Back to all lessons
Awareness Lessons
3 months ago

Earthquake Relief Scams: 212 Fake Domains Exploit Disaster Urgency

Cybercriminals rapidly registered 212 domains mimicking legitimate Venezuela earthquake relief efforts, exploiting public goodwill and the urgency of disaster situations to solicit fraudulent donations or harvest personal information. The root cause is a lack of public security awareness about how scammers weaponize breaking news events to create convincing but fraudulent campaigns. Opaque domain registrant information (WHOIS privacy) further obscures accountability, making it difficult for donors to distinguish legitimate charities from imposters. This matters because victims not only lose money but may also expose sensitive financial and personal data to threat actors. Disasters create time pressure that short-circuits critical thinking, making user education and proactive warnings essential countermeasures.

Tactical Insight

Immediate actions

  • Verify any donation site against official charity registries (e.g., IRS Tax Exempt Organization Search, Charity Navigator) before contributing.
  • Report suspicious disaster-relief domains to ICANN, national cybercrime units, or the domain registrar directly.

User awareness measures

  • Train employees and the public to recognize urgency-based social engineering tactics commonly deployed after major news events.
  • Distribute internal security advisories whenever a major disaster or breaking news event occurs, warning staff about likely phishing and scam surges.

Long-term improvements

  • Establish a process for security teams to monitor new domain registrations related to major organizational or world events using threat intelligence feeds.
  • Partner with brand-protection services to detect and initiate takedowns of domains impersonating your organization or known legitimate charities.
  • Incorporate disaster-scam scenario training into annual security awareness programs to build lasting skepticism habits.