Businesses should strengthen customer communication, warn users about common impersonation tactics, and make authentication flows easier to recognize as legitimate. They should also tune fraud controls to catch cloned sites, malicious attachments, and suspicious login behavior. The practical aim is to reduce confusion, preserve trust in normal security prompts, and limit credential theft before accounts are abused.
Why pandemic-themed impersonation works so well
Pandemic-themed campaigns succeed because they borrow urgency, fear, and familiarity from real events. The message often looks like public health guidance, relief notices, internal policy updates, or delivery notifications, which makes recipients more likely to click quickly and less likely to question the source. That combination increases both phishing conversion and the chance that normal security warnings will be ignored.
Businesses should treat these campaigns as a trust problem as much as a technical one. If customers cannot tell whether a message is authentic, the organisation loses the advantage of prior relationship and familiar branding, even when the attacker is using a simple spoofed email, cloned webpage, or malicious attachment.
A useful reference point is that identity-driven abuse remains a major fraud path, with NHI Mgmt Group’s Ultimate Guide to NHIs noting that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. That statistic is not about this campaign type directly, but it reinforces how often attackers convert a single deceptive interaction into broader account abuse once trust has been won.
How businesses should harden customer communications and fraud controls
The first priority is to make legitimate communication unmistakable. Customers should see consistent sender domains, clear support paths, and predictable wording for critical notices, especially when a message asks them to act quickly. When an organisation changes tone, channel, or branding during a crisis, it creates the exact confusion fraudsters exploit.
Authentication flows should also be easy to recognise as genuine. That means preserving familiar login domains, warning users before they leave the trusted environment, and ensuring that password resets, account recovery, and step-up verification do not resemble attacker lures. The goal is not to remove friction everywhere, but to ensure that legitimate prompts are distinguishable from impersonation attempts.
Fraud controls need to look beyond the inbox. Cloned sites, lookalike domains, malicious attachments, and unusual login patterns should be monitored together, because a pandemic-themed lure often uses multiple stages: the message creates urgency, the fake page harvests credentials, and the account is then tested for further abuse. Businesses should align detection rules with that sequence rather than treating each signal in isolation.
For broader control guidance, NIST Cybersecurity Framework 2.0 is useful for organising communication, protection, detection, response, and recovery activities, while OWASP API Security Top 10 helps when fraudsters move from customer deception into automated abuse of exposed application endpoints. If the campaign includes credential harvesting or secret theft, CISA Known Exploited Vulnerabilities Catalog is also relevant for prioritising externally exposed weaknesses that are frequently paired with phishing-driven intrusion.
Risk and Threat Considerations
Pandemic-themed impersonation campaigns are effective because they exploit heightened attention, emotional pressure, and uncertainty. The practical risk is not only credential theft, but also reduced trust in genuine business communications, higher support burden, and a larger chance that customers will accept a malicious prompt as routine.
Failure mechanism: Attackers spoof brand cues, register lookalike domains, or send malicious attachments that appear tied to a public health event or urgent service update. Once a customer interacts, the attacker can harvest credentials, redirect payments, or use the account for further fraud.
Impact: The immediate loss is often account takeover or transaction fraud, but the broader impact is erosion of customer confidence in normal messages, delayed incident response, and a higher likelihood of repeat victimisation through the same trusted channel.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Pandemic impersonation turns on trust in customer access flows and login legitimacy. |
| PR.DS — Data Security | Impersonation campaigns often aim to steal credentials and sensitive account data. | |
| DE.CM — Continuous Monitoring | Cloned sites and suspicious login behavior require ongoing detection and correlation. | |
| Recommendation — Harden customer login and recovery paths so legitimate access remains clearly distinguishable from spoofed prompts. Protect customer data and credentials against theft through phishing, fake sites, and malicious attachments. Monitor for spoofed domains, abnormal login patterns, and fraud indicators across customer channels. | ||
| CIS Controls v8 | 5 — Account Management | Fraud campaigns exploit weak account verification and recovery workflows. |
| 9 — Email and Web Browser Protections | The campaign vectors include phishing mail, cloned sites, and malicious attachments. | |
| 13 — Network Monitoring and Defense | Suspicious login behavior and fraud infrastructure need detection and response coverage. | |
| Recommendation — Tighten account lifecycle and recovery controls so impersonation cannot easily escalate to takeover. Filter malicious mail and block access to lookalike or weaponised web destinations. Detect anomalous web and authentication activity associated with impersonation campaigns. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Identity and Access Governance | Credential theft and downstream account abuse are central outcomes of impersonation fraud. |
| NHI-03 — Secrets and Credential Management | These campaigns often aim to capture or reuse login secrets and tokens. | |
| NHI-09 — Third-Party and Supply Chain Exposure | Cloned sites and deceptive external channels often exploit trusted third-party relationships. | |
| Recommendation — Reduce the blast radius of stolen credentials by enforcing least privilege and access review. Rotate and protect secrets so stolen credentials from fake sites are less useful to attackers. Verify external communications and partner-facing links before they can be abused for impersonation. | ||
Practitioner Guidance
What to prioritise: Focus first on making official communications and login flows unmistakable to customers. If users have to guess whether a message or page is real, the control environment is already too weak for a crisis-driven campaign.
What to verify: Check whether support scripts, outbound templates, password reset pages, and fraud alerts all use consistent branding, domains, and customer instructions. If the organisation cannot reliably distinguish its own messages from a clone, attackers will be able to exploit that ambiguity at scale.
Common mistake: Treating the problem as only an email-filtering issue. These campaigns often succeed because the deception continues after the first click, through fake login pages, credential replay, and secondary account abuse.
Practitioner takeaway: The strongest defence is not just blocking bad messages, but preserving recognisable trust signals after the message arrives, so customers can distinguish a legitimate security action from a fraudster’s imitation.
Related resources from NHI Mgmt Group
- Should small businesses start with password management or broader IAM projects?
- Why do standard interview and ID checks fail against coordinated impersonation campaigns?
- How should security teams respond to conflict-themed phishing campaigns?
- How should security teams respond to tax-themed phishing campaigns?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org