Skip to main content
  1. Home
  2. Computing
  3. News

New COVID-19 phishing emails may steal your business secrets

Add as a preferred source on Google

Google Forms are being used as a way to obtain the sensitive information of business owners through COVID-19 phishing emails, according to a new report.

As reported by Bleeping Computer, phishing messages based on COVID-19 have started to become increasingly popular in recent weeks.

Woman Checking Her Email
Guido Mieth / Getty Images

Email security firm INKY shared the findings of an upcoming report it is due to publish with Bleeping Computer. It found that the amount of malspam (malicious spam emails) doubled during September alone when compared to the summer period (June to August). Such attacks are expected to become more prevalent moving forward.

Recommended Videos

The phishing emails in question pretend to be from the U.S. Small Business Administration (SBA), which uses the Google Forms platform in order to host phishing pages. The objective of these pages is to steal the personal details of business owners who fill in their information.

Although the government program has provided COVID-19 financial recovery services in the past, SBA is not doing so at the moment with the pandemic slowing down.

In any case, the phishing emails highlight how individuals can still qualify for programs such as the “Paycheck Protection Program,” the“Revitalization Fund,” and “COVID Economic Injury Disaster Loan.” Contained within the email is a button that redirects targets to a Google Forms page.

The phishing forms attempt to appear as a trusted source by duplicating information deriving from past SBA financial support programs, with applicants asked to largely share the same details. Information pertaining to Google account credentials, SSNs, EINs, State ID and driver’s license details, and bank account numbers are all requested by the page.

A COVID-19 phishing email.
Image source: Bleeping Computer/INKY Image used with permission by copyright holder

Once the information is filled in and the submit button is clicked by the user, a “Your response has been recorded” message is displayed. In reality, however, all the corresponding data is sent directly to the threat actors.

With winter approaching, COVID-19 infections could be subjected to a considerable rise, which allows cybercriminals to use the opportunity to lure in unsuspecting business owners.

At the height of the pandemic, Google was blocking 18 million coronavirus scam emails on a daily basis.

As for this particular campaign, there are clear indicators that it’s a phishing attempt. As pointed out by Bleeping Computer, ​​the phishing emails redirect users toward a Google Forms page, while the SBA would request the submission of information through its official website instead. The emails, meanwhile, feature grammatical errors as well.

As always, if you are a business owner — especially one that has received monetary relief from COVID-19 programs before — be sure to carefully check any suspicious emails claiming to be from the SBA.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt
The price hike could touch every Snapdragon-powered device category.
The new Qualcomm Snadragon 8 Elite Gen 5

I want you to sit with this for a second. Qualcomm, the company whose Snapdragon chips sit inside your Android phone and tablet, your Windows laptop, your Meta smart glasses, your Galaxy Watch, and your wireless earbuds, reportedly sent a letter to every major customer telling them prices are going up by double digits. 

The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price. 

Read more
Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school
One plug, zero drama, all your devices charged by morning.
Satechi ChargeView

Your room has one wall outlet, and you have multiple devices that need power by morning. Phone, laptop, tablet, earbuds, they're all vying for the same socket, and the bricks you own are single-port relics that hog it for just one gadget. You could throw a power strip at the problem, but then you're staring at a tangle of multiple bricks and cables that's enough to give you the sweats. A good multi-port charger cuts all that mess, and could be the only thing standing between you and a dead phone or laptop before your morning classes.

Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.

Read more
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
OpenAI’s rogue AI has come back to bite it
OpenAI logo on Microsoft surface

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

Read more