Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - Steps to Avoid a Cybercrime Slam Dunk During March Madness
Attacks Latest News News & Analysis Phishing

Steps to Avoid a Cybercrime Slam Dunk During March Madness

Adam ParlettBy Adam ParlettMarch 17, 2025Updated:March 17, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
March Madness
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

For many, March signifies the spring equinox, daylight savings, and the celebration of St Patrick’s Day. For American sports enthusiasts, however, one event sits at the forefront of their thoughts – March Madness. Sadly, as with many high-profile sporting events, opportunistic cybercriminals also anticipate the event. 

March Madness centers around the NCAA Division I Men’s and Women’s basketball tournaments and features 68 teams in a single-elimination format that narrows down to crown four champions by the end of the month. It certainly provides drama on the court – but how can supporters avoid organizations avoid unnecessary upset off of it?  

Action and Opportunity 

March Madness is one of the most-watched sporting events in the US because of the high-stakes format, the sheer volume of games, and the fact that it’s the only major sporting event in the US where some games traditionally take place during business hours in the working week. The prospect of having a large audience seeking to obtain a coveted ticket, tuning in to watch the game, or looking to take advantage of promotional offers presents some juicy low-hanging fruit for cybercriminals. 

Scammers often create convincing copies of event pages to promote fake ticket sales, setting up fraudulent websites or social media profiles claiming to sell legitimate tickets. Accounts or websites like these mimic legitimate ticket vendors by copying their branding and imagery while enticing fans with promises of dramatic discounts. Following payment, buyers either receive no tickets or get counterfeit ones with incorrect serial numbers or barcodes that are invalid for entry. 

Not all apps or sites offering to stream games or provide related offers are legitimate; some are designed to install malware and steal data from mobile devices. This is of particular concern to organizations because, as some games are taking place during working hours, corporate networks may be impacted. If it all seems too good to be true, it probably is. 

A Risky Wager 

The American Gaming Association (AGA) has predicted that an estimated $3.1bn will be gambled by Americans during March. In addition to the advice detailed above relating to authentication, it is also essential that any betting sites you or your workplace pool intend to use operate security practices like multi-factor authentication (MFA). 

Kaushik Devireddy, Senior Product Manager at Deepwatch, expects malicious actors will look to “craft phishing emails and notifications for bonus bets impersonating betting platforms with the imagery/likeness of March Madness players. Their goal with these attacks will be to gain access to betting accounts which contain deposited funds, as well as bank account linkages.” 

Staying Safe 

Cybersecurity experts are acutely aware of the threats accompanying March Madness and have some important advice to beef up your defense away from the court.  

J Stephen Kowski, Field CTO at SlashNext, advocates for “Modern email security with real-time phishing detection can identify these threats at the point of click, protecting users whether they’re participating in office pools or exploring betting platforms.” 

Chris Gray, a field CTO who also operates at Deepwatch, stresses the benefits of education and vigilance on the part of both organizations and individuals. He stresses that “Organizations (and end users in general) need to invest in awareness training and protection, be it agents, system policies, or preventative gateway controls, in order to minimize damage. Monitoring of credit, dark web activity, and other associated remote access means can help identify potential harm if the door was already left open.”  

Enjoy Responsibly 

Although this year’s winners on the court won’t be confirmed until the end of the month, we do know that March Madness presents a great opportunity for malicious actors. Familiarize yourself with basic security practices and ensure the authenticity of any online interactions in order to keep yourself in the game. 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Miasma worm spreads from Red Hat packages to Microsoft repositories

June 11, 20264 Mins Read

Dutch police, NCSC take down major botnet

June 4, 20264 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}