The U.S. Attorney’s Office for the District of Massachusetts is warning small businesses that received loans through the Paycheck Protection Program (PPP) of a dramatic increase in reports of business email-compromise schemes related to the program. Scammers are using information about PPP recipients posted by the Small Business Administration (SBA) to impersonate PPP lenders requesting additional information about PPP loan applications or loan forgiveness.
In July 2020, the SBA published information about PPP loan recipients, which included business names and addresses for loans greater than $150,000. In December 2020, the SBA released the exact loan amounts for more than 600,000 small businesses and nonprofit organizations that received at least $150,000 in loans. The published data also included the names of entities receiving less than $150,000, which represent about 87 percent of the total number of loans in the program, as well as the name of the lender and distribution date for each loan.
Scammers are using this publicly-available information to send phishing emails to PPP loan recipients, impersonating the recipients’ PPP lenders to request sensitive information, such as email addresses and passwords, Social Security numbers, and financial information. This information could be used to gain access to a business’s computer network to compromise confidential information or for identity theft.
Recipients of PPP loans should carefully review the headers of emails that appear to come from their PPP lenders to ensure that the domain of the sender’s email address matches the domain of other emails received from the lender. They also should use common sense to question whether the lender is likely to be contacting the recipient at that particular time (e.g., in response to an application or loan forgiveness), or whether the timing appears to be unconnected to other communications with the lender. Recipients should not respond to, or click any links, in any suspicious emails; recipients may want to call their lenders if they believe the content or timing of an email is suspicious.
Suspected criminal activity may be reported to the Department of Justice’s National Center for Disaster Fraud at https://www.justice.gov/disaster-fraud.
It has been widely reported that hackers are taking advantage of the pandemic to perpetrate scams and frauds. We have seen attacks against workers of companies through phishing emails that include an attachment or link offering information or access to specialized treatment for COVID-19 to lure people to click on them. Once they click on the link or attachment, the attacker infects the system with malware or ransomware. Cyber criminals know that people are concerned about the coronavirus and looking for more information to protect themselves and their family members, and they also are preying on the distraction of working from home.
It has become such a problem that the Department of Justice (DOJ) instructed the National Center for Disaster Fraud (NCDF) to gather coronavirus-related complaints from the public and assist with information sharing about scams. The NCDF has received more than 76,000 tips on COVID-19 related wrongdoing, and the FBI’s Internet Crime Complaint Center has received more than 20,000 tips about suspicious websites and media postings. This doesn’t include the successful phishing campaigns using COVID-19-related information to trick people into clicking on malicious links or attachments.
The United States Attorney’s Office for the Western District of Louisiana issued a reminder this week for “members of the public to be vigilant against fraudsters who are using the COVID-19 pandemic to exploit American consumers and organizations…In particular, the department is warning the public about scams perpetrated through websites, social media, emails, robocalls, and other means that peddle fake COVID-19 vaccines, tests, treatments, and protective equipment, and also about criminals that fabricate businesses and steal identities in order to defraud federal relief programs and state unemployment programs.”
In addition, the notice states “Moving forward, the department also is concerned about, and will aim to deter and prevent, attempts by wrongdoers to prey upon potential victims by leveraging news about anticipated approval of a COVID-19 vaccine or about the potential enactment of new disaster relief bills that extend or expand upon CARES Act relief.”
The notice is a good reminder to each of us personally as well as employees of the continued threat and to need to remain vigilant to combat these scams. The DOJ “encourages the public to continue to report wrongdoing relating to the pandemic to the NCDF and to remain vigilant against bad actors looking to exploit this national emergency.”