10% of all brand-impersonation phishing attacks spoofed Apple in the first quarter of 2020, according to a new report from Check Point. Netflix came in second with 9%, followed by Yahoo and PayPal, both at 6%. These were followed by PayPal, Chase Bank, Facebook, Microsoft, eBay, and Amazon.
The researchers also broke down the statistics by specific types of phishing. Web-based phishing, which involves a user being redirected to a malicious site while browsing the Internet, was the most common attack vector, and made up 59% of all phishing attacks.
Mobile phishing, which held third place in Q4 2019, surpassed email phishing to take the number two spot in Q1 2020, making up 23% of all phishing attacks. Check Point’s researchers believe this is due to the COVID-19 pandemic, since people are spending more time at home on their phones. Criminals are aware of this, and they’ve adjusted their attacks accordingly.
Email phishing came in third place with 18%. The most impersonated brands for this type of phishing were Yahoo, Microsoft, Outlook, and Amazon.
Maya Horowitz, Check Point’s Director of Threat Intelligence and Research, said some of these numbers reflect how criminals are exploiting the shifts caused by the pandemic.
“Cybercriminals continue to exploit users by adopting highly sophisticated phishing attempts via emails, web and mobile applications purporting to be from well-recognized brands which they know will be in high demand at the moment, whether that’s a high profile product launch or just generally tapping into behavioral changes we’ve seen during the Coronavirus pandemic,” Horowitz said. “Phishing will continue to be a growing threat in the coming months, especially as criminals continue to exploit the fears and needs of people using essential services from their homes. As always, we encourage users to be vigilant and cautious when divulging personal data.”
New-school security awareness training can teach your employees how to recognize and thwart email, mobile, and web-based phishing attacks.
Check Point has the story: https://www.checkpoint.com/press/2020/apple-is-most-imitated-brand-for-phishing-attempts-check-point-researchs-q1-2020-brand-phishing-report/