the message as unconfirmed until you can reconcile the difference.

Risk and Threat Considerations

COVID-related messages are attractive to scammers because people are more likely to act quickly when the topic feels urgent, public, or personally relevant. The risk is not just misinformation, but credential theft, payment fraud, and redirection to fake portals that imitate trusted health or service providers.

Failure mechanism: The attacker uses a believable health theme, urgency, or authority cue to bypass scrutiny, then pushes the recipient to click, share secrets, or hand over money before the claim is checked elsewhere.

Impact: A successful fake message can lead to account compromise, financial loss, exposure of personal data, or harmful actions based on false health information.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Authenticator ManagementVerifying sender and access requests depends on strong authentication and trusted communication paths.
Recommendation — Require trusted channels before acting on health-related requests and limit reliance on message-origin claims.
NIST SP 800-53 Rev 5SI-10 — Information Input ValidationUsers should validate the message content and destination before following links or attachments.
IA-5 — Authenticator ManagementLegitimate organisations should not solicit secrets through unsolicited messages, so credential requests must be rejected.
Recommendation — Validate external message claims through independent sources before accepting requested actions. Reject any unsolicited request for secrets and confirm identity through a separate trusted channel.

Practitioner Guidance

What to verify: Confirm the sender, the domain, and the requested action independently. If the message demands credentials, payment, or personal data, treat that as a higher-risk condition and verify through the organisation’s official channel before proceeding.

Common mistake: People often validate only the wording of the message, not the source. A message can mention a real public health topic and still be fraudulent if the contact path, reply address, or destination link is fake.

Practitioner takeaway: The right rule is not “does this sound plausible?”, but “can I prove the source and the request outside the message itself?” If you cannot, do nothing until you have an independent confirmation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org