Fraudsters Target Those Signing Up for Health Insurance
Open enrollment has begun for Obamacare as well as for health insurance plans offered by many employers. And that means it’s prime time for fraudsters to target consumers with phishing scams, disguised as official-looking open enrollment messages, in an attempt to steal personal information.
Privacy and security experts stress the need to remind those participating in open enrollment about the dangers of phishing, including avoiding clicking on links in suspicious e-mails that bring individuals to fake websites designed to gather information.
“Open enrollment is just one of the mechanisms fraudsters use to scam people, and it often comes down to education and awareness to prevent that,” says David Kennedy, CEO of TrustedSec, a security consulting firm.
Health Benefits Ploy
The open enrollment scams typically involve e-mails that purport to be official communications about health insurance but link the user to a fake employee or government web portal designed to collect personal information that can be used to commit fraud. In some cases, simply clicking to open the e-mail or a link it contains can lead to an immediate malware infection, Kennedy says.
“People freak out when they receive e-mails about their health benefits or new regulations, and the possibility of losing [coverage] if they don’t act,” Kennedy says. That’s why so many consumers fall for the ploys.
In addition to spear-phishing e-mails targeting employees at specific companies during open enrollment season, scammers are also targeting consumers who are interested in shopping for insurance on new state health insurance exchanges and seniors looking for supplemental Medicare plans.
Security firm TrendMicro reports that even before new state health insurance exchanges under Obamacare launched on Oct. 1, scammers began sending consumers spam containing the terms “Medicare,” “enrollment” and “medical insurance.” The spam contained links taking users to nefarious websites containing surveys asking for personal information in exchange for a chance to win prizes, such as iPhones, TrendMicro explains in a blog about phishing.
Steps to Take
To prevent employees from becoming victims of these scams, organizations must educate them to avoid opening e-mail from unrecognized senders and refrain from opening attachments or clicking on links that look suspicious.
Companies can also use security controls, such as Internet filtering, that prevent employees from accessing unauthorized sites, Kennedy says.
But that tactic typically only works with company-issued devices, says Robert Siciliano, an online security expert at security vendor McAfee. If individuals are using their personal devices to read e-mail in their corporate account, for instance, corporate Internet filtering generally won’t stop them from accessing an unauthorized or fake website via a link, he points out.
Employers also should take the extra step of alerting employees in advance that the company, or its outside benefits contractor, will be sending employees messages about open enrollment information, Kennedy says.
Another important step is to remind employees to notify the IT team or other company officials when they receive suspicious e-mails.
Siciliano says basic security measures, such as keeping web browsers, anti-malware software, and firewalls updated, also can help fight phishing attacks.
J.D. Sherry, a vice president at TrendMicro, says companies should also remind employees to be mindful of scams on social media. That includes professional networking sites such as LinkedIn, where there have been incidents of fraudsters posting false profiles in attempts to entice individuals to disclose information about themselves or to access corporate systems.
“We’re seeing an uptick in incidents around social media,” he says. Fraudsters try to use the “trust factor” of social media sites to trick individuals, he says.
And while open enrollment is a favorite season for fraudsters to use phishing to prey on unsuspecting users, Siciliano says it’s important to remember that cybercriminals will look for any occasion to benefit from their scams.
