Have You Been a Victim of COVID-19-Related Cyber Incidents? Survey, Taxonomy, and Mitigation Strategies

IEEE Access. 2020 Jun 30:8:124134-124144. doi: 10.1109/ACCESS.2020.3006172. eCollection 2020.

Abstract

Cybercriminals are constantly on the lookout for new attack vectors, and the recent COVID-19 pandemic is no exception. For example, social distancing measures have resulted in travel bans, lockdowns, and stay-at-home orders, consequently increasing the reliance on information and communications technologies, such as Zoom. Cybercriminals have also attempted to exploit the pandemic to facilitate a broad range of malicious activities, such as attempting to take over videoconferencing platforms used in online meetings/educational activities, information theft, and other fraudulent activities. This study briefly reviews some of the malicious cyber activities associated with COVID-19 and the potential mitigation solutions. We also propose an attack taxonomy, which (optimistically) will help guide future risk management and mitigation responses.

Keywords: COVID-19; cyberattacks; mitigation; potential solutions; security and privacy; taxonomy.

Grants and funding

This work was supported in part by the University of Northern British Columbia under Grant FUND 15021 ORG 4460, and in part by the Deanship of Scientific Research (DSR) at King Saud University through research group project under Grant RG-1439-036.