Security News > 2020 > November > Phishing lures employees with fake 'back to work' internal memos
Scammers are trying to steal email credentials from employees by impersonating their organization's human resources department in phishing emails camouflaged as internal 'back to work' company memos.
These phishing messages have managed to land in thousands of targeted individuals' mailboxes after bypassing G Suite email defenses according to stats provided by researchers at email security company Abnormal Security who spotted this phishing campaign.
There is a high probability that some of the targets will fall for the scammers' tricks given that during this year's COVID-19 pandemic most companies have regularly emailed their employees with updates regarding remote working policy changes.
Phishing emails delivered through this campaign spoof the victims' company mail service and are designed to look like automated internal company memos with attached voicemails.
An added tactic used to make sure that the victims will provide their email credentials is the addition of an alert under the phishing form telling them to never give out their passwords to people they don't trust.