Scammers want your stimulus check: Here’s how to stop them

IRS stimulus checks
(Image credit: Future)

"Where's my stimulus check?" is now one of the most popular questions on Google, and if you're not careful, the answer will be, "in the hands of a cybercriminal." Cybersecurity firm Check Point Research spotted an upsurge of malicious domains targeting Americans questioning the whereabouts of their COVID-19 payment relief.

During March and the first week of April, more than 2,500 new domains related to the IRS stimulus check roll out were registered. Check Point Research spotted a massive spike during the week of March 16, when the stimulus package was initially proposed to taxpayers.

"The number of new domains registered that week was 3.5 times higher compared to the average of previous weeks," the report said.

Of those 2,500 new domains, more than 700 of them raised alarm bells on analysts' radar as potential cyber threats to unwitting, internet-surfing victims.

IRS stimulus package

(Image credit: Check Point Research)

In a recent blog, Google also announced concerns about the uptick of cybercriminal activity. During the second week of April, the search-engine giant discovered more than 18 million malware and phishing emails related to COVID-19 daily -- this is on top of the daily 240 million coronavirus-related spam messages Google spotted during that same time frame.

"The phishing attacks and scams we’re seeing use both fear and financial incentives to create urgency to try to prompt users to respond," Google wrote. The tech giant posted an example of a hacker capitalizing off the stimulus check roll out with an email titled, "COVID-19 Payment."

IRS stimulus check

(Image credit: Google)

Check Point Research also posted an example of their phishing discoveries. In one email, the cybercriminal goaded an internet user to click "Reconfirm," which led him or her to a new window that prompted the disclosure of one's personal information. The cybersecurity firm found malicious threats such as AgentTesla, which is a password-stealing malware program, and Zeus Sphinx, a Trojan that's used to snatch online banking credentials.

(Image credit: Check Point Research)

"These threats are not new," Google wrote. "Rather, they’re existing malware campaigns that have simply been updated to exploit the heightened attention on COVID-19." But Google assured Gmail users that its new AI malware scanners help filter out 99.9% of spam, malware and phishing attempts. 

Taking the best tips from Google's recent blog and Check Point Research's report, here's how you can protect yourself from falling into a cyber-threat trap:

  • Double-check suspicious attachments. Use Gmail's built-in document preview.
  • Beware of spelling errors in emails or websites. This is a tell-tale sign that you're looking at a cybercriminal's bait -- do not fall for it.
  • Be cautious of emails prompting you to take unusual actions. This could be a cybercriminal masquerading as a legitamate website to phish for your personal information.
  • Never order goods from promotional links in emails. You're better off Googling your desired retailer and clicking the official website from the results page.
  • Do not reuse the same password. If hackers get a hold of your "master key" password from one data breach, they can gain access to all your other accounts.

Google also advised users to enroll in their Advanced Protection Program (APP)— the tech giant claims that everyone who's participated in the program has never been successfully phished, even if they've been repeatedly targeted. 

Kimberly Gedeon

Kimberly Gedeon, holding a Master's degree in International Journalism, launched her career as a journalist for MadameNoire's business beat in 2013. She loved translating stuffy stories about the economy, personal finance and investing into digestible, easy-to-understand, entertaining stories for young women of color. During her time on the business beat, she discovered her passion for tech as she dove into articles about tech entrepreneurship, the Consumer Electronics Show (CES) and the latest tablets. After eight years of freelancing, dabbling in a myriad of beats, she's finally found a home at Laptop Mag that accepts her as the crypto-addicted, virtual reality-loving, investing-focused, tech-fascinated nerd she is. Woot!

Latest in Antivirus & Cyber-security
TP-Link routers targeted by Chinese state-sponsored cyber attacks
TP-Link routers may face nationwide ban after 'significantly alarming' link to US cyberattacks
What is a VPN kill switch — and why you should use one
You need a VPN for school, here are 3 services we recommend
The AMD Ryzen and NVIDIA RTX stickers on the Acer Nitro 17
'You basically have to throw your computer away': Researchers explain AMD 'Sinkclose' vulnerability, but do you need to worry?
Google Search
This malware is posing as Google Authenticator using Google ads — here's how to protect yourself
Windows 10 BSOD saying "It's not you, it's me."
Microsoft reveals CrowdStrike outage could have a surprising long-term impact on everyday users
MANILA, PHILIPPINES - JULY 19: Long queues of passengers form at the check-in counters at Ninoy Aquino International Airport, amid a global IT disruption caused by a Microsoft outage and a Crowdstrike IT problem, on July 19, 2024 in Manila, Philippines. A significant global outage affecting Microsoft services, particularly Microsoft 365, has caused widespread disruptions across various sectors, including airlines, banks, and health systems. The outage was attributed to a glitch in CrowdStrike's "Falcon Sensor" software, which impacted Windows systems, leading to thousands of flight cancellations and operational chaos in multiple industries. Microsoft has reported that the underlying cause of the outage has been fixed, but residual effects continue to impact some users as the company works on full recovery. (Photo by Ezra Acayan/Getty Images)
The CrowdStrike outage spotlights major vulnerabilities in the global information ecosystem
Latest in News
WWDC 2025 could mark the beginning of the end for certain iPhone users
Error when installing Google Chrome on the Asus Vivobook 16 Flip, on a white desk against a blue background.
"This app can't run on your PC": Google's Chrome Installer broke on Windows, but there's a fix
Nintendo Switch 2 handheld gaming console
Nintendo Switch 2 preorder date: It might be a lot closer than you think, say tipsters
Microsoft Surface Laptop (7th Edition, 2024)
Windows-on-Arm woes: Amazon warns customers about Surface laptop returns
Apple Watch Series 8
Siri is the biggest obstacle to making the Apple Watch an AI hit
The Lenovo Legion Go S in hand running Death's Door in front of a wood table
The Lenovo Legion Go S is a Z1 Extreme trap you'll want to avoid — Here's why