How to Guard Against Proliferating COVID-19 Scams
Privacy, Cyber & AI Decoded Alert | 2 min read
Mar 18, 2020
Risk Management Question
What precautions can lawyers, staff, and law firms take to avoid pandemic-related cyber scams?
The Issue
As the number of attorneys and law firm staff adopting social distancing and working from home increases, so do the related cyber risks. Hackers have well-rehearsed playbooks that seek to exploit distributed workforces using remote connections. As a result, lawyers and staff should be extra vigilant and take additional precautions.
Among other scams, hackers are circulating phony but legitimate looking:
- COVID-19 outbreak maps.
- Emails purportedly from IT teams to employees with the subject line: "ALL STAFF CORONAVIRUS AWARENESS." The emails describe a seminar at which the company will discuss what it's doing in response to COVID-19, which includes a link to register for the seminar.
- Emails claiming to be from vendors about COVID-19 tools and strategies that include links to PDFs and Word Documents and invite the recipient to click and open the attachment.
- SMShing messages closely resembling the employer's phone number, indicating the recipient needs to "click here" to find out about modified firm operations.
These seemingly harmless and legitimate looking emails and attachments are loaded with malware which deploy remote access tools (RAT), keystroke logging malware, desktop image capturing malware, and ransomware. Hackers are looking to potentially gain control of law firm personnel's remote access into the firm, or encrypt computers and anything else the malware can reach.
Risk Management Solutions
Here are several steps lawyers and staff alike can take to protect themselves and their firm:
- Always think before you click.
- Never click on an email or text message from anyone you don't know.
- If you receive an attachment in an email or text message you were not expecting—even if it's from someone you know—call the person at a known telephone number (not the number listed in the message) to confirm the message is legitimate.
- If you click on something you should have avoided and a box opens that asks you for your password, or to supply some information or click on a link to enable a later version of software: stop, close out, and immediately call your IT Department to have a scan run on your device(s).
- Remember the ongoing risk of public Wi-Fi. If you can connect to Wi-Fi without a password, then the network is insecure. Do not use insecure Wi-Fi to connect to your work server, do any personal banking, or send any type of confidential or personal information.
- Avoid working in public spaces where third parties can view screens or printed documents.
Now, more than ever, it's important to follow the classic Hill Street Blues' watch commander's advice: Let's be careful out there.
Related People
Related Capabilities
Featured Insights

In The News
Aug 24, 2026
David Schultz Reviews a Humorous—But Important—FDCPA Procedural Ruling

Press Release
Aug 20, 2026
115 Hinshaw Lawyers Recognized in 2027 Editions of The Best Lawyers in America® and Ones to Watch®

Press Release
Aug 20, 2026
Hinshaw’s Landmark Tower Client Project Receives 2026 Top Projects Award

Press Release
Aug 19, 2026
Fernando Rivera-Maissonet Elected as HNBA Region II Governor and Board of Governors Member

Employment Law Observer
Aug 17, 2026
Massachusetts’ First Paid Family Medical Leave Act Verdict Yields $4.75 Million Award

Press Release
Aug 13, 2026
Lauren Campisi Recognized as a 2026 BTI Client Service All-Star by BTI Consulting Group

Consumer Crossroads: Where Financial Services and Litigation Intersect
Aug 13, 2026
How Will Banks Be Impacted by the Proposed Regulation O Amendments?

Press Release
Aug 12, 2026
William Cook Honored With the Distinguished Service Award by the Chicago Bar Association

Webinar
Aug 12, 2026
John Ryan Presents on "Understanding what is Covered Under the TCPA Today"

In The News
Aug 12, 2026
Scott Seaman Analyzes California’s New Pleading Standards for Excess Insurance Policy Claims



