They work because attackers borrow current events, trusted brands, and urgency to bypass careful review. The message feels timely, familiar, and consequential, which increases the chance that a recipient will click, open an attachment, or comply with a financial request. That combination helps attackers steal credentials, deploy malware, or trick staff into making payments.
Why these messages still work
COVID-themed phishing and BEC remain effective because they exploit context, not just content. Attackers borrow a current event, a trusted brand, or a time-sensitive operational issue to lower scepticism and make the request feel normal. That is enough to push hurried recipients into clicking, opening, or paying before they verify the sender or the request.
The tactic also works because business email compromise is often a trust-and-process attack rather than a purely technical one. The message may arrive with believable tone, correct jargon, or a plausible business reason, so the recipient sees a familiar workflow instead of a threat. In practice, that makes social engineering more scalable than brute-force credential attacks.
It is not only the hook that matters, but the follow-through. Once a recipient engages, the attacker can steer them toward credential theft, malware delivery, invoice fraud, or account takeover. For email-based impersonation patterns and payment deception, see Email Identity and BEC Guide, which covers the control points that fail when organisations trust the message instead of the request.
What makes the deception hard to spot
These campaigns work best when they compress time and decision quality. A message about COVID disruptions, policy changes, staffing shortages, or urgent supplier updates creates a sense that delay is costly. That pressure matters because phishing succeeds when a reader substitutes quick recognition for careful validation.
COVID-themed lures also benefit from repeated exposure. People become used to seeing news about outbreaks, travel restrictions, remote-work changes, and health guidance, so an attacker can hide in a stream of genuinely relevant emails. The message does not need to be perfect, only plausible enough that a busy employee treats it as routine.
This is why mailbox compromise, credential theft, and invoice fraud often follow the initial click or reply. If the organisation accepts email as a sufficient trust signal, the attacker can keep the conversation inside a normal business channel. TruffleNet BEC Attack, Stolen AWS Credentials shows how stolen access can be converted into wider compromise once trust has been established.
Why the business impact is so persistent
The persistence comes from the fact that phishing and BEC target weak points in communication and approval flow, not just end users. A single successful message can produce credential reuse, malware execution, data exposure, or an unauthorised payment. In a finance or operations workflow, the harm may be immediate because the attacker is asking for an action that staff are already trained to perform quickly.
Trust is also transferable across systems. If a message appears to come from a known supplier, executive, or service desk, the recipient may extend that trust to attachments, links, or out-of-band payment instructions. That is why these attacks often overlap with mailbox compromise, OAuth abuse, and lookalike domains rather than relying on one technique alone.
Organisations can reduce the effect of these campaigns by tightening email authentication and payment verification. For practical controls around impersonation, mailbox takeover, and payment fraud, Email Identity and BEC Guide is the most direct internal reference for this pattern, while phishing-resistant authentication guidance from NIST SP 800-63 Digital Identity Guidelines helps limit the damage when users are tricked into credential entry.
Risk and Threat Considerations
These messages are attractive to attackers because they exploit urgency, legitimacy, and business process familiarity in one step. The risk is not just that someone clicks a bad link, but that an apparently routine request bypasses the checks that normally protect payments, credentials, and internal communications.
Failure mechanism: The attacker presents a believable event-driven pretext, then uses social pressure, impersonation, or a spoofed workflow to defeat normal review and obtain access or payment.
Impact: The result can be credential theft, mailbox takeover, malware execution, invoice diversion, or unauthorised transfer of funds, often before security teams see a clear technical indicator.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL — Identity Assurance Level | Phishing works by defeating identity trust and credential entry. |
| Recommendation — Use phishing-resistant authentication to reduce credential harvesting from deceptive email. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | BEC and phishing often seek stolen user credentials for access. |
| IA-5 — Authenticator Management | These attacks often depend on stolen or replayed credentials and tokens. | |
| Recommendation — Require strong user authentication and validate high-risk sign-ins. Manage authenticator lifecycle tightly and rotate compromised credentials quickly. | ||
| MITRE ATT&CK | T1566 — Phishing | The subject is explicitly about phishing lures and their effectiveness. |
| Recommendation — Map suspicious email patterns to phishing techniques and tune detection accordingly. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | Email is the primary delivery channel for these lures. |
| Recommendation — Harden email controls and filtering to reduce delivery of deceptive messages. | ||
Practitioner Guidance
What to prioritise: Focus first on the business actions that the attacker wants, not only the message content. If the lure can trigger payment approval, credential entry, or attachment execution, treat it as a high-consequence workflow issue, not just an email hygiene problem.
What to verify: Confirm that staff have a second-channel verification step for supplier changes, payment requests, and any credential prompt that arrives in email. If the process depends on email alone, the organisation is trusting the attacker’s preferred channel.
Common mistake: Training users to “spot suspicious emails” without changing the approval path. Better practice is to make the unsafe action harder to complete, especially for finance and executive workflows that are likely to be targeted.
Practitioner takeaway: The most effective defence is to shrink the number of decisions an email can make on its own, because COVID-themed lures succeed when they inherit trust from the message context instead of earning it through verification.
Related resources from NHI Mgmt Group
- Why do phishing and social engineering remain so effective against Web3 organisations?
- Why do broad phishing, credential stuffing, and password spraying remain effective against modern organisations?
- Why do phishing and fake identities remain so effective against crypto companies?
- Why do AiTM phishing attacks remain effective against SSO environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org