Security News > 2021 > April > US DOJ: Phishing attacks use vaccine surveys to steal personal info

The US Department of Justice warns of phishing attacks using fake post-vaccine surveys to steal money from people or tricking them into handing over their personal information.
"Consumers receive the surveys via email and text message and are told that, as a gift for filling out the survey, they can choose from various free prizes, such as an iPad Pro," the DOJ said.
The DOJ Office of Public Affairs recommends avoiding clicking on links received via text messages or emails claiming to be a vaccine survey if they come from unknown and unverified sources.
Consumers who have received one of these fraudulent phishing emails or text messages using COVID-19 vaccine survey lures are urged to report such incidents to the National Center for Disaster Fraud via the NCDF Web Complaint Form or by calling 866-720-5721.
New York's Department of Financial Services also revealed additional details on an ongoing series of attacks that have already resulted in the theft of private info belonging to hundreds of thousands of New Yorkers.
To protect yourself from identity theft attempts, you can get an Identity Protection PIN ASAP to block identity thieves from filing fraudulent tax returns in your name using your stolen personal information.
News URL
Related news
- Phishing platform 'Lucid' behind wave of iOS, Android SMS attacks (source)
- iOS devices face twice the phishing attacks of Android (source)
- China names alleged US snoops over Asian Winter Games attacks (source)
- Windows NTLM hash leak flaw exploited in phishing attacks on governments (source)
- Three Reasons Why the Browser is Best for Stopping Phishing Attacks (source)
- Phishing detection is broken: Why most attacks feel like a zero day (source)
- DPRK Hackers Steal $137M from TRON Users in Single-Day Phishing Attack (source)
- Low-tech phishing attacks are gaining ground (source)
- Ukrainian extradited to US for Nefilim ransomware attacks (source)
- MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks (source)