Cyberwall Blog · February 5, 2021

Top 5 Cyber Security Attacks on the Rise During the COVID-19 Pandemic

The sudden shift to remote work gave attackers a wider target. Here are the five attack types that spiked as offices emptied out.

By Alex Plotkin, CEO

When offices emptied out and remote work became the default almost overnight, attackers noticed the gap before most security teams could close it. IT teams that had spent years hardening a defined office perimeter suddenly had to secure a workforce logging in from home routers, personal laptops, and whatever internet connection happened to be available, all at once and with little lead time to plan it properly. A few attack types spiked as a result:

  1. Phishing emails: spoofed messages designed to get employees onto malicious sites or to hand over credentials directly, often dressed up as pandemic related communications. Attackers moved fast to exploit the moment, sending messages posing as health authorities with “urgent updates,” fake relief or benefits payment notices, and imitation IT department emails about new remote access tools or VPN setup instructions employees had no reason to doubt given how much legitimate guidance was also circulating at the time. The core trick wasn’t new, but the pretext was perfectly timed: people were anxious, distracted, and actively expecting unusual instructions from employers and institutions, which is exactly the emotional state phishing is designed to exploit.
  2. Malicious mobile and desktop apps: trojanized software quietly harvesting banking details, personal information, or business credentials once installed. As demand spiked for video conferencing tools, remote access software, and even contact-tracing style apps, attackers built or repackaged lookalike versions bundled with malware, counting on people downloading in a hurry from an unofficial source rather than verifying a legitimate vendor.
  3. Ransomware: increasingly systematic in how it spread across networked systems, with the added threat of leaking stolen data if the ransom wasn’t paid. This was also the period when double extortion became standard practice among ransomware operators: encrypting a victim’s files was no longer enough on its own, since a well-prepared organization could just restore from backup, so attackers began exfiltrating data first and threatening to publish it regardless of whether the ransom got paid. Healthcare and other organizations under acute operational strain during this period were particularly attractive targets, since any downtime carried an outsized cost that made a quick ransom payment look more tempting.
  4. Password based attacks: weak or reused passwords giving attackers a foothold that spread across multiple accounts and systems. Remote work pushed a lot of organizations to expose remote desktop and VPN access to the internet faster than they’d normally roll it out, and attackers responded with a sharp rise in automated login attempts against those newly exposed entry points, testing stolen or guessed credentials at scale until one worked. A single reused password on an internet-facing login was often all it took to get a foothold that then spread laterally once inside.
  5. AI assisted attacks: an early look at how automated tools were starting to help attackers gather intelligence and target their attempts more precisely. Rather than sending the same generic lure to thousands of addresses, automated tools helped attackers scrape publicly available information, personalize messages to specific roles or individuals, and identify which targets were most likely to respond, an early preview of the far more convincing, harder-to-spot social engineering that has continued to mature since.

The common denominator was distance: without the guardrails of an office network, individual employees became the front line, and the tools that used to catch a bad link or a suspicious login on the way into the building simply weren’t in the path anymore. Traffic that used to flow through a corporate firewall and a monitored internal network was now going straight from a home router to the public internet, which meant a lot of the visibility security teams had relied on simply disappeared overnight, right when the number of remote endpoints to protect went up just as sharply.

The response looked the same across all five: ongoing staff training that reflects how people are actually being targeted rather than a generic annual refresher, regular risk assessments to catch newly exposed remote access points before attackers find them, multi factor authentication on every login that matters so a stolen password alone isn’t enough, and a security team that can actually keep pace with how fast the threat landscape was moving rather than reacting to it months later.

What’s worth noting in hindsight is that almost none of this reversed once offices reopened. Remote and hybrid work stuck around for a large share of organizations, which means the wider, more distributed attack surface these five categories exploited didn’t shrink back down, it became the new normal baseline to defend. An organization that treated its pandemic-era remote access rollout as a temporary fix rather than a permanent part of its environment is very likely still carrying gaps from that rushed setup today, whether that’s VPN configurations that were never hardened, endpoint protection that never made it onto every personal or hybrid device, or access policies that still assume everyone is sitting behind an office firewall. Email and browser security is the front line for the first two on that list.

Related reading: The Weakest Link in Your Defense · Importance of Cybersecurity Awareness Training

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.