Apple, Netflix, and Yahoo Were the Most Impersonated Brands in Q1 2020

Stu Sjouwerman | Apr 21, 2020

iStock-106582469410% of all brand-impersonation phishing attacks spoofed Apple in the first quarter of 2020, according to a new report from Check Point. Netflix came in second with 9%, followed by Yahoo and PayPal, both at 6%. These were followed by PayPal, Chase Bank, Facebook, Microsoft, eBay, and Amazon.

The researchers also broke down the statistics by specific types of phishing. Web-based phishing, which involves a user being redirected to a malicious site while browsing the Internet, was the most common attack vector, and made up 59% of all phishing attacks.

Mobile phishing, which held third place in Q4 2019, surpassed email phishing to take the number two spot in Q1 2020, making up 23% of all phishing attacks. Check Point’s researchers believe this is due to the COVID-19 pandemic, since people are spending more time at home on their phones. Criminals are aware of this, and they’ve adjusted their attacks accordingly.

Email phishing came in third place with 18%. The most impersonated brands for this type of phishing were Yahoo, Microsoft, Outlook, and Amazon.

Maya Horowitz, Check Point’s Director of Threat Intelligence and Research, said some of these numbers reflect how criminals are exploiting the shifts caused by the pandemic.

“Cybercriminals continue to exploit users by adopting highly sophisticated phishing attempts via emails, web and mobile applications purporting to be from well-recognized brands which they know will be in high demand at the moment, whether that’s a high profile product launch or just generally tapping into behavioral changes we’ve seen during the Coronavirus pandemic,” Horowitz said. “Phishing will continue to be a growing threat in the coming months, especially as criminals continue to exploit the fears and needs of people using essential services from their homes. As always, we encourage users to be vigilant and cautious when divulging personal data.”

New-school security awareness training can teach your employees how to recognize and thwart email, mobile, and web-based phishing attacks.

Check Point has the story: https://www.checkpoint.com/press/2020/apple-is-most-imitated-brand-for-phishing-attempts-check-point-researchs-q1-2020-brand-phishing-report/

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.