{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff"},"incident":{"title":"WHO impersonation surge during COVID-19 targets donors and staff","date":"2020-04-23","date_precision":"day","victim_org":"World Health Organization and the general public (multi-victim campaign)","sector":"Healthcare","country":"Global","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in 2020.","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_note":"WHO did not publish a total for donations diverted by impersonators.","records_affected":450,"threat_actor":null,"summary":"On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.","how_it_worked":"Attackers exploited the single most trusted authority of the moment. Emails carrying WHO branding promised guidance on the outbreak and asked recipients to click through to a credential capture page or open an attachment, and separate campaigns solicited donations to a fake version of the COVID-19 Solidarity Response Fund or issued invoices purporting to come from it. The lever was fear plus civic goodwill under acute uncertainty, when recipients were actively seeking official pandemic information and wanted to help. The leaked credentials came from an older extranet system used by current staff, retired employees and partners.","lessons":"Legacy extranets holding partner credentials must be retired or moved behind modern multi-factor authentication, and public-facing agencies should publish a single authoritative donation channel to make impersonation obvious.","confidence":"Confirmed","sources":[{"title":"WHO reports fivefold increase in cyber attacks, urges vigilance","url":"https://www.who.int/news/item/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance","publisher":"World Health Organization"},{"title":"Cyber security: beware of criminals pretending to be WHO","url":"https://www.who.int/about/cyber-security","publisher":"World Health Organization"}],"entry_type":"campaign","slug":"2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff"}}