During the festive season, we all tend to be more cheerful, more relaxed, and indeed busier. Unfortunately, these factors can lead to us lowering our guard against suspicious online activity, meaning that December is a high-risk period for scams and phishing. In this blog, the Lucid team have put together a list of tips on the most common types of Christmas cybercrime, and how we can help you to protect your business from the people on Santa’s Naughty List.
1. Phishing and Email Scams
This is perhaps the most well-known form of security breach. A scammer will send an email asking for the recipient to input sensitive information, or click on a link that contains malware, under the guise of a plausible scenario. For example, common email scams reported around Christmas include links to seasonal discounts and offers, surveys to win gift cards for Christmas shopping, and links to supposedly track a package delivery.
2. QR Code Malware (Quishing)
At Lucid, we always warn our clients that phishing scams evolve quickly, particularly in response to developments in technology. Quishing, or QR code phishing, is an example of scammers using new methods to attempt to install malware on your devices or retrieve sensitive data. Your employees might see a QR code on a Christmas-themed poster and scan it with their work-issued mobile phone, or perhaps receive a QR code in an email they do not recognise — within seconds your data could be compromised.
3. Christmas E-Card Scams
Sending festive greetings via email is a fantastic way to spread cheer amongst your coworkers for free, so many people will receive e-cards to their work inbox during the holidays. Scammers are aware of this, and there have been many examples of malware or phishing links being embedded into e-cards.
How Can Lucid Help?
The Lucid team would like to encourage every business to offer their staff additional cybersecurity training this Christmas — it really is the gift that keeps on giving. Our LucidSecure programme offers bite-sized chunks of cyber training, and also generates random, completely safe test emails for your staff. They will receive emails created by us that display features that they should identify and report as suspicious; on the other hand, if they interact with the test email, our team is notified so that we can follow up with further support and education. We also offer encryption and protection services, penetration testing, cybersecurity audits, and threat detection. Partnering with Lucid allows your business to benefit from our decades of cyber security and IT outsourcing experience all year round, ensuring that the only mysterious intruder your business receives this December is Santa!
For more information about working with Lucid, you can contact our team here.
Sources:

