Why the holiday period is a hot spot for cyber-crime | #cybercrime | #infosec


ISJ hears exclusively from Adrian Podkaminer, Head of Security for G2A.com about how the holidays influence cybersecurity scams.

Why does the summer holiday season create a favourable window for business scams and cyber-attacks?

The summer holiday season can create favourable conditions for business scams and cyber-attacks because several risk factors often converge at the same time.

Reduced staffing can slow detection and response, as fewer employees may be available, escalation paths may be less straightforward and security or finance teams may be operating with reduced coverage.

Threat actors have long been known to take advantage of nights, weekends and holiday periods when organisations may be less able to respond quickly.

There is also a clear historical pattern of high-profile incidents occurring around holiday weekends, reinforcing the view that attackers pay close attention to timing.

Examples include the JBS ransomware attack over Memorial Day weekend in 2021, the MOVEit exploitation wave over Memorial Day weekend in 2023, the Kaseya attack over Independence Day weekend in 2021 and the Los Angeles Unified School District attack over Labor Day weekend in 2022.

In addition, employees covering for colleagues may have less context about normal vendor relationships, invoice timing, approval chains, or the communication styles of internal stakeholders.

This lack of day-to-day familiarity can make it harder to identify unusual requests, particularly because a large share of breaches still involves a human element, including error and social engineering.

Seasonal distractions can also increase susceptibility to scams, as summer often involves travel bookings, personal schedule changes, family logistics and back-to-school planning.

Attackers may use these seasonal themes in phishing campaigns because they attract attention and can lower employees’ caution, with travel-related scams, fake booking confirmations and holiday-themed messages all potentially being used to lure employees into clicking malicious links or disclosing information.

Finally, lighter staffing and the absence of key decision-makers can give attackers more time to operate unnoticed, allowing suspicious activity to take longer to escalate and giving threat actors additional time to move through systems, compromise accounts or interfere with payment processes before someone intervenes.

In short, summer does not create new cyber-risks on its own; rather, it can amplify existing weaknesses in staffing, process oversight and human attention.

AI-generated emails and voice cloning are among the major scams impacting businesses. What advice would you give to employees who are covering for a colleague when it comes to spotting a scam?

This is one of the most important risk scenarios for businesses today.

Someone covering for a colleague can be particularly vulnerable to an AI-enabled scam because they may not have the usual context that helps them identify whether a request is normal or suspicious.

The key advice is simple: do not rely on instinct alone; rely on verification.

The first step is to assume that even a highly convincing message could be fraudulent.

AI has made scam emails, messages and voice calls more polished and persuasive, meaning poor spelling, awkward phrasing or obvious mistakes are no longer reliable warning signs.

A fraudulent request may look professional, sound credible and appear to come from a familiar senior executive or trusted supplier.

When dealing with requests involving money, credentials or sensitive information, always verify the request through a separate, trusted channel.

If you receive an email, message or call asking for a payment, a change to bank details, login information, payroll data or confidential business information, do not act on the original communication alone.

Instead, verify the request using a trusted phone number, an existing contact record, or another authorised internal approver.

There are several warning signs that should prompt additional scrutiny:

  • Urgency and secrecy: Requests such as “This must be done today,” “I need this before close of business,” or “Do not discuss this with anyone else” are designed to create pressure and discourage verification. Even a genuinely urgent request should be able to withstand a short verification step
  • Unfamiliar sender details: Do not rely on the display name alone. Check the full email address, domain name, links, and attachments carefully. Small differences, such as an extra character, a substituted number, or an unfamiliar domain, can indicate impersonation
  • Voice calls and virtual meetings: AI-generated voice cloning and impersonation attempts are now realistic enough that hearing a familiar voice is no longer sufficient proof of identity. For higher-risk requests, teams should agree in advance on a callback process using pre-established phone numbers, never numbers provided in the suspicious request. For authorisations above defined thresholds, organisations may also consider requiring in-person verification

If you are covering for a colleague, preparation is particularly important.

Before they go on leave, make sure you have a clear understanding of which vendors may contact you, which payments are expected, who can approve exceptions, and which phone numbers or contact details are trusted for verification.

Working from a simple checklist can make it much easier to identify something unusual when you are operating outside your normal responsibilities.

Finally, when in doubt, pause. It is always better to delay a payment or request briefly while you verify it than to rush and make a costly mistake.

A short delay is manageable; fraud losses, reputational damage, and incident response costs are not.

What are the biggest red flags businesses should look out for when it comes to invoice and payment fraud?

Invoice and payment fraud often succeeds because the request looks routine. The most effective defence is to know which warning signs should trigger immediate verification, such as:

Sudden changes to payment instructions or bank account details

  • This is one of the clearest red flags
  • If a vendor suddenly asks for payment to a new account, especially by email, that request should always be verified through a trusted secondary channel before any money is sent

Pressure to act quickly or bypass normal approvals

  • Fraudsters often create urgency to stop people from following procedure
  • Messages that insist on same-day action, confidentiality or executive pressure should be treated with caution, particularly if they involve payments or data disclosure

Slight differences in sender addresses or domains

  • A fraudulent message may come from an address that looks almost correct at first glance
  • One changed character, a different domain ending, or a lookalike invoice portal can be enough to fool a busy employee

Unusual payment destinations or jurisdictions

  • If a long-standing supplier suddenly asks to be paid through a different country, bank or account structure than usual, that is a significant anomaly and should be verified independently

Invoices that fall outside the normal billing pattern

  • A request that arrives earlier than expected, duplicates a recent invoice, appears outside the usual billing cycle, or does not match the agreed purchase history deserves closer inspection

Small but important changes in the invoice itself

  • Fraudulent invoices may look highly convincing, but details such as the company name, legal entity, tax number, banking coordinates, invoice numbering pattern, formatting or wording may differ slightly from previous legitimate invoices

Requests sent to someone who would not normally handle them

  • During holiday periods in particular, fraudsters may target whoever is covering the finance function, assuming that person is less familiar with normal patterns and contacts

The best response is not to rely on a single red flag, but to treat unusual payment requests as process exceptions.

If anything about the request is different, verify it before funds are released.

And if a fraudulent transfer is discovered, the organisation should contact its financial institution immediately and escalate internally without delay.

What is the five-minute security check every employee should complete before leaving the office to go on holiday?

Every employee should complete a short security check before going on leave.

It does not need to be complicated, but it should be deliberate and cover the key areas where risk can arise.

Start by securing your workstation: lock your screen and leave your device in the state required by your company’s IT policy.

In some organisations, this may mean shutting it down, while in others it may mean leaving it connected for monitoring, patching or updates.

The important point is that the device is not left exposed or accessible.

Next, set a minimal out-of-office message that provides only the information people need.

State that you are away and, if necessary, provide a team mailbox or alternate contact, but avoid oversharing details such as travel plans, personal phone numbers or unnecessary information about internal coverage arrangements.

If someone is covering for you, hand over critical work securely by providing a brief summary of expected vendor contacts, pending approvals, time-sensitive tasks and any known risk areas.

Include verified contact details for key people and make clear that payment instructions or bank detail changes must never be accepted based on email alone.

You should also clear and secure any sensitive material by following a clean-desk approach: put away confidential documents, remove sensitive printouts, secure notebooks and never leave USB drives, external storage devices, or company badges unattended.

Finally, sign out of shared systems and browsers where appropriate. If you work in a shared or hot-desk environment, log out of email, finance platforms, CRM tools, collaboration applications and browser sessions so that others cannot access your accounts.

Taking five minutes to complete these checks can significantly reduce risk across four practical areas: device security, information disclosure, workflow continuity and access control.

How can organisations build stronger cyber-resilience during periods of reduced staffing and how do they keep these measures effective throughout the rest of the year?

This is the most important question strategically, because reduced staffing does not create entirely new problems; it exposes the weaknesses that already exist. The goal should therefore be to build resilience that works all year, rather than relying on seasonal measures that are only introduced during the summer.

Organisations should start by cross-training critical roles and documenting coverage clearly, avoiding situations where essential knowledge sits with a single person.

Critical functions such as payment approvals, vendor verification, incident escalation and access administration should always have backup coverage, with those arrangements documented, reviewed regularly, and easy to use when someone is away.

Organisations should also maintain and regularly test an incident response plan.

A response plan is only useful if people know how to use it under pressure, so escalation paths, communication procedures, decision-making authority and external contact lists should be tested regularly, including scenarios where key leaders or technical staff are unavailable.

At the same time, strong approval controls should remain in place for sensitive transactions.

Reduced staffing is not a reason to weaken controls; if anything, it is a reason to make high-risk actions more structured.

Wire transfers, payroll changes, vendor bank-detail updates, and access changes should require clear approvals and verification steps, particularly when normal staff are absent.

Organisations must also ensure that security monitoring continues to work outside normal business hours.

Threats do not wait for office hours, so logging, alerting, endpoint protection and escalation processes should remain effective during evenings, weekends and holidays.

Automated controls can help, but only when they are properly configured, regularly reviewed and supported by people who know how to respond when an alert is triggered.

Before major holiday periods, organisations should also establish a pre-holiday readiness routine that includes reviewing open vulnerabilities, confirming backup status, checking contact lists, reminding staff about phishing and payment fraud risks and confirming who is responsible for key operational decisions during absences.

A short readiness review can prevent confusion at exactly the wrong time.

These practices should ultimately be embedded into normal operations rather than treated as seasonal extras.

Organisations should review coverage arrangements regularly, test response procedures on a recurring basis, tune security alerts over time and include staffing-related risks in ongoing security governance discussions.

Just as importantly, they should reinforce a culture where verification is normal.

Technology matters, but culture matters just as much. Employees should feel supported when they pause a payment, question an unusual request or escalate a suspicious message.

A resilient organisation is one where verification is seen as good judgement, not obstruction.

Ultimately, strong cyber-resilience during holiday periods comes from mature day-to-day operations.

If an organisation can function securely when key people are away, it is usually a sign that its controls, processes and culture are genuinely robust.

If security depends on everyone being at their desk, the organisation has work to do.



Click Here For The Original Source.

——————————————————–

..........

.

.