Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What should businesses do when fraudsters start targeting…
Identity Beyond IAM

What should businesses do when fraudsters start targeting customers with pandemic-themed impersonation campaigns?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Identity Beyond IAM

Businesses should strengthen customer communication, warn users about common impersonation tactics, and make authentication flows easier to recognize as legitimate. They should also tune fraud controls to catch cloned sites, malicious attachments, and suspicious login behavior. The practical aim is to reduce confusion, preserve trust in normal security prompts, and limit credential theft before accounts are abused.

Why pandemic-themed impersonation works so well

Pandemic-themed campaigns succeed because they borrow urgency, fear, and familiarity from real events. The message often looks like public health guidance, relief notices, internal policy updates, or delivery notifications, which makes recipients more likely to click quickly and less likely to question the source. That combination increases both phishing conversion and the chance that normal security warnings will be ignored.

Businesses should treat these campaigns as a trust problem as much as a technical one. If customers cannot tell whether a message is authentic, the organisation loses the advantage of prior relationship and familiar branding, even when the attacker is using a simple spoofed email, cloned webpage, or malicious attachment.

A useful reference point is that identity-driven abuse remains a major fraud path, with NHI Mgmt Group’s Ultimate Guide to NHIs noting that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. That statistic is not about this campaign type directly, but it reinforces how often attackers convert a single deceptive interaction into broader account abuse once trust has been won.

How businesses should harden customer communications and fraud controls

The first priority is to make legitimate communication unmistakable. Customers should see consistent sender domains, clear support paths, and predictable wording for critical notices, especially when a message asks them to act quickly. When an organisation changes tone, channel, or branding during a crisis, it creates the exact confusion fraudsters exploit.

Authentication flows should also be easy to recognise as genuine. That means preserving familiar login domains, warning users before they leave the trusted environment, and ensuring that password resets, account recovery, and step-up verification do not resemble attacker lures. The goal is not to remove friction everywhere, but to ensure that legitimate prompts are distinguishable from impersonation attempts.

Fraud controls need to look beyond the inbox. Cloned sites, lookalike domains, malicious attachments, and unusual login patterns should be monitored together, because a pandemic-themed lure often uses multiple stages: the message creates urgency, the fake page harvests credentials, and the account is then tested for further abuse. Businesses should align detection rules with that sequence rather than treating each signal in isolation.

For broader control guidance, NIST Cybersecurity Framework 2.0 is useful for organising communication, protection, detection, response, and recovery activities, while OWASP API Security Top 10 helps when fraudsters move from customer deception into automated abuse of exposed application endpoints. If the campaign includes credential harvesting or secret theft, CISA Known Exploited Vulnerabilities Catalog is also relevant for prioritising externally exposed weaknesses that are frequently paired with phishing-driven intrusion.

Risk and Threat Considerations

Pandemic-themed impersonation campaigns are effective because they exploit heightened attention, emotional pressure, and uncertainty. The practical risk is not only credential theft, but also reduced trust in genuine business communications, higher support burden, and a larger chance that customers will accept a malicious prompt as routine.

Failure mechanism: Attackers spoof brand cues, register lookalike domains, or send malicious attachments that appear tied to a public health event or urgent service update. Once a customer interacts, the attacker can harvest credentials, redirect payments, or use the account for further fraud.

Impact: The immediate loss is often account takeover or transaction fraud, but the broader impact is erosion of customer confidence in normal messages, delayed incident response, and a higher likelihood of repeat victimisation through the same trusted channel.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlPandemic impersonation turns on trust in customer access flows and login legitimacy.
PR.DS — Data SecurityImpersonation campaigns often aim to steal credentials and sensitive account data.
DE.CM — Continuous MonitoringCloned sites and suspicious login behavior require ongoing detection and correlation.
Recommendation — Harden customer login and recovery paths so legitimate access remains clearly distinguishable from spoofed prompts. Protect customer data and credentials against theft through phishing, fake sites, and malicious attachments. Monitor for spoofed domains, abnormal login patterns, and fraud indicators across customer channels.
CIS Controls v85 — Account ManagementFraud campaigns exploit weak account verification and recovery workflows.
9 — Email and Web Browser ProtectionsThe campaign vectors include phishing mail, cloned sites, and malicious attachments.
13 — Network Monitoring and DefenseSuspicious login behavior and fraud infrastructure need detection and response coverage.
Recommendation — Tighten account lifecycle and recovery controls so impersonation cannot easily escalate to takeover. Filter malicious mail and block access to lookalike or weaponised web destinations. Detect anomalous web and authentication activity associated with impersonation campaigns.
OWASP Non-Human Identity Top 10NHI-01 — Identity and Access GovernanceCredential theft and downstream account abuse are central outcomes of impersonation fraud.
NHI-03 — Secrets and Credential ManagementThese campaigns often aim to capture or reuse login secrets and tokens.
NHI-09 — Third-Party and Supply Chain ExposureCloned sites and deceptive external channels often exploit trusted third-party relationships.
Recommendation — Reduce the blast radius of stolen credentials by enforcing least privilege and access review. Rotate and protect secrets so stolen credentials from fake sites are less useful to attackers. Verify external communications and partner-facing links before they can be abused for impersonation.

Practitioner Guidance

What to prioritise: Focus first on making official communications and login flows unmistakable to customers. If users have to guess whether a message or page is real, the control environment is already too weak for a crisis-driven campaign.

What to verify: Check whether support scripts, outbound templates, password reset pages, and fraud alerts all use consistent branding, domains, and customer instructions. If the organisation cannot reliably distinguish its own messages from a clone, attackers will be able to exploit that ambiguity at scale.

Common mistake: Treating the problem as only an email-filtering issue. These campaigns often succeed because the deception continues after the first click, through fake login pages, credential replay, and secondary account abuse.

Practitioner takeaway: The strongest defence is not just blocking bad messages, but preserving recognisable trust signals after the message arrives, so customers can distinguish a legitimate security action from a fraudster’s imitation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org